Slowmist Still Hasn't Confirmed Crypto Theft From Iphone Safari Attack
In a statement provided to Cointelegraph, SlowMist said the campaign it investigated appears to reuse techniques from an earlier iOS exploit chain known as DarkSword. While multiple reports urged users to update immediately and cited an especially broad iOS window-“iOS 13 through iOS 26.5” in some coverage-SlowMist cautioned that this range should be treated as preliminary until the company can demonstrate reproducible technical evidence for the latest versions.
Key takeaways- SlowMist has not independently confirmed a real victim compromise or confirmed crypto theft tied to the exact Safari sample it analyzed. The strongest technical evidence from SlowMist focuses on iOS 18.4 through 18.6.2. SlowMist says the suspected Safari exploit chain reuses techniques from Google -disclosed DarkSword, rather than being the same as the separate FomoPeek incident. The analyzed malware includes functionality aimed at reading and decrypting data from Apple Keychain, which can contain sensitive wallet-related information. Even without proof of a successful extraction on every targeted device, SlowMist still recommends updating iOS and avoiding suspicious links.
Multiple reports this week prompted immediate iOS updates, warning that malicious Safari pages could potentially expose crypto private keys and seed phrases. Some of those reports referenced a wide range of iOS versions, extending from iOS 13 to iOS 26.5.
SlowMist's assessment is more restrained. The company told Cointelegraph that it has not independently verified a victim device compromised by the particular Safari attack sample it reviewed. It also indicated that the iOS range appearing in public warnings may be broader than what it can technically support right now.
In particular, SlowMist said it“prefer[s] to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence,” and noted its strongest evidence spans iOS 18.4 through 18.6.2. That distinction matters for users and organizations because overbroad impact claims can either create unnecessary fear on unexposed versions or, conversely, obscure where defenses should be prioritized first.
What SlowMist says was reused from DarkSwordThe Safari campaign is not being treated by SlowMist as an entirely new exploitation method. According to SlowMist, the attack reuses techniques from DarkSword, an iOS exploit chain disclosed by Google 's Threat Intelligence Group (GTIG) in March. Google described DarkSword as having been used by multiple threat actors since at least November 2025, and documented the exploit chain publicly in a dedicated threat intelligence post.
SlowMist said its own MistEye threat intelligence team-led by chief information security officer 23pds-first identified relevant activity in early May. Later, SlowMist published its analysis of the“WYINCC” Safari campaign on Sept. 4, describing how the malicious page presented a lure related to a free virtual private server service.
SlowMist reported that when the page was opened in Safari on an iPhone, the exploit code could load without necessarily requiring an additional user click. Apple later patched the vulnerabilities used in the chain, and SlowMist stated that those underlying weaknesses had already been disclosed and fixed.
Importantly, SlowMist also separated this issue from a different investigation it previously ran regarding FomoPeek-an iOS App Store-related incident described in earlier Cointelegraph coverage. SlowMist characterized the Safari attack as distinct from that separate App Store compromise vector.
Targets inside the device: Apple Keychain and wallet exposureBeyond the exploit mechanism, SlowMist highlighted what the malicious sample was trying to access. In its analysis of the sample, the firm said the code included capabilities to interact with Apple's Keychain-retrieving and decrypting information stored there. SlowMist added that the code could also access app files and shared app data, which could potentially include sensitive data handled by crypto wallet applications.
At the same time, SlowMist emphasized limits in what can be proven from static or controlled analysis. The company said the sample“demonstrates the collection capability and the intended targets,” but does not automatically prove successful extraction from every wallet or every targeted device.
Critically, SlowMist said it did not execute the full chain on a real victim device, which is why it cannot identify a specific victim whose device it independently confirmed was successfully compromised by that exact sample.
Recommendations: update, avoid links, and move funds if exposedEven with those uncertainties, SlowMist urged iPhone users to take practical defensive steps. The firm advised updating to the latest iOS security updates available for affected devices and avoiding suspicious links-especially those delivered via unsolicited messages or pages that promise free services.
For users who cannot update immediately or who face elevated risk, SlowMist pointed to Apple's Lockdown Mode as an additional layer of defense. However, the company cautioned that it has not confirmed Lockdown Mode fully blocks this specific Safari attack.
SlowMist also offered guidance for wallet users who believe their credentials may have been compromised. Its recommendation was to move assets to a newly generated wallet created on a clean device rather than continuing to use potentially exposed private keys or seed phrases.
As more technical details become available, the key question for investors, traders, and wallet users is whether reproducible evidence will narrow the affected iOS versions further-and whether researchers can confirm how often, and under what conditions, the Keychain access successfully results in usable wallet secret extraction on real devices. For now, the safest approach remains the straightforward one highlighted by SlowMist: update promptly, be cautious with Safari links, and treat any suspected seed or key exposure as a reason to rotate credentials immediately.
Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment