Skip to content

Invest1 publisher3 min readPublished

SlowMist puts 14 iOS versions inside one Safari key-theft chain

Blockchain security firm SlowMist says an active exploit chain walks from a Safari page to kernel access and the iOS Keychain on everything from iOS 13 to 26.5, while Apple's patches, by the same account, reach 26.3.

The Investor · Invest desk

Illustration accompanying SlowMist puts 14 iOS versions inside one Safari key-theft chain

What happened

  • SlowMist said on September 19 that an active full-chain exploit is being used against iPhones running iOS 13 through 26.5 to lift private keys and mnemonic seed phrases out of crypto wallets.
  • The chain starts on a malicious Safari page that exploits memory corruption in WebKit and JavaScriptCore, then bypasses Pointer Authentication Codes, escapes the sandbox, reaches the kernel and opens the iOS Keychain.
  • SlowMist's CISO, who publishes as 23pds, issued the alert, and Ledger CTO Charles Guillemet amplified it on September 21, telling users to update iOS immediately and avoid unfamiliar links.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • contradiction The same account puts the affected range at 26.5 and the patch line at 26.3, so the one instruction both named parties gave, update iOS, cannot be shown from the published record to close the chain.
  • cost A suspected exposure costs the holder a full key migration, new keys generated on clean hardware plus funds moved to a new address, and no part of that is recoverable from anyone.
  • decision Anyone holding size in a software wallet on an iPhone now has to decide whether a device that runs every app and webpage is where the keys belong.
  • exposure Key theft has no remediation path comparable to a password reset, so the loss lands in full on the self-custody holder rather than on an intermediary.

A full chain is several separate bugs stacked in order, and this one makes four moves after the browser foothold: past Pointer Authentication Codes, out of the sandbox, up to kernel level, into the Keychain [2][13]. Each move needs its own fix. Apple has patched several of the vulnerabilities in the chain through iOS 26.3, according to the report, while the affected range SlowMist published ends at 26.5, two point releases higher [4][1][12]. The instruction to update iOS, which Ledger's Charles Guillemet gave on September 21, is the best available step, and whether it closes the chain is undemonstrated [3].

Fourteen major versions sit inside the stated range, iOS 13 through 26 [11][1]. A range that wide leaves the number of handsets actually reached open, and SlowMist published no CVE number, victim count or loss figure [14].

Two people carry this on the record: SlowMist's CISO, who publishes as 23pds and issued the alert on September 19, and the chief technology officer of Ledger, who amplified it two days later [3][1]. The remedy the article settles on is architectural: keys held on a dedicated physical device that never touches a network, out of reach of a Safari bug [5].

For a holder who suspects exposure, the recommended fix is not a password reset. Researchers advise regenerating keys entirely on a clean device and moving funds to a new wallet address [6]. A stolen private key has no reset at all; whoever holds it holds the funds [7].

This is the second iOS episode aimed at crypto users in 2026, by cryptobriefing's count [9]. In March, researchers flagged an exploit kit called DarkSword that chained six separate vulnerabilities against iPhones on iOS 18.x variants and went after Coinbase and MetaMask [8]. The March kit used six bugs; the September chain uses four escalation steps [8][13].

I would treat the published version range as the operative fact here and a single firm's confirmation as thin evidence. The asymmetry still favours rotating keys: being wrong about waiting costs the balance [7], while being wrong about rotating costs transaction fees and the work of standing up a new address [6]. The more interesting decision sits behind it: whether a general-purpose phone is a custody venue at all, given that a software wallet shares its attack surface with every app, webpage and piece of code on the device [10]. Two things would change my mind. An Apple security note naming the CVEs fixed in 26.4 or 26.5 would collapse the gap between the patch line and the top of the affected range [12], or a second firm publishing victims and on-chain losses would move this from a version range to a measured event.

What to watch

  • An Apple security note naming the CVEs fixed in iOS 26.4 or 26.5 would close the gap between the patch line and the top of the affected range.
  • A second security firm publishing victim counts or on-chain losses traceable to this chain.
  • Any technical detail beyond the alert itself, such as an exploit sample or the affected WebKit build numbers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories