Skip to content

Invest1 publisher3 min readPublished

SlowMist's evidence places the iPhone Safari wallet attack on iOS 18.4 through 18.6.2

SlowMist says its evidence for the iPhone Safari attack on crypto wallet keys covers iOS 18.4 to 18.6.2 and that it has confirmed no theft victim. The firm calls this week's iOS 13 to 26.5 warnings preliminary and still tells iPhone users to install security updates.

The Investor · Invest desk

Illustration accompanying SlowMist's evidence places the iPhone Safari wallet attack on iOS 18.4 through 18.6.2

What happened

  • Reports this week warned that malicious Safari pages could expose crypto private keys and seed phrases on iPhones running anything from iOS 13 through iOS 26.5.
  • SlowMist has not independently confirmed any victim compromised by the specific Safari sample it analyzed.
  • The attack page advertised a free virtual private server service and loaded exploit code when opened in Safari on an iPhone, possibly with no further click.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • contradiction The two ranges call for different responses: under the broad one every iPhone holder should treat stored keys as at risk, while SlowMist's evidence documents exposure only on 18.4 to 18.6.2.
  • exposure Because loading a page can be enough, a holder on an unpatched phone in the documented range can be reached through a link alone.
  • decision Holders who cannot update have to decide on Lockdown Mode before SlowMist has confirmed that it fully blocks this attack.
  • cost Anyone who suspects a leaked seed phrase is told to move assets to a new wallet on a clean device, a migration the holder pays for in hardware and time before any theft is confirmed.

The warnings in circulation go further than the evidence of the firm that analyzed the sample [1][2]. "We therefore prefer to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence," SlowMist said [5]. It had told Cointelegraph that the iOS 13 to 26.5 range should be treated as preliminary [4].

The analysis documents what the attackers intended in some detail. The sample carried a component designed to reach Apple's Keychain and to retrieve and decrypt what is stored there. The code could also read app files and shared app data, where crypto wallet applications may keep information [6]. "The sample demonstrates the collection capability and the intended targets; it does not by itself prove successful extraction from every targeted wallet," SlowMist said [7]. The firm also stopped short of running the attack end to end. "We did not execute the full chain on a real victim device, so we cannot identify a specific victim whose device we independently confirmed was successfully compromised by this exact sample," it said [8].

The version band follows from what the chain is built on. The attack reuses techniques from DarkSword, an iOS exploit chain that Google Threat Intelligence Group disclosed in March and described as used by multiple threat actors since at least November 2025 [9]. DarkSword was therefore in use for at least four months before it was public [1]. SlowMist said the vulnerabilities used in the chain had already been disclosed and patched by Apple [10]. Its MistEye team, led by chief information security officer 23pds, first identified the relevant activity in early May [11], and the firm published its WYINCC analysis on Sept. 4 [12], roughly four months later [2]. The findings, as reported, do not include a count of affected devices or a dollar figure for wallets at risk.

There are three ways this can go. Reproducible evidence on iOS 26.5 would make the broad warnings early, and phones on that version would carry an exposure SlowMist has not yet shown. Confirmed victims on 18.4 to 18.6.2 devices would prove theft inside the band SlowMist already documented and leave later versions outside it. If neither arrives, the 13-to-26.5 range stays an assertion with no demonstration behind it [4].

In my view the risk belongs to the narrow band. An exploit assembled from flaws Apple has already patched works only against phones whose owners skipped the fixes [10]. For a holder, that makes the version number on the phone the first thing to check, before any decision about moving funds. A confirmed theft from a fully updated iPhone would prove that view wrong.

The Safari attack is also separate from FomoPeek, another SlowMist investigation, which involves malicious components embedded in an App Store app [14].

What to watch

  • Whether SlowMist tests Apple's Lockdown Mode against this Safari sample and confirms that it blocks the attack.
  • SlowMist's findings in its separate FomoPeek investigation of the malicious App Store app, a second vector it is examining.
  • Any statement from Apple or Google Threat Intelligence Group on which iOS versions the DarkSword techniques can reach.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories