- SlowMist has not confirmed any cryptocurrency theft linked to the Safari attack it analyzed, despite widespread security warnings
- The attack reuses techniques from the previously disclosed DarkSword exploit chain and targets iOS devices through malicious Safari pages
- The iOS version range cited in reports (13 through 26.5) remains preliminary, with SlowMist’s strongest evidence covering versions 18.4 through 18.6.2
- The malicious code can access Apple’s Keychain and shared app data, potentially exposing crypto wallet information
An iPhone Safari attack that triggered urgent security warnings this week has not been linked to a confirmed cryptocurrency theft, according to blockchain security firm SlowMist. The company told Cointelegraph that it has not independently verified a victim compromised by the specific attack sample it analyzed.
Multiple reports urged iPhone users to update devices immediately, warning that malicious Safari pages could expose crypto private keys and seed phrases across a range from iOS 13 through iOS 26.5. However, SlowMist said this version range should be treated as preliminary, and the company’s strongest technical evidence covers iOS 18.4 through 18.6.2. “We therefore prefer to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence,” the firm stated.
SlowMist identified the WYINCC Safari campaign on Sept. 4, discovering a malicious webpage that advertised a free virtual private server service. The page loaded exploit code when opened on an iPhone using Safari, without requiring an additional click from the user.
The attack reuses techniques from DarkSword, an iOS exploit chain that Google Threat Intelligence Group disclosed in March. SlowMist said the vulnerabilities used in the chain had already been patched by Apple.
The malicious sample included a component designed to access Apple’s Keychain and retrieve decrypted information stored there. The code could also access app files and shared app data, potentially exposing information stored by crypto wallet applications. “The sample demonstrates the collection capability and the intended targets; it does not by itself prove successful extraction from every targeted wallet,” SlowMist said.
Consequently, SlowMist advised iPhone users to install the latest iOS security updates and avoid suspicious links. For users facing elevated risks, the firm recommended considering Apple’s Lockdown Mode as an additional defense, while cautioning that it has not confirmed this feature completely blocks the attack.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
