SlowMist has yet to confirm crypto theft from iPhone Safari attack

SlowMist, after analyzing a malicious Safari webpage sample, has not independently confirmed any cryptocurrency thefts linked to that specific exploit. The firm’s technical evidence shows the sample worked against iOS 18.4–18.6.2, while claims that it affects iOS 13 through 26.5 remain preliminary and unverified.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished less than a minute agoUpdated less than a minute ago0 views
SlowMist has yet to confirm crypto theft from iPhone Safari attack

Why It Matters

The finding narrows the confirmed scope of a high-profile iPhone attack that targeted crypto wallet data and highlights uncertainty around broader version impact, informing users and defenders about which iOS releases have demonstrable risk. SlowMist’s analysis also connects the campaign to previously disclosed exploit techniques, which matters for tracking reuse by threat actors.

Key Facts

  • Analyzed attack type: Malicious Safari webpage (WYINCC campaign) loading exploit code on iPhone Safari
  • Confirmed iOS range (per SlowMist): iOS 18.4 through 18.6.2
  • Unverified broader range cited elsewhere: iOS 13 through iOS 26.5 (SlowMist calls this preliminary)
  • Exploit lineage: Reuses techniques from the DarkSword exploit chain disclosed by Google Threat Intelligence Group
  • Capabilities observed in sample: Component to access Apple Keychain, decrypt stored data, and read app files/shared app data (potentially exposing crypto wallet data)

Cybersecurity firm SlowMist said it has not independently confirmed a cryptocurrency theft tied to a specific malicious Safari sample it analyzed. Multiple alerts this week urged iPhone users to update immediately after reports claimed malicious web pages could exfiltrate private keys and seed phrases across a wide iOS span. SlowMist’s own testing, however, provides the firm’s strongest reproducible evidence only for iOS 18.4 through 18.6.2.

SlowMist cautioned that the broader “iOS 13 to 26.5” range referenced in some reports should be treated as preliminary. The company said it prefers not to assert that iOS 26.5 is affected until reproducible technical evidence emerges. The analysed Safari page was part of a campaign SlowMist labeled WYINCC and appeared to present a free virtual private server offering; the page loaded exploit code when opened in Safari on an iPhone without requiring an additional click.

The malicious sample incorporated code intended to access Apple’s Keychain, retrieve and decrypt stored items, and read application files and shared app data. SlowMist noted these capabilities could put data kept by cryptocurrency wallet apps at risk, but emphasized that the sample demonstrating collection capability does not itself prove successful extraction from every targeted wallet. The vulnerabilities in the exploit chain had previously been disclosed by Apple and patched, SlowMist said.

SlowMist traced elements of the Safari attack back to techniques from DarkSword, an iOS exploit chain Google Threat Intelligence Group described in March as used by multiple threat actors since at least November 2025. The firm’s MistEye threat intelligence team first identified the relevant WYINCC activity in early May and published its analysis on Sept. 4. SlowMist also distinguished this Safari campaign from a separate investigation, FomoPeek, which involved malicious components inside an App Store app.

While SlowMist did not execute the full exploit chain on a live victim device and therefore could not confirm a specific compromised user, the firm advised users to install the latest iOS security updates and avoid suspicious links. For those unable to update immediately or who face heightened risk, SlowMist recommended considering Apple’s Lockdown Mode as an extra safeguard—while noting it has not verified that Lockdown Mode definitively blocks this Safari attack. The company also suggested that users who believe wallet keys or seed phrases were exposed should move assets to a newly generated wallet from a clean device.

Keep Reading