DarkSword Exploit Chain Adapted to Target iOS Crypto Wallets

1 hour ago 3 sources negative

Key takeaways:

  • Escalating iOS exploits make hardware wallets structurally more attractive than mobile self-custody for BTC holders.
  • Unconfirmed iOS 26.5 targeting claims risk amplifying short-term fear-driven outflows from mobile-stored ETH and SOL.
  • Counterfeit app losses highlight App Store vetting gaps, a persistent structural risk to retail self-custody adoption.

Cybersecurity firms SlowMist and Ledger have issued urgent warnings about a sophisticated iOS exploit chain called DarkSword that could be used to compromise iPhones and steal cryptographic keys from self-custody crypto wallets.

The DarkSword framework, first documented by Google's Threat Intelligence Group, chains together six iOS security vulnerabilities to compromise devices. On September 21, 2026, Ledger Chief Technology Officer Charles Guillemet issued a public alert describing the attack vector: "Attackers socially engineer a Safari click, then walk the full chain: WebKit/JSC memory corruption → PAC bypass → sandbox escape → kernel/root. From there they pull Keychain + wallet data and drain seeds / private keys."

SlowMist Chief Information Security Officer 23pds warned that attackers may have adapted the exploit chain to potentially target devices running iOS 26.5, although this claim has not been independently confirmed by Apple or Google. Google's original research documented DarkSword activity targeting iOS 18.4 through 18.7, tracked from at least December 2025 through March 2026.

The attack typically begins when an iPhone user opens a malicious link in Safari, often delivered through social media, messaging apps, or other communication channels. Once triggered, the exploit sequence compromises JavaScriptCore (Safari's processing engine), bypasses Apple's Pointer Authentication Codes (PAC) designed to prevent software execution hijacking, escapes the sandbox environment, and ultimately gains kernel-level control.

With root-level access, attackers can read the iOS Keychain, local files, messages, and application data – potentially exposing private keys, wallet recovery phrases, and credentials stored on the device. Google found that various groups have used DarkSword with different payloads to collect account details, browser records, location history, and cryptocurrency wallet information. Operations were connected to victims in Saudi Arabia, Turkey, Malaysia, and Ukraine.

The DarkSword warning follows a related threat called Coruna, an exploit kit containing 23 vulnerabilities across five attack chains targeting iPhones running iOS 13 through iOS 17.2.1. Like DarkSword, Coruna could search files for terms such as "backup phrase" and "bank account."

The warnings also come amid broader iOS security concerns. Binance recently alerted users about malicious code in FomoPeek versions 1.1 and 1.2, which contained kernel exploitation frameworks capable of accessing private keys and recovery phrases. Additionally, three U.S. investors filed a lawsuit alleging fake Sparrow Wallet apps on the App Store caused approximately $1.835 million in Bitcoin losses. A counterfeit Ledger Live application allegedly stole at least $9.5 million from more than 50 victims between April 7 and April 13, with funds traced across Bitcoin, Ethereum, Solana, Tron, and XRP addresses.

Security experts recommend that users promptly install iOS updates, avoid opening unsolicited links, enable Lockdown Mode for enhanced protection, and keep private keys isolated on dedicated hardware devices rather than stored on mobile devices.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.