SlowMist has warned that attackers may have modified the Darksword exploit chain to target iPhones running iOS 26.5 and extract private keys from self-custody cryptocurrency wallets.
The warning has not been independently confirmed by Apple or Google. Google Threat Intelligence Group previously documented Darksword activity affecting iOS 18.4 through iOS 18.7, but SlowMist Chief Information Security Officer 23pds said attackers had since adapted the tool for the newer operating system.
Darksword attacks can begin when a victim opens a malicious link in Safari. The link may be sent through a social network, messaging service or another communication platform. Once the page loads, malicious web content attempts to exploit Safari and other iOS components without requiring the victim to install a conventional application.
According to 23pds, a successful attack can give criminals root-level access to an iPhone. That could undermine the separation between applications and allow attackers to read files, credentials and private keys held by cryptocurrency wallets on the device.
Google identified Darksword as a complete iOS exploit chain combining six vulnerabilities. It said related activity had been observed from at least December 2025 through March 2026, with different groups using different final-stage payloads.
The original framework supported iOS 18.4 to iOS 18.7. One vulnerability used against devices running iOS 18.6 to iOS 18.7 was CVE-2025-43529, which affected JavaScriptCore, the engine used by Safari to process JavaScript. Apple fixed the vulnerability in iOS 18.7.3 and iOS 26.2 after it was reported by Google.
SlowMist has not detailed which vulnerability, or replacement exploit, might allow Darksword to compromise iOS 26.5. Google’s research linked related operations to victims in Saudi Arabia, Turkey, Malaysia and Ukraine. Some activity was associated with commercial surveillance providers and suspected state-linked groups, while financially motivated attackers also appeared to have obtained advanced iPhone exploitation tools.
The final payloads could collect account information, messages, browser history, files, location records, saved Wi-Fi details and cryptocurrency wallet data. SlowMist did not provide a victim count or confirmed total for cryptocurrency stolen through Darksword.
A similar delivery method was used by Coruna, another mobile exploit kit reported by Google. It contained 23 vulnerabilities across five attack chains and targeted iPhones running iOS 13 through iOS 17.2.1. Coruna could search files and images for terms including “backup phrase” and “bank account”, fingerprint a visitor’s device and choose an exploit based on the iPhone model and software version. Some operators hosted it on fake gambling and cryptocurrency websites.
Recent threats have also targeted wallet credentials directly. Binance warned iPhone and iPad users on Sep. 19 about malicious code in FomoPeek versions 1.1 and 1.2. Researchers found an eight-method kernel exploitation framework supporting iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1. It could escape the iOS sandbox, decrypt Keychain data and access private keys, recovery phrases, account credentials and files belonging to other applications.
Binance advised affected users to delete the app and update iOS. Self-custody users were told to create a wallet on a clean device and transfer their assets, as removing the app would not secure a wallet if its private key or recovery phrase had already been copied.
SlowMist advised users to install operating-system updates promptly and avoid unsolicited links. Apple has patched the six vulnerabilities documented in Google’s original Darksword research.
The warning follows separate legal action in the United States. Three investors allege that fake applications impersonating Sparrow Wallet appeared in Apple’s App Store and caused about $1.835 million in Bitcoin losses.
In another case, a counterfeit Ledger Live application allegedly stole at least $9.5 million from more than 50 victims between April 7 and April 13. Blockchain investigator ZachXBT traced funds from Bitcoin, Ethereum, Solana, Tron and XRP users to more than 150 KuCoin deposit addresses and a mixing service.
The fake Ledger application asked users to enter 24-word recovery phrases during an apparently normal wallet setup. Apple later removed the listing. Unlike Darksword, the application did not need to bypass iOS security controls: users handed over control of their wallets by entering their recovery phrases into the fraudulent software.
