A security firm called SlowMist has released a thorough technical examination of a Safari exploit chain that could enable attackers to take crypto private keys and seed phrases from iPhones. The report does not confirm that any single person had funds stolen as a result. The findings raise serious questions about the trustworthiness of security warnings that circulate online.
This warning arrives after several publications cautioned this week that malicious Safari pages might reveal crypto private keys and seed phrases on iOS devices. Now SlowMist has released its own examination, though its most compelling proof applies to just a limited range of iOS versions.
The WYINCC Campaign
The SlowMist researchers focused on a website offering a free virtual private server service, which secretly included code designed to take advantage of a weakness in Safari on iPhones. The exploit code ran simply by opening the page, and it did not always need a second tap from the person viewing it.
The sample reused techniques from a previously disclosed DarkSword exploit chain. SlowMist said MistEye, a threat intelligence team led by its chief information security officer, 23pds, first identified the relevant activity in early May.
SlowMist published its findings on Sept. 4.
What the Code Could Do
The malicious Safari sample came with a part built to reach into Apple’s Keychain. That part was able to pull out and read through information kept inside it, including data from crypto wallet apps.
The software was capable of reaching app files and shared app data too. SlowMist pointed out that the sample showed the gathering power and the intended targets, though it failed to confirm successful removal from every targeted wallet.
“We did not execute the full chain on a real victim device, so we cannot identify a specific victim whose device we independently confirmed was successfully compromised by this exact sample,” SlowMist said.
The iOS 26.5 Question
A sequence of attacks was aimed at versions of iOS from 18.4 through 18.6.2, relying on flaws that Apple had already fixed. Whether it also works against iOS 26.5 has not been confirmed.
Cointelegraph was told by SlowMist that it has not confirmed on its own that any victim fell prey to the particular Safari attack sample it examined. The company also said that the “iOS 13 to 26.5” range cited in other reports should be treated as preliminary.
“We therefore prefer to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence,” it said.
Related Research
Google Threat Intelligence Group (GTIG) first revealed the DarkSword exploit chain in March. The group said it is an iOS exploit chain that has been employed by several threat actors since at least November 2025.
Recommendations From SlowMist
SlowMist urged iPhone users to put on the newest iOS security updates for their devices and stay away from dubious links, even with the limitations of what is known.
SlowMist advised users who cannot update immediately or carry elevated risks to consider adopting Apple’s Lockdown Mode as added protection. The firm warned, however, that it has yet to confirm the feature entirely blocks this particular Safari attack.
SlowMist encouraged people who think they might have exposed a wallet key or seed phrase to move their funds to a fresh wallet created on a clean device instead of keeping hold of possibly compromised login details.
The Key Gaps
The main shortcoming in SlowMist’s examination is the absence of a confirmed person who suffered a loss. The firm has not independently established that any individual gave up crypto assets due to this particular Safari attack specimen.
The document lays out the exploit chain’s technical capabilities in full, yet refrains from asserting any stolen data. That gap between description and confirmation is worth keeping in mind when weighing security warnings found online.
There is no confirmed information backing up the warning about iOS 26.5. SlowMist considers the stated range to be preliminary only, pending reproducible technical proof.
The Broader Picture
The pace of security research means findings frequently move online at a rapid clip, sometimes before the complete picture has emerged. A technical analysis can turn into a headline before the whole story is known.
The fact that SlowMist is publishing its findings without asserting that it has caught a thief red-handed is telling.
The advice is sensible even without a confirmed breach:
- Install the latest iOS security updates
- Avoid suspicious links
- Consider Lockdown Mode for elevated risks
- Move assets to a new wallet on a clean device if a key or seed phrase may have been exposed
GTIG reports that several threat actors have turned to the DarkSword chain since November 2025, putting the network back in the spotlight once more.
What This Means for Users
The bottom line is straightforward: make sure your software stays current. The attack relies on patched flaws, so a solution already exists — all that remains is to put it into use.
Be cautious when you click on links. Untrusted pages can deliver attacks, and malicious webpages are among the most frequent sources of such threats.
When a device appears to have been taken over, the best course is to begin anew. Create a fresh wallet on an uninfected machine and move your funds into it.
The SlowMist study demonstrates the full scope of what the attack might have accomplished, though it is still unclear whether any victims ever fell into the trap.
There is genuine reason to be concerned, yet no evidence has been offered. The assault is recorded, but its subjects remain unnamed.
Source material: “SlowMist has yet to confirm crypto theft from iPhone Safari attack,” Cointelegraph.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

