NewsCryptoSlowMist Warns Darksword Exploit Chain May Target Bitcoin Wallets on iOS 26.5

SlowMist Warns Darksword Exploit Chain May Target Bitcoin Wallets on iOS 26.5

Author: Coinotag·

Key Takeaways

  • •SlowMist's chief information security officer 23pds warned that attackers may have adapted the Darksword exploit chain to target devices running iOS 26.5, placing self-custody wallet private keys at risk.
  • •Google Threat Intelligence Group identified Darksword as a chain of six vulnerabilities used in active campaigns from at least December 2025 through March 2026, with Apple patching them, including CVE-2025-43529 in JavaScriptCore.
  • •The attack is delivered through malicious links opened in Safari without any app install and achieves root or kernel-level control, enabling export of credentials and data tied to locally stored crypto wallets.
  • •Neither Apple nor Google has confirmed the iOS 26.5 claim, and SlowMist's warning did not cite technical analysis identifying a specific vulnerability in that release.
  • •The warning follows other recent iPhone crypto threats, including Binance's notice of malicious code in FomoPeek versions 1.1 and 1.2 and three U.S. investors' allegations of $1.835 million in Bitcoin losses from fake Sparrow Wallet apps.
SlowMist Warns Darksword Exploit Chain May Target Bitcoin Wallets on iOS 26.5

SlowMist, the blockchain security firm, has warned that attackers may have adapted the Darksword exploit chain to compromise devices running iOS 26.5, placing private keys held in self-custody cryptocurrency wallets directly at risk.

The assessment came from 23pds, the firm's chief information security officer, who said in a public warning post that attackers are deploying Darksword to bypass Apple's security controls, gain broad access to affected iPhones and harvest data from locally installed crypto wallets. The warning extends a threat that Google Threat Intelligence Group has documented in detail.

The Original Darksword Chain

Google's researchers identified Darksword as a full iOS exploit chain — six vulnerabilities chained together to compromise a device and deliver interchangeable malicious payloads — and tracked active campaigns from at least December 2025 through March 2026. The original framework supported iOS versions 18.4 through 18.7.

One flaw used against devices running iOS 18.6 and 18.7, tracked as CVE-2025-43529, sat in JavaScriptCore, the engine that processes JavaScript in Safari. Apple patched it in iOS 18.7.3 and iOS 26.2 after Google reported it.

SlowMist's claim that the chain now reaches iOS 26.5 has not been confirmed by Apple or Google, and the firm's warning did not cite technical analysis identifying which vulnerability or replacement exploit could compromise the newer release.

Delivery Method and Device-Level Impact

The delivery method, however, follows the documented pattern: a target receives a link through a social network or messaging app and opens the page in Safari, where malicious web content attempts to exploit the browser and other iOS components without requiring any application install.

Once the chain succeeds, an attacker can obtain root-level control — access that dissolves the isolation normally preventing one app from reading another app's files. That places private keys and wallet records stored on the device, rather than on a remote server or a blockchain node, within reach. Unlike cryptojacking, which hijacks device resources to mine, this class of attack targets the credentials themselves.

Google's March Research on Darksword

The anatomy of the attack, mapped in Google Threat Intelligence Group research published in March, starts with a memory-corruption flaw in JavaScriptCore and begins when the victim visits a malicious or compromised website in Safari. From there, the chain defeats Pointer Authentication Codes (PAC) — Apple's hardware-level defense that cryptographically signs memory pointers to block exploit primitives — breaks out of Safari's WebContent sandbox and, in its final stage, achieves kernel-level privileges, effectively handing the attacker full control of the handset.

Lookout's research into the aftermath found that user credentials and data associated with crypto wallets can be exported from the device shortly after compromise. That makes the exposure acute for self-custody users who store a recovery phrase or private key on the phone itself, including those who sign transactions for a DeFi app from a mobile wallet.

Google's findings show several separate groups operating Darksword with different final-stage payloads rather than one fixed malware strain. Depending on the campaign, the payloads could collect account details, messages, browser records, files, location history, saved Wi-Fi data and information tied to cryptocurrency wallets.

Researchers connected operations to victims in Saudi Arabia, Turkey, Malaysia and Ukraine, and associated some activity with commercial surveillance providers and suspected state-linked groups, while also finding signs that financially motivated actors had obtained access to advanced iPhone exploitation tooling. No confirmed victim total or verified amount of cryptocurrency stolen through Darksword has been disclosed in the material published so far; the emphasis remains on the framework's capability to reach wallet data after compromising the device that stores it.

Recommended Precautions

SlowMist's guidance is unchanged from earlier advisories: install mobile operating-system updates promptly and avoid opening unsolicited links from strangers. Because Apple has already patched the six vulnerabilities in the original Darksword chain, keeping software current is treated by both Apple and Google as the primary line of defense. No specific fix corresponds to the iOS 26.5 claim itself, since SlowMist's warning did not identify a vulnerability in that release.

A Rising iPhone Threat Pattern

The warning arrives days after Binance's official Sep. 19 notice flagged malicious code in FomoPeek versions 1.1 and 1.2 — a kernel framework with eight attack methods spanning iOS 12.0 through 18.7.2 and 26.0 through 26.1, capable of escaping the sandbox and decrypting Keychain data. Separately, three U.S. investors allege that fake Sparrow Wallet apps in the App Store caused $1.835 million in Bitcoin losses. Read together, the recent incidents show threats to iPhone-based crypto users arriving on two fronts: exploit chains aimed at the operating system itself and code delivered through apps.

The core claim in SlowMist's warning — iOS 26.5 exposure — remains unconfirmed by Apple or Google, meaning it currently stands as a warning rather than a verified breach report. Any change in that status would surface through SlowMist's own technical detail or the security publications of Apple and Google, the channels through which the original chain's vulnerabilities were disclosed and patched.