Overview
- SlowMist reported an active full‑chain exploit that begins in Safari and aims to extract private keys and 12–24 word recovery phrases from software crypto wallets on iPhones.
- The chain uses a WebKit/JavaScriptCore memory‑corruption bug in a malicious webpage to bypass protections, break the browser sandbox, escalate to kernel level, and access the iOS Keychain where wallet secrets can be stored.
- Google previously documented the Darksword framework against iOS 18.4–18.7 and Apple has patched several vulnerabilities used in those chains, while SlowMist says operators may have adapted the tool toward iOS 26.5 but Apple and Google have not independently confirmed that specific exposure.
- If a device is compromised, copied private keys and seed phrases cannot be reversed so users should install OS updates, avoid unsolicited links, prefer hardware (air‑gapped) wallets for large holdings, and regenerate keys on a known‑clean device if compromise is suspected.
- The alert follows separate losses from counterfeit wallet apps and scams, showing that browser exploit chains and malicious or fake apps together create persistent, human‑facing distribution paths that threaten self‑custody crypto users.