SlowMist is currently investigating a Safari attack targeting iPhones running iOS versions 18.4 to 18.6.2, which could potentially expose cryptocurrency private keys and seed phrases. However, the company has not confirmed any actual theft linked to this attack.
Reports have emerged urging iPhone users to update their devices immediately, as malicious Safari pages may compromise sensitive information. SlowMist has stated that the range of affected iOS versions from 13 to 26.5 is preliminary and requires further verification.
The attack utilizes techniques from the previously disclosed DarkSword exploit chain, which has been in use by various threat actors since at least November 2025. SlowMist's analysis revealed that the malicious Safari page could load exploit code without any user interaction.
While the analyzed sample demonstrated capabilities to access Apple’s Keychain and potentially extract information from crypto wallet applications, SlowMist emphasized that it has not confirmed any successful extractions from targeted wallets.
In light of these findings, SlowMist recommends that iPhone users install the latest iOS security updates and avoid clicking on suspicious links. For heightened security, users are advised to consider Apple’s Lockdown Mode and to transfer assets to new wallets if they suspect exposure of their keys or seed phrases.