Apple DarkSword Hack Puts iPhone Crypto at Risk
DarkSword can compromise vulnerable iPhones through Safari and steal sensitive data, including crypto wallet information. Here is what Apple users need to know.
DarkSword, an iOS exploit chain that may turn a Safari visit into a complete device compromise, has caused Apple users' concerns again. Security analysts have cautioned that the attack's revealed capabilities could put crypto users at special risk, while Google researchers discovered that the attack was being employed by several threat actors. Sensitive data kept on an iPhone, such as wallet information and Keychain contents, can be compromised. Although Apple has delivered security fixes, customers shouldn't put off updating susceptible devices, according to more recent advisories.
DarkSword Turns a Safari Visit Into a Serious Attack
DarkSword is not a single security issue, but a series of six bugs. Researchers from Google Threat Intelligence discovered that when a victim used Safari to browse a malicious or compromised website, attackers could start the operation. The assault might start without the user having to download an app or consent to an installation.
The chain takes advantage of flaws in the iOS kernel, dyld, ANGLE, and JavaScriptCore. Before breaking out of the WebContent sandbox, it first gives malicious JavaScript more power over the device and then gets over Apple's Pointer Authentication safeguards. Attackers have far more influence over the iPhone because of the last steps, which grant kernel level access.
CVE 2025 31277, CVE 2025 43529, CVE 2025 14174, CVE 2025 43510, and CVE 2025 43520 were among the vulnerabilities. According to Google, before the necessary patches were released, the chain was being used in the wild against iOS versions 18.4 through 18.7.

The Attack Can Reach Crypto Wallet Information
For those who store financial data on their phones, the vulnerability becomes very alarming. Messages, emails, contacts, pictures, notes, browser data, iCloud files, location records, and Keychain information can all be searched by the spyware linked to DarkSword campaigns.
Cryptocurrency applications are also part of its targeting. Coinbase, Binance, Kraken, KuCoin, OKX, Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe are among the apps and services that researchers discovered checks for.
This implies that a typical personal information attack is not the only kind. Attackers may be able to access cryptocurrency holdings if sensitive wallet content is available via a hacked device.
Additionally, one campaign delivered GHOSTBLADE by using hijacked websites as watering holes. Researchers found similar activities directed at users in Saudi Arabia, Turkey, Malaysia, and Ukraine, among other nations.

Apple Expanded Its Security Updates
After fixing the vulnerabilities, Apple released iOS and iPadOS 18.7.7 for some older devices. Later, as more information on the DarkSword chain became available, security coverage was extended to other devices.
While newer devices were being directed toward iOS 26, some users who continued to utilize iOS 18 experienced uncertainty. The security update was located in Settings, General and Software Update's Also Available section for users who want to stick with iOS 18.
Zero-day remote code execution vulnerability in iPhone Safari. Click a link, and your crypto, passwords and everything else on your iPhone are gone.
— Mikko Ohtamaa (@moo9000) September 21, 2026
Exploited in the wild by "DarkSword" malware.
"The DarkSword attack program has leaked, with its core capability being:… https://t.co/oggNfPch5K
After SlowMist CISO 23pds issued a warning, the situation has drawn further attention. The researcher cautioned that hackers might target bitcoin private keys and mnemonic seed phrases using the revealed DarkSword capability and recommended iPhone owners to apply the most recent update.
Additionally, the alert stated that iOS 13 to iOS 26.5 could be the possible range. It should be regarded as an unverified warning rather than an established affected range because the larger range has not been fully independently confirmed.
Urgent security advisory for iOS users!
— Officer's Notes (@officer_secret) September 21, 2026
Install the latest iOS update immediately. Security researchers report that financially motivated attackers are now using a complete, in-the-wild exploit chain that can quietly steal cryptocurrency private keys and mnemonic seed phrases…
Lockdown Mode Gives High Risk Users Extra Protection
For individuals who are susceptible to highly targeted attacks, Apple's Lockdown Mode offers an additional security option. While some standard functions become less useful when it is activated, it limits some device functionalities and minimizes potential attack surfaces.
Users can turn it on by going to Settings, Security and Privacy, then Lockdown Mode. When the feature is activated, the phone will restart.

Updating iOS is still the first step for crypto users. It's also crucial to keep clear of suspicious links in Safari, especially if a phone has vital recovery data or wallet apps.
When possible, people who own large amounts of crypto should think about keeping their private keys away from regular phones. Since resetting a password does not replace an exposed blockchain key, transferring money to a freshly created wallet may be required if a seed phrase or private key has been saved on a potentially compromised device.
If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- S&P Global to Acquire OpenZeppelin
- Derive.xyz Bets Big on On-Chain Options Trading
- CoinEx Shuts Down After Nine Years
- Bitcoin ETFs Lose $463M, Ethereum ETFs Gain $197M
- Revolut Shares Customer Data After Fake Government Email
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.