iPhone Users Warned of Safari Exploit Risk to Crypto Wallets

4–6 minutes
Fact Checked by Mazel Ventura

Last Updated:

September 23, 2026

iPhone showing a Safari security warning beside a locked crypto wallet.

iPhone Users Warned of Safari Exploit Risk to Crypto Wallets

iPhone showing a Safari security warning beside a locked crypto wallet.

iPhone Users Warned of Safari Exploit Risk to Crypto Wallets

iPhone users have been warned about a reported Safari exploit that could allow attackers to access cryptocurrency private keys, recovery phrases, and Apple Keychain data through a malicious webpage.

The warning was issued by SlowMist Chief Information Security Officer 23pds, who said attackers could use a Safari-based exploit chain to move from browser-level access to deeper iOS privileges. The researcher claimed the attack could affect devices running iOS 13 through 26.5, although that range has not been independently confirmed by Apple or Google.

The warning is particularly relevant to crypto users because gaining access to an iPhone’s Keychain or wallet data could expose credentials used to control self-custodied assets.

How the Reported Safari Attack Could Work

According to the security warning, the attack begins when a user visits a malicious webpage through Safari.

The reported exploit chain involves memory corruption in WebKit and JavaScriptCore, the technologies that power Safari’s browser and JavaScript functions. The attacker could then attempt to bypass Apple’s Pointer Authentication Code protections, escape the browser’s security sandbox, and gain deeper access to the device.

The researcher said the final stage could provide kernel-level access, potentially allowing attackers to extract sensitive information stored on the iPhone.

This is different from a normal phishing attack. A phishing website typically tries to trick users into entering their recovery phrase or login credentials. The reported exploit instead aims to compromise the device through the browser itself.

Crypto Wallets Could Be at Risk

The potential impact is serious for users who keep wallet information on their iPhones.

According to the warning, an attacker with deep device access could potentially extract private keys, seed phrases, and keychain data. Wallet applications that rely on the device to store or temporarily access sensitive credentials could therefore be exposed.

However, the warning does not establish that specific crypto wallets have already been drained through this newly reported attack.

The risk is also different from an exchange account compromise. With a self-custodial wallet, whoever obtains the private key or recovery phrase can potentially control the assets associated with that wallet. 

Moving funds to a new wallet is therefore necessary if the original credentials are confirmed to have been exposed.

DarkSword Has Already Been Used Against iPhones

The new warning is related to DarkSword, an iOS exploit framework previously documented by Google’s Threat Intelligence Group and other security researchers.

In the past, DarkSword used multiple vulnerabilities in iOS and Safari to compromise devices through infected websites. The documented campaigns targeted iPhones running older versions of iOS, including versions 18.4 to 18.7. Apple subsequently patched the vulnerabilities used in those attacks.

The newer warning suggests that attackers may have adapted similar techniques to newer iOS versions. However, no public independent confirmation currently shows that DarkSword can successfully compromise iOS 26.5.

That distinction matters because the earlier DarkSword vulnerabilities and the newly reported iOS 26.5 exposure should not be treated as the same confirmed vulnerability.

Apple Updates Remain the Main Defense

Apple continues to release security updates for iPhone and Safari vulnerabilities.

A September 16 advisory from the Canadian Center for Cyber Security listed vulnerabilities affecting iOS versions before 27 and 26.7, as well as Safari versions before 27. The agency advised users to apply available security updates.

Users should therefore check Settings > General > Software Update and install the latest available iOS version for their device.

Keeping the operating system updated is especially important for crypto users because browser vulnerabilities can create a path to information that wallet applications and device security features would otherwise protect.

Security Detail Current Information 
Reported threat Safari-based iOS exploit 
Researcher issuing warning SlowMist CISO 23pds 
Reported affected range iOS 13 to 26.5 
Newer iOS exposure Not independently confirmed 
Potential data at risk Private keys, seed phrases, and Keychain data 
Attack method Malicious webpage through Safari 
Apple patches Earlier DarkSword vulnerabilities were patched 
Recommended action Update iOS and avoid suspicious links 

Table 1. Current information about the reported Safari exploit and its potential impact on crypto wallets.

Crypto Users Should Treat Exposed Keys Differently

If a private key or recovery phrase has actually been exposed, simply deleting a malicious webpage, closing Safari, or removing an application does not make the wallet safe again.

The compromised credentials could still be used by an attacker. Users who have strong evidence that their wallet credentials were exposed should create a new wallet on a clean device and move remaining assets to the new address.

Users should also avoid storing recovery phrases in screenshots, notes or other easily accessible digital locations. A hardware wallet can provide additional protection by keeping key operations separate from the phone.

At the same time, users should not assume that every iPhone or crypto wallet has been compromised based only on the latest warning. The reported newer iOS attack remains subject to independent verification.

What Comes Next

Security researchers are expected to continue investigating whether the reported attack chain works against newer iOS versions and whether it is connected to the earlier DarkSword campaigns. Apple would also need to confirm and patch any newly identified vulnerabilities if they are verified.

For now, the main steps for crypto users are to keep iOS updated, avoid suspicious links, and review wallet activity for unauthorized transactions. Users whose private keys or recovery phrases are confirmed to have been exposed should move their assets to a new wallet rather than continue using compromised credentials.

What This Means for You: iPhone users should install the latest available iOS update and be careful with links opened in Safari, especially when using crypto wallets. The newer iOS 26.5 warning has not been independently confirmed, but users with confirmed exposure of private keys or recovery phrases should move their funds to a new wallet created on a clean device. 

Join our growing community

David Constantino

Author

David is a crypto enthusiast, airdrop farmer, and blog writer with a focus on discovering and analyzing new token launches and blockchain projects. He explores the latest trends, shares actionable insights, and guides readers through opportunities in the fast-paced world of digital assets.