Close Menu
NCIJ Network NCIJ Network
    What's Hot

    What are the Lib Dems for? They must champion localism to stay relevant in an age of single-issue politics | Simon Jenkins

    September 25, 2026

    India’s ‘cockroach’ movement demands election chief’s resignation | Politics News

    September 25, 2026

    Healey appoints Labour manifesto writer, fuelling election speculation | Labour

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • What are the Lib Dems for? They must champion localism to stay relevant in an age of single-issue politics | Simon Jenkins
    • India’s ‘cockroach’ movement demands election chief’s resignation | Politics News
    • Healey appoints Labour manifesto writer, fuelling election speculation | Labour
    • Your LG TV is constantly collecting your data – here’s how to stop it
    • The SOC Doesn’t Need to Start Over with Every Alert
    • SlowMist Has Yet to Confirm Crypto Theft From iPhone Safari Attack
    • CNOOC keeping Worley busy on its North Sea assets for five more years
    • Ethiopia war: Internet disrupted in Tigray
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    SlowMist Has Yet to Confirm Crypto Theft From iPhone Safari Attack

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Crypto & Blockchain No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An iPhone Safari attack behind recent security warnings hasn’t yet been linked to a confirmed cryptocurrency theft in SlowMist’s investigation.

    Multiple reports surfaced this week urging iPhone users to update their devices immediately and warning that malicious Safari pages could expose crypto private keys and seed phrases, with some citing a range from iOS 13 through iOS 26.5.

    SlowMist told Cointelegraph that it has not independently confirmed a victim compromised by the specific Safari attack sample it analyzed, while its strongest technical evidence covers iOS 18.4 through 18.6.2.

    The company said the “iOS 13 to 26.5” range should be treated as preliminary. “We therefore prefer to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence,” it said.

    The Safari attack reuses techniques from a previously disclosed DarkSword exploit chain and is separate from FomoPeek, another SlowMist investigation involving malicious components embedded in an App Store app.

    SlowMist finds DarkSword reuse

    Google Threat Intelligence Group (GTIG) disclosed DarkSword in March, describing it as an iOS exploit chain that had been used by multiple threat actors since at least November 2025.

    SlowMist said MistEye, a threat intelligence team led by its chief information security officer, 23pds, first identified the relevant activity in early May.

    SlowMist published its analysis of the WYINCC Safari campaign on Sept. 4, identifying a malicious webpage advertising a free virtual private server service.

    SlowMist said the page loaded the exploit code when opened on an iPhone using Safari, without necessarily requiring another click from the user.

    The vulnerabilities used in the chain had already been disclosed and patched by Apple, SlowMist said.

    What the Safari attack was designed to access

    SlowMist found that the malicious Safari sample it analyzed included a component designed to access Apple’s Keychain and retrieve and decrypt information stored there. The code could also access app files and shared app data, potentially exposing information stored by crypto wallet applications.

    “The sample demonstrates the collection capability and the intended targets; it does not by itself prove successful extraction from every targeted wallet,” SlowMist said.

    Related: EU watchdogs warn quantum computers could pick crypto’s locks

    “We did not execute the full chain on a real victim device, so we cannot identify a specific victim whose device we independently confirmed was successfully compromised by this exact sample,” SlowMist added.

    SlowMist still recommends updating iOS

    Despite the limits of the available evidence, SlowMist advised iPhone users to install the latest iOS security updates available for their devices and avoid suspicious links.

    For users who cannot update immediately or face elevated risks, SlowMist recommended considering Apple’s Lockdown Mode as an additional defense, while cautioning that it has not confirmed the feature completely blocks this specific Safari attack.

    SlowMist also urged users who believe a wallet key or seed phrase may have been exposed to move their assets to a newly generated wallet on a clean device rather than continue using potentially compromised credentials.

    Magazine: Asia dominates Crypto Adoption Index, Bitget’s $352M hack: Asia Express

    attack Confirm Crypto iPhone safari SlowMist theft
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    MultiversX resumes blocks while Kraken bars new EGLD trades

    Saifedean Ammous: The Bond Crisis & Bitcoin’s Rise As A True Macro Asset

    Bitget’s North Korea-linked $352 million hack could drain 76% of its protection fund

    Hackers steal $351.6 million in Bitget crypto exchange hack

    Solana DEX volume spike hides circular trades, and automated bots are blamed

    Jeff Booth: Why $1 Million BTC Is Thinking Too Small

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    What are the Lib Dems for? They must champion localism to stay relevant in an age of single-issue politics | Simon Jenkins

    September 25, 2026

    India’s ‘cockroach’ movement demands election chief’s resignation | Politics News

    September 25, 2026

    Healey appoints Labour manifesto writer, fuelling election speculation | Labour

    September 25, 2026

    Your LG TV is constantly collecting your data – here’s how to stop it

    September 25, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    What are the Lib Dems for? They must champion localism to stay relevant in an age of single-issue politics | Simon Jenkins

    September 25, 2026

    India’s ‘cockroach’ movement demands election chief’s resignation | Politics News

    September 25, 2026

    Healey appoints Labour manifesto writer, fuelling election speculation | Labour

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.