SlowMist has yet to confirm crypto theft from iPhone Safari attack

Summary

Recent warnings about an iPhone Safari exploit have not been tied to a confirmed crypto theft in SlowMist’s investigation. SlowMist said the sample it analyzed does not prove a real victim was compromised, and its strongest technical evidence covers iOS 18.4 through 18.6.2, not the broader “iOS 13 to 26.5” range circulating online. The firm said that wider range should be treated as preliminary until reproducible evidence exists. The attack appears to reuse techniques from the previously disclosed DarkSword exploit chain and is separate from SlowMist’s FomoPeek case. SlowMist found a malicious webpage that could trigger exploit code in Safari and a component aimed at accessing Apple Keychain data, app files, and shared app data, which could expose crypto wallet information. Apple had already patched the vulnerabilities used. SlowMist still advises immediate iOS updates, avoiding suspicious links, and using Lockdown Mode if needed. If a seed phrase or key may be exposed, it recommends moving funds to a new wallet on a clean device.