SlowMist: The Darksword vulnerability is reportedly able to attack iOS 26.5 and steal wallet private keys
The Chief Information Security Officer of the blockchain security company SlowMist, 23pds, stated that attackers are exploiting the Darksword vulnerability to bypass iOS security mechanisms through Safari, gaining control of devices and extracting private keys and other data from self-hosted cryptocurrency wallets. This vulnerability has been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. The Google Threat Intelligence Group previously disclosed that Darksword initially only affected iOS versions 18.4 to 18.7.23pds noted that attackers have adapted it to iOS 26.5, but this assessment has not yet been officially verified. Attacks typically begin with social engineering, where users click on malicious links sent via social media or messaging applications, potentially granting Root access to the device and extracting wallet data. Users should promptly update their mobile systems and avoid visiting website links sent by strangers; additionally, three investors have lost nearly 1.8 million dollars in Bitcoin due to downloading fake wallet applications from the official Apple App Store and have filed a lawsuit against Apple.