Loading prices…
🩸BEARISH

iOS Exploit Can Drain Crypto Keys, SlowMist Warns

The reported attack chain reaches from Safari to kernel-level access, putting private keys and seed phrases stored on affected devices at direct risk.

SlowMist Chief Information Security Officer 23pds urged iOS users to update their devices after warning that cybercriminals have operationalized a full-chain exploit capable of extracting private keys and mnemonic seed phrases. The reported attack path begins with a malicious Safari webpage and ends with root access to device Keychains and local crypto wallet data.

Why it matters

The chain reportedly exploits memory corruption in WebKit and JavaScriptCore to gain arbitrary read and write access, bypasses Pointer Authentication Codes, executes native code, escapes the WebContent sandbox, and escalates privileges through the kernel. That sequence could let attackers reach sensitive wallet material without directly compromising a wallet service.

The potentially affected range spans iOS 13 through iOS 26.5, although final confirmation is still pending. Users holding wallet data or seed phrases on iOS devices should treat updates and secure key storage as urgent priorities.

Market impact

The warning raises the security risk for mobile crypto users rather than pointing to a protocol failure or a weakness in a specific blockchain. If exploitation is confirmed across the reported versions, wallets that rely on device-stored keys could face targeted theft and users may shift toward hardware-based or isolated key storage.

Frequently asked questions

  1. What can the reported iOS exploit access?

    The exploit is reported to reach device Keychains and local crypto wallet application data, including private keys and mnemonic seed phrases.

  2. How does the attack reportedly begin?

    It begins when a target is lured to a malicious webpage through Safari using social engineering or watering-hole tactics.

  3. Which iOS components are targeted in the exploit chain?

    The reported chain targets WebKit and JavaScriptCore memory handling, then bypasses Pointer Authentication Codes before pursuing sandbox escape and kernel privilege escalation.

  4. Which iOS versions may be affected?

    The potentially affected range is reported as iOS 13 through iOS 26.5, although final confirmation is still pending.

  5. What should crypto users do after the warning?

    Users should update their iOS devices immediately and avoid keeping seed phrases or significant private-key material on internet-connected phones.

Source attribution
Aggregated from WuBlockchain · Verified · Last refreshed 1h ago
Open original →