Amid this week's warnings for iPhone users, SlowMist reported that it has not yet confirmed any cases of cryptocurrency theft resulting from a Safari-based attack. The analyzed sample targets iOS 18.4–18.6.2 and exploits vulnerabilities that have already been patched; its effectiveness on iOS 26.5 has not been verified.
The "iOS 13–26.5" Range Called Preliminary
The company stressed that the widely cited "iOS 13–26.5" range of vulnerable versions should be considered preliminary, and that iOS 26.5 should not be assumed affected without reproducible technical evidence. According to SlowMist, the strongest technical confirmation currently concerns iOS 18.4–18.6.2.
Reuse of DarkSword Chain and WYINCC Campaign
The attack vector studied reuses techniques from the previously disclosed DarkSword exploit chain and is not related to the FomoPeek case. Google Threat Intelligence Group disclosed DarkSword in March, noting its use by several groups since at least November 2025. The MistEye threat team, led by CISO 23pds, observed relevant activity in early May and on September 4 published an analysis of the WYINCC campaign, which involved a malicious page promising a free VPS. Opening this page in Safari on an iPhone loaded the exploit without additional clicks. The vulnerabilities used had already been disclosed and patched by Apple.
Access to Keychain and App Data
The sample contains a component for accessing the Apple Keychain, with the ability to extract and decrypt stored information. The code can also access files and shared app data, potentially putting at risk information stored by crypto wallets. However, the sample demonstrates intent and capability to collect data, but does not itself prove successful extraction from every targeted wallet. SlowMist did not execute the entire chain on a real victim device and has not identified any specific, confirmed incident linked to this sample.
Recommendations for iPhone Users
Despite the limitations of the evidence base, SlowMist recommends installing the latest iOS security updates and avoiding suspicious links. Users at higher risk or unable to update promptly are advised to consider Lockdown Mode as an additional measure, though its full effectiveness against this attack is unconfirmed. Those who suspect a key or seed phrase leak are advised to move assets to a new wallet on a "clean" device.
