Browse categories
AIAltcoinsAnalysisBitcoinCryptoDeFiEthereumExchangesFundingGoldInstitutionalLayer 2MacroMarketsMemecoinsMiningNewsOn-ChainPaymentsRegulationRWASecurityStablecoinsTradFi
BTC$85,579.00 5.13%
ETH$2,737.91 2.75%
BNB$789.15 1.62%
SOL$116.94 4.85%
XRP$1.51 6.51%
ADA$0.2479 6.94%
BTC$85,579.00 5.13%
ETH$2,737.91 2.75%
BNB$789.15 1.62%
SOL$116.94 4.85%
XRP$1.51 6.51%
ADA$0.2479 6.94%

Safari Zero-Day Exploit Targets iPhone Crypto Wallets

A critical full-chain iOS vulnerability allows attackers to steal private keys and seed phrases from crypto wallets via malicious Safari webpages.

A security vulnerability affecting iPhones running iOS 13 through 26.5 is being used to target crypto assets. Blockchain security firm SlowMist confirmed on September 19 that the exploit allows attackers to silently extract private keys and mnemonic seed phrases from software wallets.

The attack is triggered when a user visits a malicious webpage in Safari. The exploit leverages a memory corruption flaw in WebKit and JavaScriptCore to gain an initial foothold. From there, the code bypasses Pointer Authentication Codes, escapes the browser sandbox, and achieves kernel-level access.

With kernel-level control, attackers can access the iOS Keychain where sensitive credentials are stored. SlowMist CISO 23pds issued an alert regarding the threat, which was later amplified by Ledger CTO Charles Guillemet on September 21. Guillemet advised users to update their devices immediately and avoid clicking suspicious links.

This incident follows a similar pattern observed in March 2026, when an exploit kit known as DarkSword targeted iPhones running iOS 18.x to harvest data from apps like Coinbase and MetaMask. While Apple has released patches for several vulnerabilities in the current chain through iOS 26.3, the delay between discovery and user updates remains a primary risk factor.

For self-custody users, the loss of a private key is permanent. Security researchers suggest that those who suspect their device has been compromised should regenerate their keys on a clean device and transfer their funds to a new wallet address. Hardware wallets remain unaffected by this specific Safari-based exploit as they keep keys air-gapped from the device's network connection.

Crypto Research
@cryptoresearch
47.5K members · Free real-time crypto news and price alerts, the moment they break.
Join
980,723
Total members across the Channels
@ChartsSignalsTrading
115K members
Join
@OnlyFinance_Pro
91.0K members
Join
@Nakamoto_Signals
77.0K members
Join
@BlackBlockMarkets
76.2K members
Join
@KryptoNewsInsider
73.3K members
Join
View all channels