SlowMist finds no confirmed crypto theft from iPhone Safari attack
Safari warnings spread, but no theft is confirmed yet
Security firm SlowMist says it has not yet linked the recent iPhone Safari attack warnings to any confirmed cryptocurrency theft.
Reports this week urged iPhone users to update their devices right away. They warned that malicious Safari pages could expose crypto private keys and seed phrases, the secret codes that control a crypto wallet. Some of those reports cited a version range from iOS 13 through iOS 26.5.
What SlowMist told Cointelegraph
- SlowMist has not independently confirmed a victim compromised by the specific Safari sample it analyzed.
- Its strongest technical evidence covers iOS 18.4 through 18.6.2.
- The company said the wider iOS 13 to 26.5 range should be treated as preliminary. It said it prefers to avoid stating that iOS 26.5 is affected until there is reproducible technical evidence.
- The attack reuses techniques from the previously disclosed DarkSword exploit chain. SlowMist says it is separate from FomoPeek, another of its investigations involving malicious components embedded in an App Store app.
How the WYINCC Safari campaign worked
Google Threat Intelligence Group disclosed DarkSword in March. It described the tool as an iOS exploit chain used by multiple threat actors since at least November 2025.
SlowMist said MistEye, a threat intelligence team led by its chief information security officer, 23pds, first identified the relevant activity in early May. On Sept. 4, SlowMist published its analysis of the WYINCC Safari campaign, which involved a malicious webpage advertising a free virtual private server service.
SlowMist said the page loaded the exploit code when opened on an iPhone using Safari, without necessarily requiring another click from the user. The vulnerabilities used in the chain had already been disclosed and patched by Apple, according to the company.
What the malicious Safari code could reach
SlowMist found that the sample it analyzed included a component designed to access Apple's Keychain, the system Apple uses to store passwords and keys, and to retrieve and decrypt information stored there. The code could also reach app files and shared app data, potentially exposing information stored by crypto wallet applications.
SlowMist said the sample shows the collection capability and the intended targets, but does not by itself prove successful extraction from every targeted wallet. It added that it did not execute the full chain on a real victim device, so it cannot identify a specific victim whose device it independently confirmed was compromised by that exact sample.
SlowMist's advice for iPhone users
SlowMist advised iPhone users to install the latest iOS security updates available for their devices and to avoid suspicious links.
For users who cannot update immediately or face higher risk, the company suggested considering Apple's Lockdown Mode as an additional defense. It cautioned that it has not confirmed the feature completely blocks this specific Safari attack.
SlowMist also urged users who believe a wallet key or seed phrase may have been exposed to move their assets to a newly generated wallet on a clean device instead of continuing to use potentially compromised credentials.
What is confirmed
- SlowMist analyzed a malicious Safari sample and published its analysis of the WYINCC campaign on Sept. 4.
- Its strongest technical evidence covers iOS 18.4 through 18.6.2, using flaws that Apple had already disclosed and patched.
- The sample included a component aimed at Apple Keychain data, app files and shared app data.
- The attack reuses DarkSword techniques and is separate from the FomoPeek investigation.
What is still unclear
- Whether any specific person lost crypto to this exact sample. SlowMist says it has not confirmed a victim.
- Whether iOS 26.5 is affected. SlowMist calls the wider version range preliminary and says it needs reproducible technical evidence.
- Whether Lockdown Mode fully blocks the attack. SlowMist says it has not confirmed that.
Why the gap in evidence matters
The analyzed sample was built to reach Keychain data, app files and shared app data, which SlowMist says could expose information stored by crypto wallet apps. The open question is scope: the company's technical evidence is strongest for iOS 18.4 to 18.6.2, while the much wider version range circulating in reports has not been verified.