Slow Fog Warns iOS Attack Chain Can Steal Wallet Data

Slow Fog Warns iOS Attack Chain Can Steal Wallet Data

By: WEEX|2026/09/19 11:52:18

WEEX View

  1. The immediate variable is whether Apple or wallet providers issue a formal response, including patches, security guidance, or app-level mitigations for mobile wallet users.
  2. Market participants should also watch whether Slow Fog publishes technical indicators, exploit details, or a narrower affected-version range, since the reported scope remains broad and some key implementation details are still undisclosed.
  3. For exchanges and wallet operators, the operational risk is concentrated around mobile access flows, especially where users open wallet-linked links in Safari or store sensitive credentials on-device.

Until more technical confirmation emerges, the main signal is elevated security risk for older or unpatched iPhones used to manage crypto assets.

Slow Fog warned that a black-market attack chain targeting iOS users can steal private keys, mnemonic phrases, Keychain data and wallet information, describing a Safari-based compromise path that can escalate to root access and advising users on affected iOS versions to upgrade as soon as possible.

According to Slow Fog, the attack chain begins when a user opens a webpage in Safari. The firm said the chain can abuse memory corruption in WebKit and JavaScriptCore to achieve JavaScript-level read and write access, bypass pointer authentication, obtain native call capability, escape the WebContent sandbox, and then escalate privileges at the kernel level.

Slow Fog said that process can ultimately give attackers access to Keychain data and wallet-related information stored on the device, including private keys and mnemonic phrases. The warning framed the issue as a black- and gray-market attack chain rather than a single isolated phishing page or wallet-specific exploit.

The report said affected versions span iOS 13 to 26.5, but additional official technical confirmation on that version range was not included in the available disclosure. No CVE identifiers, Apple advisory references, or public patch details were provided in the warning. Slow Fog’s immediate recommendation was for users to update their systems as quickly as possible.

The broader context is that iOS-targeted crypto theft has increasingly focused on browser-based delivery, social engineering, and sideloading-related abuse rather than direct attacks on a single wallet product. Earlier security warnings tied to older iPhone users also described Safari-driven compromise paths that could expose wallet secrets once a victim interacted with malicious content.

Why It Matters

This warning matters because it shifts crypto security attention back to the mobile device itself. If an attacker can move from a Safari session to system-level access, hardware and app-level wallet protections may be less effective once the operating environment is compromised.

It also underlines a broader market-structure issue for exchanges, wallets, and custodial service providers: a large share of retail crypto activity now depends on smartphones. Security incidents that target iPhone browsing, credential storage, and on-device wallet use can affect account safety, user trust, and support operations even when the underlying blockchain or wallet protocol is not at fault.

Milestones

2026/03/25
2026/05/15
SlowMist CISO 23pds warned that the DarkSword attack program had leaked, saying attackers could use social engineering or watering-hole tactics to lure iOS users and extract device data.
Slow Fog said DarkSword had leaked through public channels and was being used in attacks against crypto wallet holders, with Safari-based malicious webpages used to steal private keys and mnemonic phrases.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

About WEEX View

WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com