WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Bitcoin & Crypto SINGLE SOURCE

SlowMist has yet to confirm crypto theft from iPhone Safari attack

Stacks of Bitcoin coins with a financial market chart in the background, depicting cryptocurrency trading.
Illustrative photo.Photo by Rafael Minguet Delgado on PexelsApple logo shown for identification only; no affiliation with or endorsement of WORLDTECH is implied.

What happened

The analyzed Safari sample targets iOS 18.4–18.6.2 using previously patched flaws, while its effectiveness on iOS 26.5 remains unverified. An iPhone Safari attack behind recent security warnings hasn’t yet been linked to a confirmed cryptocurrency theft in SlowMist’s investigation.

SlowMist told Cointelegraph that it has not independently confirmed a victim compromised by the specific Safari attack sample it analyzed, while its strongest technical evidence covers iOS 18.4 through 18.6.2. The Safari attack reuses techniques from a previously disclosed DarkSword exploit chain and is separate from FomoPeek, another SlowMist investigation involving malicious components embedded in an App Store app.

SlowMist finds DarkSword reuse Google Threat Intelligence Group (GTIG) disclosed DarkSword in March, describing it as an iOS exploit chain that had been used by multiple threat actors since at least November 2025. The company said the “iOS 13 to 26.5” range should be treated as preliminary. 4, identifying a malicious webpage advertising a free virtual private server service.

Sources & evidence