iOS Users Urged to Update: New Exploit Targets Wallet Apps, Data at Risk

September 5, 2026
iOS Users Urged to Update: New Exploit Targets Wallet Apps, Data at Risk
  • The core defense is staying up to date: install the latest iOS updates, keep automatic updates on, enable Background Security Improvements on compatible devices, practice safe browsing to avoid gambling or redirect-heavy sites, and keep recovery phrases offline and separate from cloud or device storage.

  • If exposure is suspected, act quickly by updating the iOS version, confirming the active version at the time of exposure, creating a new wallet on a clean device with a new recovery phrase, moving assets to new addresses, revoking unknown wallet connections, reviewing accounts and sessions, and preserving forensic data if erasing a device; do not pay for seed phrase recovery and rely on legitimate wallet support and offline seed storage.

  • Additional defense steps include avoiding redirect-heavy sites and gambling pages, sticking to Safe Browsing domains, keeping recovery phrases offline, using hardware wallets for larger holdings, and after exposure, updating the iPhone, creating a new wallet on a clean device if confirmed, revoking unknown connections, changing critical passwords from a trusted device, preserving forensic data if needed, and not sharing seed phrases or private keys with anyone claiming recovery services.

  • Two parallel threat analyses describe a wallet-targeting campaign: Socket’s Packagist/theme delivery affecting iOS Safari via WebKit and SlowMist’s WYINCC-infrastructure findings, both linked to the DarkSword exploit family tracked by Google Threat Intelligence since late 2025.

  • Wallet-targeting payloads come from two streams: Socket’s malicious Packagist themes delivering wallet-access payloads and SlowMist’s separate delivery chain; both point to similar exploitation paths for wallets such as Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, OKX in one stream and imToken, TokenPocket, TronLink in another.

  • The attack leveraged two WebKit entry points (CVE-2025-31277 for iOS 18.4–18.5 and CVE-2025-43529 for iOS 18.6), tied to the DarkSword family, with separate SlowMist findings targeting other wallet apps; both streams form part of the same overarching exploit family.

  • The article contains a disclaimer and references to threats and advisories, urging reliance on official patches and cautious recovery procedures.

  • Spyware could exfiltrate Keychain data, messages, contacts, photos, browser cookies, Wi‑Fi passwords, location history, account databases, and wallet files across multiple providers, reflecting wallet-targeted capabilities identified in different delivery chains.

  • Researchers describe a malware campaign that poisoned OphimCMS and KKPhim themes hosted on Packagist, delivering hostile JavaScript to mobile Safari to trigger the iOS exploit chain and reach protected data.

  • Further details show the malware reading Keychain data, messages, contacts, photos, cookies, Wi‑Fi passwords, location history, and wallet databases on iOS devices from XS to newer models running iOS 18.4–18.6.

  • Apple has addressed the exploit chain in later iOS releases; users should update to current versions, with patches available on newer iOS builds as of early September 2026.

Summary based on 2 sources


Get a daily email with more Tech stories

More Stories