iOS Users Urged to Update: New Exploit Targets Wallet Apps, Data at Risk
September 5, 2026
The core defense is staying up to date: install the latest iOS updates, keep automatic updates on, enable Background Security Improvements on compatible devices, practice safe browsing to avoid gambling or redirect-heavy sites, and keep recovery phrases offline and separate from cloud or device storage.
If exposure is suspected, act quickly by updating the iOS version, confirming the active version at the time of exposure, creating a new wallet on a clean device with a new recovery phrase, moving assets to new addresses, revoking unknown wallet connections, reviewing accounts and sessions, and preserving forensic data if erasing a device; do not pay for seed phrase recovery and rely on legitimate wallet support and offline seed storage.
Additional defense steps include avoiding redirect-heavy sites and gambling pages, sticking to Safe Browsing domains, keeping recovery phrases offline, using hardware wallets for larger holdings, and after exposure, updating the iPhone, creating a new wallet on a clean device if confirmed, revoking unknown connections, changing critical passwords from a trusted device, preserving forensic data if needed, and not sharing seed phrases or private keys with anyone claiming recovery services.
Two parallel threat analyses describe a wallet-targeting campaign: Socket’s Packagist/theme delivery affecting iOS Safari via WebKit and SlowMist’s WYINCC-infrastructure findings, both linked to the DarkSword exploit family tracked by Google Threat Intelligence since late 2025.
Wallet-targeting payloads come from two streams: Socket’s malicious Packagist themes delivering wallet-access payloads and SlowMist’s separate delivery chain; both point to similar exploitation paths for wallets such as Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, OKX in one stream and imToken, TokenPocket, TronLink in another.
The attack leveraged two WebKit entry points (CVE-2025-31277 for iOS 18.4–18.5 and CVE-2025-43529 for iOS 18.6), tied to the DarkSword family, with separate SlowMist findings targeting other wallet apps; both streams form part of the same overarching exploit family.
The article contains a disclaimer and references to threats and advisories, urging reliance on official patches and cautious recovery procedures.
Spyware could exfiltrate Keychain data, messages, contacts, photos, browser cookies, Wi‑Fi passwords, location history, account databases, and wallet files across multiple providers, reflecting wallet-targeted capabilities identified in different delivery chains.
Researchers describe a malware campaign that poisoned OphimCMS and KKPhim themes hosted on Packagist, delivering hostile JavaScript to mobile Safari to trigger the iOS exploit chain and reach protected data.
Further details show the malware reading Keychain data, messages, contacts, photos, cookies, Wi‑Fi passwords, location history, and wallet databases on iOS devices from XS to newer models running iOS 18.4–18.6.
Apple has addressed the exploit chain in later iOS releases; users should update to current versions, with patches available on newer iOS builds as of early September 2026.
Summary based on 2 sources
Get a daily email with more Tech stories
Sources

CryptoNews • Sep 5, 2026
How to Secure an iPhone Crypto Wallet Against Malware and Web-Based Exploits
Coin Edition • Sep 5, 2026
How to Secure an iPhone Crypto Wallet Against Malware and Web-Based Exploits