SlowMist says it has not confirmed crypto asset theft caused by iPhone Safari attacks
BIBIBI
AT A GLANCE
SlowMist says it has not confirmed crypto asset theft related to the iPhone Safari attacks, and the scope of impact also remains to be verified.
Article
SlowMist: Crypto asset theft from iPhone Safari attacks has not been confirmed
PANews September 25 reports, according to Cointelegraph, SlowMist stated that it has not independently confirmed that recent attack samples targeting iPhone Safari resulted in the theft of any users' crypto assets. The technical evidence currently available primarily concerns iOS 18.4 to 18.6.2. Claims that iOS 13 to 26.5 are all affected remain preliminary. SlowMist stated that the attack reused the previously disclosed DarkSword exploit chain. A malicious webpage can load attack code after a user opens it in Safari, and the samples include the ability to access Apple Keychain and read crypto wallet application data, but this does not prove that attackers successfully extracted information from specific wallets. SlowMist recommends that users promptly update iOS and avoid clicking suspicious links.
SlowMist stated that it has not independently confirmed that recent attack samples targeting iPhone Safari resulted in the theft of any users' crypto assets.
02
The technical evidence currently available to SlowMist primarily concerns iOS 18.4 to 18.6.2。
03
Claims that iOS 13 to 26.5 are all affected remain preliminary.
04
SlowMist stated that the attack reused the previously disclosed DarkSword exploit chain.
05
A malicious webpage can load attack code after a user opens it in Safari.
06
The samples include the ability to access Apple Keychain and read crypto wallet application data, but this does not prove that attackers successfully extracted information from specific wallets.
07
SlowMist recommends that users promptly update iOS and avoid clicking suspicious links.
AI-assisted interpretation
The following is analysis, separate from reported facts. Verify important claims independently.
This report means that the attack samples are capable of accessing Apple Keychain and wallet application data, but “being capable” does not mean that wallet information has already been successfully obtained, much less that crypto theft has occurred. What can currently be confirmed is the existence of a technical risk; actual losses and the full scope of impact have not yet been confirmed.
Why it matters to readers
If a user opens a malicious webpage in Safari, attack code may be loaded and attempt to read sensitive data. Therefore, even though there is no confirmed evidence of asset theft, users who manage crypto wallets on iPhone should remain vigilant against suspicious links.
Beginners should promptly update iOS and avoid clicking links from suspicious sources; at the same time, do not misinterpret “the sample can read data” as “it has been confirmed that someone was robbed.”
Risks and unknowns
It has not yet been confirmed whether the attack resulted in any user's crypto assets being stolen.
It has not yet been proven that the attackers successfully extracted information from a specific wallet.
iOS 13 to 26.5 Whether all were affected remains a preliminary assessment.
The actual scope of the attack's impact on specific wallet applications and user data remains unclear.
Related Developments
Loading event timeline…
Related concepts
Exploit Chain
This term is not in the glossary yet. Browse related concepts in the glossary.