SlowMist finds no confirmed crypto theft in iPhone Safari attack
SlowMist says it has not confirmed any victim compromised by the Safari attack sample it analysed, and its strongest evidence covers iOS 18.4 to 18.6.2.

Key points
- SlowMist told CoinTelegraph it has not independently confirmed a crypto theft linked to the Safari attack sample it studied.
- The firm's strongest technical evidence covers iOS 18.4 through 18.6.2, not the wider iOS 13 to 26.5 range cited in reports.
- The campaign reuses techniques from DarkSword, an iOS exploit chain disclosed by Google Threat Intelligence Group in March.
- SlowMist published its analysis of the WYINCC Safari campaign on Sept. 4, tied to a page advertising a free virtual private server.
- The sample included code to access Apple's Keychain and app data, but SlowMist says this does not prove extraction from every wallet.
SlowMist has not confirmed any cryptocurrency theft linked to the iPhone Safari attack behind this week's security warnings, the firm told CoinTelegraph. Its investigation found no independently verified victim compromised by the specific Safari sample it analysed.
Multiple reports this week urged iPhone users to update their devices immediately, warning that malicious Safari pages could expose crypto private keys and seed phrases. Some of those reports cited an affected range from iOS 13 through iOS 26.5.
No confirmed victim
SlowMist said that range should be treated as preliminary. Its strongest technical evidence covers iOS 18.4 through 18.6.2, and it said it prefers to avoid stating that iOS 26.5 is affected until reproducible technical evidence exists.
The Safari attack reuses techniques from DarkSword, an exploit chain disclosed by Google Threat Intelligence Group in March. GTIG described DarkSword as an iOS exploit chain used by multiple threat actors since at least November 2025. SlowMist said MistEye, a threat intelligence team led by its chief information security officer 23pds, first identified the relevant activity in early May.
DarkSword techniques reused
SlowMist published its analysis of the WYINCC Safari campaign on Sept. 4. It identified a malicious webpage advertising a free virtual private server service that loaded exploit code when opened on an iPhone using Safari, without necessarily requiring another click. The vulnerabilities used had already been disclosed and patched by Apple, SlowMist said.
The analysed sample included a component designed to access Apple's Keychain and retrieve and decrypt stored information. The code could also reach app files and shared app data, potentially exposing information held by crypto wallet applications. SlowMist said the sample shows collection capability and intended targets, but does not by itself prove successful extraction from every targeted wallet.
What the sample targeted
SlowMist said it did not run the full chain on a real victim device, so it cannot name a specific victim confirmed as compromised by this exact sample. It still advised users to install the latest iOS security updates and avoid suspicious links. For those who cannot update immediately, it suggested considering Apple's Lockdown Mode, while noting it has not confirmed the feature fully blocks this attack. Users who believe a key or seed phrase was exposed should move assets to a newly generated wallet on a clean device.
The Safari campaign is separate from FomoPeek, another SlowMist investigation involving malicious components embedded in an App Store app.
