SlowMist Has Yet to Confirm Crypto Theft From iPhone Safari Attack
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
SlowMist has not yet confirmed any cryptocurrency theft linked to a recent iPhone Safari attack, despite warnings about malicious webpages possibly exposing crypto private keys and seed phrases. Their investigation analyzed a malicious Safari sample that targeted iOS versions 18.4 through 18.6.2, finding it aimed to access Apple’s Keychain and app data but without directly confirming any compromised victims. SlowMist cautions that the broader reported impact range from iOS 13 to 26.5 remains preliminary and unverified.
Why it matters
The development highlights potential risks to iPhone users’ crypto assets through Safari-based exploits targeting sensitive wallet information. SlowMist’s findings underline the importance of updating devices and considering additional security measures, although the source does not specify the broader market or industry impact beyond user security recommendations.
Key context
The Safari attack reuses exploits from the earlier DarkSword iOS exploit chain disclosed by Google Threat Intelligence Group in March 2023. SlowMist's MistEye team identified the activity in May and released an analysis in September outlining the malicious webpage and its exploit behavior. The vulnerabilities had been previously disclosed and patched by Apple, and this incident is separate from another SlowMist investigation into FomoPeek, an App Store-based threat.
Key numbers and entities
The entities involved include SlowMist, Google Threat Intelligence Group (GTIG), and Apple. The iOS version range specifically investigated by SlowMist is 18.4 to 18.6.2, with a tentative wider range from iOS 13 to 26.5 mentioned but not confirmed. The malicious campaign is known as WYINCC.
What remains unclear
It remains uncertain whether any victims have been successfully compromised by this specific Safari attack sample, as SlowMist did not execute the full exploit chain on real devices or identify confirmed cases of crypto theft. The true scope of affected iOS versions and the effectiveness of Apple’s Lockdown Mode against this attack also have not been conclusively established.