BTCBTC$85,346-0.92%|
ETHETH$2,714.78-1.62%|
USDTUSDT$0.99970-0.00%|
BNBBNB$778.0000-1.58%|
XRPXRP$1.5600+0.98%|
USDCUSDC$0.99977-0.00%|
SOLSOL$116.5000-1.11%|
TRXTRX$0.34156-1.14%|
ZECZEC$1,623.58+6.77%|
FIGR_HELOCFIGR_HELOC$1.0310+1.62%|
HYPEHYPE$94.6300-1.23%|
DOGEDOGE$0.09889-1.35%|
XMRXMR$563.2200-2.97%|
WBTWBT$85.7300-1.14%|
USDSUSDS$0.99986-0.01%|
LINKLINK$12.6500-3.47%|
ADAADA$0.24830-1.20%|
RAINRAIN$0.01271-5.95%|
LEOLEO$8.9800-0.08%|
XLMXLM$0.21220-0.68%|
BCHBCH$354.7500+11.76%|
NEARNEAR$4.6700+2.34%|
UNIUNI$9.6100+1.55%|
USDEUSDE$0.99965+0.00%|
LTCLTC$61.7700+0.25%|
AVAXAVAX$10.6600-2.87%|
DAIDAI$0.99982+0.01%|
CCCC$0.11210-4.97%|
USD1USD1$0.99917-0.00%|
HBARHBAR$0.09417-1.46%|
BTCBTC$85,346-0.92%|
ETHETH$2,714.78-1.62%|
USDTUSDT$0.99970-0.00%|
BNBBNB$778.0000-1.58%|
XRPXRP$1.5600+0.98%|
USDCUSDC$0.99977-0.00%|
SOLSOL$116.5000-1.11%|
TRXTRX$0.34156-1.14%|
ZECZEC$1,623.58+6.77%|
FIGR_HELOCFIGR_HELOC$1.0310+1.62%|
HYPEHYPE$94.6300-1.23%|
DOGEDOGE$0.09889-1.35%|
XMRXMR$563.2200-2.97%|
WBTWBT$85.7300-1.14%|
USDSUSDS$0.99986-0.01%|
LINKLINK$12.6500-3.47%|
ADAADA$0.24830-1.20%|
RAINRAIN$0.01271-5.95%|
LEOLEO$8.9800-0.08%|
XLMXLM$0.21220-0.68%|
BCHBCH$354.7500+11.76%|
NEARNEAR$4.6700+2.34%|
UNIUNI$9.6100+1.55%|
USDEUSDE$0.99965+0.00%|
LTCLTC$61.7700+0.25%|
AVAXAVAX$10.6600-2.87%|
DAIDAI$0.99982+0.01%|
CCCC$0.11210-4.97%|
USD1USD1$0.99917-0.00%|
HBARHBAR$0.09417-1.46%|
News/Security
Security

DarkSword Is Back, and This Time It May Run on iOS 26.5

Bitnxt news cover showing a glowing dark fantasy sword beside an iPhone-style device displaying “26.5,” with Apple-themed visuals in a black-and-gold futuristic setting, and the headline “DarkSword Is Back May Run on iOS 26.5” on a white panel.

Summary :

  • SlowMist says attackers may have adapted the DarkSword exploit chain to compromise devices running iOS 26.5 and extract wallet private keys.

  • Google's Threat Intelligence Group documented the original chain against iOS 18.4 through 18.7, tracked from December 2025 to March 2026.

  • The attack starts with a malicious Safari link, requires no app installation, and can end in root-level device access.

  • Apple patched the six documented DarkSword vulnerabilities, but the claimed iOS 26.5 reach is unconfirmed.

  • Separately, three U.S. investors sued over fake Sparrow Wallet apps that caused $1.835 million in Bitcoin losses.

DarkSword may have jumped to iOS 26.5, and if SlowMist's warning holds, the exploit chain Google documented this spring is now reaching iPhones running Apple's newest software, with crypto wallets as the payload target. SlowMist Chief Information Security Officer 23pds said attackers are using DarkSword to bypass Apple's security controls, gain extensive access to affected iPhones, and collect data from locally installed cryptocurrency wallets. The critical caveat belongs up front: Google Threat Intelligence Group's published research only verified support for iOS 18.4 through 18.7, and the iOS 26.5 claim has not been confirmed by Apple, Google, or any published technical analysis naming the vulnerability involved. Treat it as a credible security firm flagging a moving threat, not a verified breach of the latest iOS.

How the DarkSword chain reaches wallet data

The mechanics Google documented deserve restating because they break the usual mental model of mobile security. DarkSword is a full exploit chain combining six vulnerabilities to compromise a device and deliver separate payloads, and Google tracked related activity from at least December 2025 through March 2026. One flaw used against iOS 18.6 to 18.7 devices, tracked as CVE-2025-43529, affected JavaScriptCore, the engine that processes JavaScript in Safari, and Apple patched it in iOS 18.7.3 and iOS 26.2 after Google reported it. The entry point is social engineering rather than the App Store: a target receives a link through a social network or messaging app, opens it in Safari, and the malicious web content attempts to exploit the browser and other iOS components without the user ever installing an application. If the chain succeeds, the attacker may obtain root-level control, stripping away the sandbox isolation that normally prevents one application from reading another's files and credentials, which places private keys and wallet records on the device at risk.

Google found several groups using DarkSword with different final-stage payloads, collecting account details, messages, browser records, files, location history, saved Wi-Fi data and cryptocurrency wallet information, with victims documented in Saudi Arabia, Turkey, Malaysia and Ukraine. Some activity was associated with commercial surveillance providers and suspected state-linked groups, and researchers found signs that financially motivated actors had also gained access to advanced iPhone exploitation tools, a distribution pattern that echoes the state-and-criminal convergence documented in Japan's wallet-record warnings.

Why DarkSword is the third strike against iOS wallet security this month

The context makes this warning worth taking seriously even pending confirmation. Binance warned on Sept. 19 about FomoPeek, an App Store-distributed app whose versions 1.1 and 1.2 carried a kernel exploitation framework capable of escaping the sandbox and decrypting Keychain data, and before that, Google's Coruna kit showed 23 vulnerabilities across five chains searching iPhones for wallet recovery phrases. DarkSword is the third distinct vector, and the important difference is the delivery route: FomoPeek needed a user to install an app, the fake wallet scams needed a user to type a seed phrase, but DarkSword's documented campaigns begin with a link. No tap-and-hold caution about sideloading helps here, because the documented attack runs through Safari on a fully patched-looking phone, the same one-tap failure mode that made social engineering so productive for scammers on other platforms.

The legal backdrop is also moving. Three investors filed a federal lawsuit alleging fake applications impersonating Sparrow Wallet appeared in the App Store and caused about $1.835 million in Bitcoin losses, and the earlier counterfeit Ledger Live listing was traced to at least $9.5 million stolen from more than 50 victims. Those cases concern fraudulent apps rather than browser exploits, but they share a center: the security of Apple's distribution and platform model, and the financial damage that follows when it fails with a wallet on the device.

What to do about it

The defenses are boring and non-negotiable. Update iOS immediately, since Apple has patched the six vulnerabilities in the original DarkSword chain, and the iOS 26.5 claim, if real, depends on either an unpatched flaw or a new exploit that a current OS version may already mitigate. Do not open unsolicited links from strangers, in any app, ever, which is now wallet hygiene the same way never sharing a seed phrase is. And the structural advice stands regardless of whether the iOS 26.5 report is confirmed: keep meaningful holdings off the phone entirely, on hardware that has never opened a browser link. SlowMist published no victim count or confirmed stolen amount, and Apple and Google have not verified the newest version claim, so calibrate your alarm accordingly. But the trend across FomoPeek, Coruna and DarkSword is verified enough: the iPhone holding your wallet is the target, and the exploits are arriving through every door it has.

#DarkSword#iOS#SlowMist#Exploit#Crypto Security#Safari#Wallets
Aaron Bailey

Author

Aaron Bailey

Blockchain Tech Analyst

Aaron Bailey has covered blockchain technology and decentralized systems for 2 years, focusing on protocol upgrades, Layer 2 developments, and emerging DeFi infrastructure. He breaks down complex technical shifts into clear, actionable insights for Bitnxt readers.

Share: