星球日报|Sep 21, 2026 19:21
[SlowMist Warns of Darksword Vulnerability Allegedly Capable of Attacking iOS 26.5 and Stealing Wallet Private Keys]
Odaily Planet Daily News: Blockchain security company SlowMist's Chief Information Security Officer, 23pds, stated that attackers are exploiting the Darksword vulnerability to bypass iOS security mechanisms via Safari, taking control of devices and extracting private keys and other data from self-custodial crypto wallets. This vulnerability has previously been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had earlier disclosed that Darksword initially only affected iOS versions 18.4 to 18.7. According to 23pds, attackers have now adapted it to iOS 26.5, though this claim has not yet been officially verified. The attacks typically begin with social engineering, where users click on malicious links sent via social media or messaging apps, potentially granting attackers root access to the device and enabling wallet data extraction. Users are advised to update their phone systems promptly and avoid visiting links sent by strangers. Additionally, three investors have reportedly lost nearly $1.8 million worth of Bitcoin after downloading fake wallet apps from Apple's official App Store and have filed a lawsuit against Apple. (Bitcoin.com News)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink