BNB $803.75 +4.67%
XRP $1.51 +7.31%
ETH $2,792.26 +6.13%
BTC $86,902.06 +7.13%
BNB $803.75 +4.67%
XRP $1.51 +7.31%
ETH $2,792.26 +6.13%
BTC $86,902.06 +7.13%
BREAKING
Regulations

Darksword iOS Exploit Threatens Crypto Wallets as Apple Faces $1.8M Lawsuit

Darksword iOS Exploit Hits Crypto Wallets as Apple Faces $1.8M Bitcoin Lawsuit
Darksword iOS Exploit Hits Crypto Wallets as Apple Faces $1.8M Bitcoin Lawsuit

Community Trust ScoreVerified

88%
Real
Verified17 votes
Updated 3 hours ago

A nasty new exploit is going after iPhone users’ crypto wallets. Slowmist’s security team flagged it, and the damage potential is real — especially for anyone holding self-custody crypto on an Apple device.

The exploit goes by the name Darksword. According to Slowmist’s Chief Information Security Officer, 23pds, threat actors are using vulnerabilities baked into the iOS operating system itself to run these attacks. It’s not a simple phishing kit. It’s a full chain that ends with root-level access to your phone — which basically means game over for whatever keys you’ve stored there.

Google Threat Intelligence Group spotted it first, back in March.

Advertisement

Darksword’s Reach Keeps Growing

When Google’s team caught it, Darksword was already active across multiple countries — Saudi Arabia, Turkey, Malaysia, and Ukraine all saw campaigns. At that point, the exploit worked on iOS versions 18.4 through 18.7. Older builds, easier targets. That’s usually where these things stay. But hackers didn’t stop there. They kept working the code until it could hit iOS 26.5, a much newer version. That’s a pretty significant jump and it blows up the pool of people who could get hit.

The attack doesn’t start with some flashy zero-day popup. It starts with a link. Users get lured — through social engineering, probably via messaging apps or social platforms — into clicking something that opens in Safari. Once Safari loads the compromised page, the exploit kicks in. It bypasses security controls, escalates to root permissions, and starts pulling sensitive data off the device. Wallet keys. Gone. The whole self-custody model assumes the device is clean. Darksword makes that assumption dangerous.

Slowmist’s advice is pretty standard but it matters: update your iOS, don’t click links from sources you can’t verify. The problem is that social engineering works precisely because the links look fine. A message from what seems like a contact, a link that looks normal — that’s the entry point. Traditional security hygiene catches some of it. Not all of it.

Apple Faces a Parallel Legal Fight

The Darksword news lands at a rough time for Apple. Three investors have filed a lawsuit against the company claiming losses of roughly $1.8 million in Bitcoin. Their case isn’t about Darksword directly — it’s about a fake wallet app that made it onto the App Store. They downloaded it, trusted it, and lost their Bitcoin. The lawsuit says Apple didn’t enforce adequate security measures when vetting apps for the store.

That’s a separate attack vector but the same basic problem: iOS users losing crypto because something slipped through. Whether it’s a malicious link exploiting a kernel vulnerability or a fraudulent app sitting in an official marketplace, the outcome is the same for the person holding the wallet.

The plaintiffs want compensation. They’re also, probably, hoping to set some kind of precedent around how much responsibility Apple carries when its platform becomes a vector for financial loss. That’s murky legal territory. App store liability cases are hard to win, but $1.8 million in Bitcoin is a number that tends to get a courtroom’s attention.

What Crypto Holders Should Do Right Now

Self-custody is supposed to be the safe option. You control the keys, no exchange counterparty risk, no custodian to get hacked. But Darksword flips that logic. If an attacker can root your phone through a browser exploit, your keys aren’t safe just because they’re on your device. They’re just sitting there waiting to be extracted.

The full scope of Darksword’s effectiveness on the very latest iOS builds isn’t fully verified yet. Unclear exactly how many wallets have been compromised so far — Slowmist hasn’t put a number on it. But the fact that hackers actively updated the exploit to cover newer iOS versions says something about how much effort is going into this campaign. It’s not opportunistic. It’s targeted and it’s evolving.

For now, the practical steps are thin but necessary. Update immediately. Don’t click unsolicited links, especially anything that routes through Safari. Hardware wallets don’t solve the social engineering problem entirely, but they do keep keys off a device that can be rooted remotely.

Apple hasn’t publicly commented on the Darksword vulnerability. The company is also navigating the $1.8 million investor lawsuit, which seeks compensation for losses tied to a fraudulent App Store listing.

Frequently Asked Questions

What is the Darksword exploit and which iOS versions does it affect?

Darksword is a security exploit that targets iOS devices to steal cryptocurrency wallet keys by gaining root access through Safari. It was originally effective on iOS versions 18.4 to 18.7 and has since been adapted to target iOS 26.5.

What lawsuit is Apple currently facing related to crypto losses?

Three investors filed a lawsuit against Apple claiming approximately $1.8 million in Bitcoin losses caused by a fake wallet app available on the App Store, alleging the company failed to enforce adequate security measures.

Why It Matters

The emergence of the Darksword exploit highlights significant vulnerabilities within widely used operating systems, particularly among crypto wallet users who rely on self-custody solutions. This situation raises concerns about the security of digital assets in a market where trust is paramount, potentially leading to a reevaluation of security practices among both users and developers. Additionally, the legal challenges facing Apple could prompt increased scrutiny on the security measures implemented by tech giants, further influencing user confidence and regulatory discussions in the crypto space.

Community Trust IndexModerate Confidence
88%
Real
Real88%12%Fake
17 community signals

Sakamoto Nashi

Nashi Sakamoto is a dedicated crypto journalist from the Virgin Islands who brings expert analysis on Bitcoin, Ethereum, DeFi protocols, and the broader digital asset ecosystem to The Currency Analytics.

Advertisement

Related Stories