Researchers warn of Safari zero-day exploit targeting Apple iPhones and crypto wallets

apple logo

Researchers warn of Safari zero-day exploit targeting Apple iPhones and crypto wallets

A full-chain iOS exploit can silently extract private keys and seed phrases from crypto wallets, affecting devices running iOS 13 through 26.5.

A critical security vulnerability is making its way through Apple’s mobile ecosystem, and the target is not just your photos or messages. Blockchain security firm SlowMist confirmed on September 19 that an active, full-chain exploit is being used against iPhones running iOS 13 through 26.5, with the specific goal of stealing private keys and mnemonic seed phrases from crypto wallets.

The attack arrives through something most people do dozens of times a day: visiting a webpage in Safari. That casual tap on a link is all it takes.

How the exploit actually works

The attack chain begins with a malicious Safari webpage that exploits a memory corruption flaw in WebKit, the browser engine Apple uses across its products, and its JavaScript runtime environment, JavaScriptCore. Once that initial foothold is established, the attacker’s code does not stop there.

From that entry point, the exploit navigates through a sequence of escalating privileges. It bypasses Pointer Authentication Codes, which are Apple’s built-in mechanism for verifying that software instructions have not been tampered with. It then breaks out of the browser’s sandbox, the isolated environment designed to keep web content from touching the rest of the operating system. From there, it escalates all the way to kernel-level access.

Advertisement

Kernel access is the highest level of control possible on a device. With it, an attacker can reach the iOS Keychain, which is where sensitive credentials, including crypto wallet keys, are stored. For self-custody users, that means private keys and seed phrases can be quietly copied off a device without the owner ever knowing.

SlowMist’s CISO, known as 23pds, issued the public alert. Two days later, on September 21, Ledger CTO Charles Guillemet amplified the warning, urging users to update iOS immediately and avoid clicking unfamiliar links.

What makes this particularly alarming for crypto holders is the nature of the loss. If your email password gets stolen, you reset it. If your private key gets stolen, there is no reset. Whoever has that key has the funds, permanently.

A pattern, not an isolated incident

This is not the first time iOS has been weaponized against crypto users in 2026. In March, security researchers flagged an exploit kit called DarkSword, which chained together six separate vulnerabilities to harvest data from iPhones running iOS 18.x variants. That kit specifically targeted popular crypto apps including Coinbase and MetaMask, pulling sensitive data from compromised devices.

Apple has patched several vulnerabilities in this exploit chain through iOS 26.3, but the window between discovery, patching, and the average user actually updating their device is where attackers operate.

For users who rely on software wallets stored on their iPhones, the risk is direct. A hardware wallet, by contrast, stores private keys on a dedicated physical device that never connects to the internet, meaning a Safari exploit cannot reach them. The recommendation from security researchers for users who suspect their device may have been exposed is to regenerate keys entirely on a clean device, a process that also requires moving funds to a new wallet address.

What this means for self-custody users

A hardware wallet addresses the threat at the architectural level, keeping keys air-gapped from any network connection. But software wallets on general-purpose smartphones share attack surface with every app, webpage, and piece of code running on that device.

For now, the immediate steps are straightforward. Update iOS to the latest available version, avoid clicking links from unknown sources, and consider whether a software wallet on a general-purpose smartphone is the right place to hold significant crypto assets. If there is any suspicion of exposure, the security community’s consensus is clear: treat the device as compromised and regenerate keys on clean hardware.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Researchers warn of Safari zero-day exploit targeting Apple iPhones and crypto wallets
Researchers warn of Safari zero-day exploit targeting Apple iPhones and crypto wallets

A full-chain iOS exploit can silently extract private keys and seed phrases from crypto wallets, affecting devices running iOS 13 through 26.5.

apple logo

A critical security vulnerability is making its way through Apple’s mobile ecosystem, and the target is not just your photos or messages. Blockchain security firm SlowMist confirmed on September 19 that an active, full-chain exploit is being used against iPhones running iOS 13 through 26.5, with the specific goal of stealing private keys and mnemonic seed phrases from crypto wallets.

The attack arrives through something most people do dozens of times a day: visiting a webpage in Safari. That casual tap on a link is all it takes.

How the exploit actually works

The attack chain begins with a malicious Safari webpage that exploits a memory corruption flaw in WebKit, the browser engine Apple uses across its products, and its JavaScript runtime environment, JavaScriptCore. Once that initial foothold is established, the attacker’s code does not stop there.

From that entry point, the exploit navigates through a sequence of escalating privileges. It bypasses Pointer Authentication Codes, which are Apple’s built-in mechanism for verifying that software instructions have not been tampered with. It then breaks out of the browser’s sandbox, the isolated environment designed to keep web content from touching the rest of the operating system. From there, it escalates all the way to kernel-level access.

Advertisement

Kernel access is the highest level of control possible on a device. With it, an attacker can reach the iOS Keychain, which is where sensitive credentials, including crypto wallet keys, are stored. For self-custody users, that means private keys and seed phrases can be quietly copied off a device without the owner ever knowing.

SlowMist’s CISO, known as 23pds, issued the public alert. Two days later, on September 21, Ledger CTO Charles Guillemet amplified the warning, urging users to update iOS immediately and avoid clicking unfamiliar links.

What makes this particularly alarming for crypto holders is the nature of the loss. If your email password gets stolen, you reset it. If your private key gets stolen, there is no reset. Whoever has that key has the funds, permanently.

A pattern, not an isolated incident

This is not the first time iOS has been weaponized against crypto users in 2026. In March, security researchers flagged an exploit kit called DarkSword, which chained together six separate vulnerabilities to harvest data from iPhones running iOS 18.x variants. That kit specifically targeted popular crypto apps including Coinbase and MetaMask, pulling sensitive data from compromised devices.

Apple has patched several vulnerabilities in this exploit chain through iOS 26.3, but the window between discovery, patching, and the average user actually updating their device is where attackers operate.

For users who rely on software wallets stored on their iPhones, the risk is direct. A hardware wallet, by contrast, stores private keys on a dedicated physical device that never connects to the internet, meaning a Safari exploit cannot reach them. The recommendation from security researchers for users who suspect their device may have been exposed is to regenerate keys entirely on a clean device, a process that also requires moving funds to a new wallet address.

What this means for self-custody users

A hardware wallet addresses the threat at the architectural level, keeping keys air-gapped from any network connection. But software wallets on general-purpose smartphones share attack surface with every app, webpage, and piece of code running on that device.

For now, the immediate steps are straightforward. Update iOS to the latest available version, avoid clicking links from unknown sources, and consider whether a software wallet on a general-purpose smartphone is the right place to hold significant crypto assets. If there is any suspicion of exposure, the security community’s consensus is clear: treat the device as compromised and regenerate keys on clean hardware.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.