๐Ÿ“… Tuesday, 22 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Rantai Kerentanan Darksword Incar iOS 26.5 - Tautan Safari Biasa Bisa Kuras Dompet Kripto

Darksword Exploit Chain Targets iOS 26.5 - Simple Safari Links Can Drain Crypto Wallets

Security firm SlowMist has warned that attackers may have modified the Darksword exploit chain to target iOS 26.5 devices. The exploit pursues a clear objective: extracting private keys from self-custody crypto wallets belonging to iPhone users.

SlowMist Chief Information Security Officer 23pds explained that hackers use the tool to bypass Apple’s security controls. Once breached, attackers gain broad access to the operating system and collect sensitive data from crypto wallets installed locally on the victim’s device.

Six Vulnerabilities in a Single Chain

An analysis report from Google Threat Intelligence Group identified Darksword as a complete iOS exploit chain combining six different vulnerabilities. This code combination allows threat actors to compromise a victim’s device and then deliver separate malicious payloads.

Google researchers tracked the hackers’ activity from December 2025 to March 2026. Their data documented that Darksword was initially designed to support exploits only on iOS 18.4 through 18.7. One of the primary targets was CVE-2025-43529, a vulnerability directly attacking the Safari browser’s JavaScriptCore engine on iOS 18.6 and 18.7.

Apple previously patched the flaw in the JavaScript engine via iOS 18.7.3 and iOS 26.2 updates. Following SlowMist’s new warning regarding Darksword’s expanded operations to iOS 26.5, Apple has yet to release an official confirmation regarding the validity of these claims.

The Darksword hacking operation completely bypasses the conventional method of tricking victims into installing fake apps. Its attack vector originates simply from a link sent via social media or instant messaging apps.

Once a victim opens the link in Safari, the compromised webpage immediately exploits the browser engine and underlying iOS components in the background. The breach occurs silently without requesting any installation permissions, paving the way for hackers to successfully retrieve the victim’s crypto wallet private keys.

This exploit chain underscores that avoiding interaction with unfamiliar links remains the most critical defense for self-custody wallet users. Reported by crypto.news.

Read also: Thousands of Polymarket Accounts Compromised in $10 Million Stolen Card Scheme - CEO Reportedly Opts to Pay Fines Later


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share