SlowMist, a blockchain security firm, has warned iPhone users about a sophisticated iOS exploit. The warning is about a threat that could allow attackers to steal cryptocurrency private keys and mnemonic seed phrases. The reported attack uses a chain of vulnerabilities to gain deep system access and potentially extract sensitive data from crypto wallet applications.

Hackers Steal $21M From DeFi Platforms in 1 Month
According to SlowMist’s Chief Information Security Officer, the attackers have developed an operational framework capable of extracting sensitive information from iOS devices. The potentially affected versions reportedly range from iOS 13 to iOS 26.5. However, the full version range remains subject to confirmation.
iPhone Attackers Can Bypass iOS Security Protections
The attack can reportedly begin with social engineering or watering-hole techniques. These techniques usually direct users to malicious webpages through Safari. Once a victim visits the page, attackers can exploit memory corruption vulnerabilities in WebKit and JavaScriptCore (JSC).
The exploit chain can provide attackers with arbitrary read and write capabilities at the JavaScript level. Attackers can then reportedly bypass Pointer Authentication Codes (PAC), achieve native code execution, escape the WebContent sandbox, and escalate privileges to the kernel or root level.
With this level of access, attackers can extract private keys and seed phrases from the device’s Keychain and local crypto wallet applications.
SlowMist Urges Users to Update iOS Devices
SlowMist has urged iOS users to install the latest available software updates to reduce exposure to known vulnerabilities. Users are also advised to avoid suspicious or unsolicited links that could direct them to malicious webpages.
For cryptocurrency holders, security researchers and industry participants have additionally recommended minimizing the storage of sensitive recovery information on everyday internet-connected devices. Hardware wallets and offline storage can provide an additional layer of protection.
The reported vulnerability highlights the potential security risks crypto users face when private keys or seed phrases are stored on mobile devices. Users should update their iPhones and other phones to the latest available version and must avoid suspicious links.

