Ledger Chief Technology Officer Charles Guillemet has warned cryptocurrency holders about a sophisticated iPhone attack that can compromise a victim's device via a malicious page in the Safari browser.
The warning pertains to DarkSword, an iOS exploit chain that is being used in real-world attacks.
The malware can break through layers of Apple's security protections before gaining deep access to an iPhone.
"In plaintext, you visit a website and lose your crypto," Guillemet wrote on X.
He urged users who keep cryptocurrency seed phrases or other sensitive wallet information on an iPhone to reconsider that setup, recommending a hardware wallet and, crucially, updating iOS.
Google Threat Intelligence Group disclosed DarkSword in March. Multiple threat actors have exploited the vulnerability since at least November 2025.
Researchers identified campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.
The iOS exploit chain can steal sensitive information, including credentials and cryptocurrency wallet data, in a very quick manner.
How the attack works
A normal website opened in Safari does not have any meaningful access to the rest of an iPhone. Web content is usually isolated within Apple's browser sandbox.
DarkSword gets around those protections by chaining multiple vulnerabilities.
It targets JavaScriptCore, the JavaScript engine used by Safari, to gain control inside the browser process, bypasses Apple's Pointer Authentication Codes, or PAC, a security feature intended to make it much harder for attackers to hijack program execution, and eventually escapes Safari's sandbox. Finally, it exploits the iOS kernel, the core part of the operating system, collecting keychains, messages, contacts, files, location information, and, of course, crypto wallet data.
Guillemet specifically warned that attackers could use such access to extract wallet information. Keeping a recovery phrase in screenshots, notes, or cloud-synced files is extremely dangerous.
Update your iPhone
The vulnerabilities in the DarkSword chain disclosed by Google are no longer unpatched zero-days.
Google said all six flaws had been fixed by the release of iOS 26.3. The company urged users to update their devices.
Meanwhile, Apple has continued shipping additional security fixes since then. Its recent iOS 26.6.1 update, for example, addresses a number of separate WebKit vulnerabilities.
en.bitcoinsistemi.com
crypto.news
news.bitcoin.com
cryptoslate.com