Ledger CTO Warns of Safari-Based iPhone Attack Chain Targeting Wallet Data

icon币界网
Share
AI summary iconSummary
Ledger CTO Charles Guillemet highlighted a Safari-based iPhone attack chain called DarkSword, which targets wallet data. The exploit, disclosed in on-chain news by Google in March 2026, had been active since November 2025. Six vulnerabilities were patched in iOS 16.3, with additional fixes released in iOS 16.6.1. Guillemet warned that storing recovery phrases in screenshots or cloud files increases risk. Users are urged to update their systems and secure their mnemonic phrases. Inflation data trends have not impacted this security alert.
CoinDesk reports:

Ledger Chief Technology Officer Charles Guillemet warns cryptocurrency asset users that a malware attack chain named DarkSword is actively being used in real-world attacks. Simply opening a malicious webpage in Safari can compromise the device, potentially leading to the exposure of credentials and wallet data.

The attack begins at the web entry point.

These attacks do not rely on users actively installing applications. Normally, web pages opened in Safari are confined within the browser’s sandbox and cannot access other sensitive data on the iPhone. The danger of DarkSword lies in its ability to chain multiple vulnerabilities together to gradually bypass these restrictions.

The report states that this attack chain first exploits a vulnerability in JavaScriptCore, used by Safari, to gain control of the browser process, then bypasses Apple's Pointer Authentication Codes (PAC) protection, escapes the browser sandbox, and finally exploits an iOS kernel vulnerability to obtain elevated privileges.

Can read various types of sensitive information

If the attack succeeds, the attacker can extract various types of sensitive data from the device, including account credentials, keychain data, text messages, contacts, files, location information, and cryptocurrency wallet-related data.

  • Account credentials and keychain data
  • SMS, contacts, files, and location information
  • Data related to cryptocurrency wallets

Guillemet specifically noted that if users store their mnemonic phrases in screenshots, notes, or cloud-synced files, the risk significantly increases. If such information is accessed, attackers could directly take control of the associated wallet.

The related vulnerability has been fixed.

Google's Threat Intelligence team disclosed DarkSword in March this year, reporting that multiple threat actors had been exploiting this vulnerability chain as early as November 2025, with affected operations targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.

Google stated that the six vulnerabilities involved in this attack chain were patched with the release of iOS 26.3 and are no longer unpatched zero-day vulnerabilities. Since then, Apple has continued to release additional security updates. For example, iOS 26.6.1 also fixed several independent WebKit vulnerabilities.

For iPhone users holding crypto assets, this alert highlights not just a single vulnerability, but also the fact that web portals can serve as entry points for wallet information leaks. Keeping your system updated and avoiding the plaintext storage of recovery phrases on your device have become fundamental security practices.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.