Ledger Chief Technology Officer Charles Guillemet warns cryptocurrency asset users that a malware attack chain named DarkSword is actively being used in real-world attacks. Simply opening a malicious webpage in Safari can compromise the device, potentially leading to the exposure of credentials and wallet data.
The attack begins at the web entry point.
These attacks do not rely on users actively installing applications. Normally, web pages opened in Safari are confined within the browser’s sandbox and cannot access other sensitive data on the iPhone. The danger of DarkSword lies in its ability to chain multiple vulnerabilities together to gradually bypass these restrictions.
The report states that this attack chain first exploits a vulnerability in JavaScriptCore, used by Safari, to gain control of the browser process, then bypasses Apple's Pointer Authentication Codes (PAC) protection, escapes the browser sandbox, and finally exploits an iOS kernel vulnerability to obtain elevated privileges.
Can read various types of sensitive information
If the attack succeeds, the attacker can extract various types of sensitive data from the device, including account credentials, keychain data, text messages, contacts, files, location information, and cryptocurrency wallet-related data.
- Account credentials and keychain data
- SMS, contacts, files, and location information
- Data related to cryptocurrency wallets
Guillemet specifically noted that if users store their mnemonic phrases in screenshots, notes, or cloud-synced files, the risk significantly increases. If such information is accessed, attackers could directly take control of the associated wallet.
The related vulnerability has been fixed.
Google's Threat Intelligence team disclosed DarkSword in March this year, reporting that multiple threat actors had been exploiting this vulnerability chain as early as November 2025, with affected operations targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.
Google stated that the six vulnerabilities involved in this attack chain were patched with the release of iOS 26.3 and are no longer unpatched zero-day vulnerabilities. Since then, Apple has continued to release additional security updates. For example, iOS 26.6.1 also fixed several independent WebKit vulnerabilities.
For iPhone users holding crypto assets, this alert highlights not just a single vulnerability, but also the fact that web portals can serve as entry points for wallet information leaks. Keeping your system updated and avoiding the plaintext storage of recovery phrases on your device have become fundamental security practices.


