Odaily Planet Daily reports that 23pds, Chief Information Security Officer at blockchain security firm SlowMist, stated that attackers are exploiting the Darksword vulnerability to bypass iOS security mechanisms via Safari, gaining control of devices and extracting private keys and other data from self-custodial crypto wallets. This vulnerability has previously been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.
The Google Threat Intelligence Group previously disclosed that Darksword initially affected only iOS versions 18.4 to 18.7. 23pds claims the attackers have adapted it to iOS 26.5, but this assessment has not yet been officially verified.
Attacks often begin with social engineering, where users' devices may be compromised with root access and wallet data stolen after clicking malicious links sent via social media or messaging apps. Users should promptly update their mobile operating systems and avoid visiting websites linked by strangers. Additionally, three investors lost nearly $1.8 million in Bitcoin after downloading fake wallet apps from the Apple App Store and have since filed a lawsuit against Apple. (Bitcoin.com News)

