SlowMist: It has not yet been confirmed that the iPhone Safari attack led to the theft of cryptocurrency assets
According to Cointelegraph, blockchain security company SlowMist stated that its investigation has not linked the recent security warning regarding iPhone Safari attacks to confirmed cryptocurrency theft incidents. SlowMist told Cointelegraph that it has not independently confirmed any victims affected by the specific Safari attack samples it analyzed, and its strongest technical evidence covers iOS versions 18.4 to 18.6.2. The company claims that the reported impact range of "iOS 13 to 26.5" should be considered a preliminary assessment, and it tends to avoid claiming that iOS 26.5 is affected until reproducible technical evidence is obtained.
SlowMist pointed out that this Safari attack reused previously disclosed DarkSword exploit chain technology, which is independent of another investigation involving malicious components embedded in App Store applications called FomoPeek. Google's Threat Intelligence Group (GTIG) disclosed DarkSword in March, describing it as an iOS exploit chain used by multiple threat actors since November 2025.