Back to top
  • 공유 Share
  • 인쇄 Print
  • 글자크기 Font size
URL copied.

Ledger CTO Warns iPhone Users of DarkSword Crypto Attack

Ledger CTO Warns iPhone Users of DarkSword Crypto Attack.

Ledger Chief Technology Officer Charles Guillemet has warned cryptocurrency users about DarkSword, a sophisticated iPhone exploit capable of stealing sensitive wallet information after victims visit a malicious website through Safari.

Guillemet highlighted the threat on X, warning that the iOS exploit chain can bypass several layers of Apple security and gain extensive access to compromised devices.

“In plaintext, you visit a website and lose your crypto,” Guillemet wrote.

The Ledger executive urged crypto holders who store seed phrases, recovery phrases, or other wallet credentials on their iPhones to reconsider the practice. He recommended using a hardware wallet and keeping iOS updated with Apple's latest security patches.

Google Threat Intelligence Group disclosed DarkSword in March, saying multiple threat actors had used the exploit chain in real-world attacks since at least November 2025. Researchers identified campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.

DarkSword works by combining several iOS vulnerabilities rather than relying on a single security flaw. The attack initially targets JavaScriptCore, Safari's JavaScript engine, allowing malicious code to gain control within the browser process.

It then bypasses Apple's Pointer Authentication Codes, a protection designed to prevent attackers from hijacking program execution, before escaping Safari's browser sandbox. The exploit ultimately targets the iOS kernel, giving attackers access to highly sensitive device information.

Once compromised, an iPhone could expose keychain data, messages, contacts, files, location information, credentials and cryptocurrency wallet data. For crypto investors, storing a wallet recovery phrase in screenshots, Notes or cloud-synced files could therefore create significant risks if the device is breached.

The vulnerabilities identified in the original DarkSword exploit chain are no longer unpatched zero-days. Google said all six security flaws had been fixed by iOS 26.3 and urged users to install available updates.

Apple has since released additional security patches. The more recent iOS 26.6.1 update also addressed separate WebKit vulnerabilities, reinforcing the importance of keeping iPhones updated as attackers continue targeting browser and operating-system weaknesses.

<Copyright ⓒ TokenPost, unauthorized reproduction and redistribution prohibited>

Most Popular

Comment 0

Comment tips

Great article. Requesting a follow-up. Excellent analysis.

0/1000

Comment tips

Great article. Requesting a follow-up. Excellent analysis.
1