SlowMist finds no confirmed crypto theft from iPhone Safari attack

Security firm SlowMist says it has not independently confirmed any cryptocurrency theft from a specific iPhone Safari attack sample it analyzed, despite widespread warnings this week urging users to update their devices.
The firm told Cointelegraph that while the malicious webpage could potentially expose private keys and seed phrases from crypto wallets, its strongest technical evidence covers iOS versions 18.4 through 18.6.2. It cautioned that reports of the attack affecting iOS versions from 13 through to the current 26.5 should be treated as preliminary.
SlowMist’s analysis, published on September 4, identified a campaign dubbed WYINCC that loads exploit code when a malicious page is opened in Safari. The attack reuses techniques from the DarkSword exploit chain disclosed by Google in March. The vulnerabilities used had already been patched by Apple.
The firm found the sample included code designed to access Apple’s Keychain and app files, which could retrieve information stored by wallet applications. However, SlowMist stated the sample “does not by itself prove successful extraction from every targeted wallet” and it has not confirmed a specific victim was compromised by this exact sample.
Despite the lack of confirmed theft, SlowMist still recommends iPhone users install the latest iOS security updates, avoid suspicious links, and consider using Apple’s Lockdown Mode if at elevated risk.
Original reporting: Cointelegraph.com News