Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

DarkSword iOS Exploit Targets Crypto Wallets, Google Warns Millions at Risk

A sophisticated zero-click exploit chain targets millions of iOS devices, silently stealing crypto assets through critical zero-day vulnerabilities.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
March 21, 2026
in Security & Hacks
0 0
DarkSword iOS Exploit
Share on FacebookShare on Twitter

Google Threat Intelligence has identified DarkSword, a complete iOS exploit chain that deploys six zero-day vulnerabilities to seize full device control on iPhones running iOS 18.4 through 18.7. Users face compromise without installing any app or clicking links beyond simply visiting a compromised website, enabling attackers to extract private keys and credentials from major crypto platforms before self-erasing traces. The campaign, active since November 2025, ties to espionage and surveillance entities and has prompted Apple patches in the latest builds. Security firms urge immediate updates amid confirmed large-scale deployment.

DarkSword iOS Exploit
DarkSword iOS Exploit

DarkSword Chain Revealed

Google Threat Intelligence Group, working alongside iVerify and Lookout, detailed how the JavaScript-based kit fingerprints devices via malicious iframes on watering-hole sites before chaining exploits that escape the Safari sandbox, achieve kernel privileges, and load payloads into system processes like configd and Springboard. The chain specifically enumerates and harvests data from Coinbase, Binance, Kraken, KuCoin, OKX, MEXC, Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe, along with passwords and account details, all within minutes in a hit-and-run operation. iVerify analysis estimates 14.2 percent of iOS users, roughly 221 million devices, on vulnerable builds remain exposed pending updates, with the kit last modified in December 2025 and sharing infrastructure patterns with prior kits like Coruna.

Crypto Theft Alarms

The operation blends espionage with clear financial motives, as payloads rapidly stage and exfiltrate wallet contents before cleanup, leaving victims unaware until funds vanish. Ledger CTO Charles Guillemet explicitly warned the exploit “is already deployed at scale,” highlighting risks for hardware and software wallet holders alike. Lookout researchers noted the stealth surpasses typical malware by injecting directly into privileged services and leveraging potential AI-assisted code, while Google added delivery domains to Safe Browsing lists. This follows broader security efforts by Google, including recent fixes to critical browser vulnerabilities. Unpatched users in targeted regions face immediate credential and asset loss, reinforcing calls for Lockdown Mode activation where full updates prove impossible and underscoring the shift toward mass exploitation of mobile crypto holdings.

Critical Incident Facts

  • iVerify projects up to 270 million broader iOS 18 devices potentially susceptible before accounting for partial fixes in 18.7.x branches.
  • Key zero-day CVE-2026-20700 (dyld PAC bypass) and companion flaws like CVE-2025-14174 were reported to Apple in late 2025 and fully closed in iOS 26.3.1 alongside 18.7.6.
  • Threat clusters include UNC6353 deploying GHOSTBLADE against Ukrainian targets and PARS Defense customers using GHOSTSABER variants regionally.
  • Recommendation remains updating to the newest iOS builds or enabling Lockdown Mode, as Google has integrated protections and collaborated on IOC sharing.
Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: crypto securitygoogle

Related Posts

Google Engineer Accused
Scams & Fraud

Google Engineer Accused of Using Internal Search Data to Win $1.2 Million on Polymarket

by Saravana Kumar Mahendran
May 28, 2026

A Google software engineer is facing federal fraud charges in the United States after prosecutors alleged he used confidential company...

Read moreDetails
Vitalik Buterin

Vitalik Buterin Proposes AI-Assisted Formal Verification as the Final Form of Secure Software Development

May 19, 2026
Ethereum Launches Clear Signing Standard to Prevent Blind Signing Scams

Ethereum Launches Clear Signing Standard to Prevent Blind Signing Scams

May 13, 2026
Tether Freezes $515 Million USDT

Tether Blacklists 371 Addresses and Freezes $515 Million USDT in 30 Days

May 8, 2026
Solv Protocol Migrates to Chainlink CCIP After LayerZero Security Incident

Solv Protocol Migrates to Chainlink CCIP After LayerZero Security Incident

May 8, 2026 - Updated on May 11, 2026
Solana and Google Cloud Launch Pay.sh for Stablecoin Payments to AI Agents

Solana and Google Cloud Launch Pay.sh for Stablecoin Payments to AI Agents

May 6, 2026
Kelp DAO Migrates rsETH from LayerZero to Chainlink CCIP

Kelp DAO Migrates rsETH from LayerZero to Chainlink CCIP After $292M Exploit

May 6, 2026
Next Post
Hong Kong Crypto Scam

Hong Kong Crypto Scam: Retiree Loses HK$6.6 Million in Multi-Stage Fraud

Recommended

  • All
  • News
Samsung Affiliates Buy 4% Stake in Upbit Operator Dunamu as Korean Finance Firms Deepen Crypto Push

Samsung Affiliates Buy 4% Stake in Upbit Operator Dunamu as Korean Finance Firms Deepen Crypto Push

May 28, 2026
Bitcoin Falls to 13th Largest Global Asset as BTC Drops Again Under $74K

Bitcoin Falls to 13th Largest Global Asset as BTC Drops Again Under $74K

May 28, 2026
CFTC Seeks to Vacate Gemini’s $5 Million Settlement in Major Reversal of Crypto Enforcement Case

CFTC Seeks to Vacate Gemini’s $5 Million Settlement in Major Reversal of Crypto Enforcement Case

May 28, 2026
New York Lawsuit Seeks Ownership of 39,069 Dormant Bitcoin Wallets Holding 3.79 Million BTC

New York Lawsuit Seeks Ownership of 39,069 Dormant Bitcoin Wallets Holding 3.79 Million BTC

May 28, 2026
Samsung Affiliates Buy 4% Stake in Upbit Operator Dunamu as Korean Finance Firms Deepen Crypto Push

Samsung Affiliates Buy 4% Stake in Upbit Operator Dunamu as Korean Finance Firms Deepen Crypto Push

May 28, 2026
Bitcoin Falls to 13th Largest Global Asset as BTC Drops Again Under $74K

Bitcoin Falls to 13th Largest Global Asset as BTC Drops Again Under $74K

May 28, 2026
CFTC Seeks to Vacate Gemini’s $5 Million Settlement in Major Reversal of Crypto Enforcement Case

CFTC Seeks to Vacate Gemini’s $5 Million Settlement in Major Reversal of Crypto Enforcement Case

May 28, 2026
New York Lawsuit Seeks Ownership of 39,069 Dormant Bitcoin Wallets Holding 3.79 Million BTC

New York Lawsuit Seeks Ownership of 39,069 Dormant Bitcoin Wallets Holding 3.79 Million BTC

May 28, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Samsung Affiliates Buy 4% Stake in Upbit Operator Dunamu as Korean Finance Firms Deepen Crypto Push
  • Bitcoin Falls to 13th Largest Global Asset as BTC Drops Again Under $74K
  • CFTC Seeks to Vacate Gemini’s $5 Million Settlement in Major Reversal of Crypto Enforcement Case

Categories

  • AI × Crypto
  • Data & Dashboards
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.