Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

DarkSword iOS Exploit Targets Crypto Wallets, Google Warns Millions at Risk

A sophisticated zero-click exploit chain targets millions of iOS devices, silently stealing crypto assets through critical zero-day vulnerabilities.

by Saravana Kumar Mahendran
March 21, 2026
in Security & Hacks
0 0
DarkSword iOS Exploit
Share on FacebookShare on Twitter

Google Threat Intelligence has identified DarkSword, a complete iOS exploit chain that deploys six zero-day vulnerabilities to seize full device control on iPhones running iOS 18.4 through 18.7. Users face compromise without installing any app or clicking links beyond simply visiting a compromised website, enabling attackers to extract private keys and credentials from major crypto platforms before self-erasing traces. The campaign, active since November 2025, ties to espionage and surveillance entities and has prompted Apple patches in the latest builds. Security firms urge immediate updates amid confirmed large-scale deployment.

DarkSword iOS Exploit
DarkSword iOS Exploit

DarkSword Chain Revealed

Google Threat Intelligence Group, working alongside iVerify and Lookout, detailed how the JavaScript-based kit fingerprints devices via malicious iframes on watering-hole sites before chaining exploits that escape the Safari sandbox, achieve kernel privileges, and load payloads into system processes like configd and Springboard. The chain specifically enumerates and harvests data from Coinbase, Binance, Kraken, KuCoin, OKX, MEXC, Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe, along with passwords and account details, all within minutes in a hit-and-run operation. iVerify analysis estimates 14.2 percent of iOS users, roughly 221 million devices, on vulnerable builds remain exposed pending updates, with the kit last modified in December 2025 and sharing infrastructure patterns with prior kits like Coruna.

Crypto Theft Alarms

The operation blends espionage with clear financial motives, as payloads rapidly stage and exfiltrate wallet contents before cleanup, leaving victims unaware until funds vanish. Ledger CTO Charles Guillemet explicitly warned the exploit “is already deployed at scale,” highlighting risks for hardware and software wallet holders alike. Lookout researchers noted the stealth surpasses typical malware by injecting directly into privileged services and leveraging potential AI-assisted code, while Google added delivery domains to Safe Browsing lists. This follows broader security efforts by Google, including recent fixes to critical browser vulnerabilities. Unpatched users in targeted regions face immediate credential and asset loss, reinforcing calls for Lockdown Mode activation where full updates prove impossible and underscoring the shift toward mass exploitation of mobile crypto holdings.

Critical Incident Facts

  • iVerify projects up to 270 million broader iOS 18 devices potentially susceptible before accounting for partial fixes in 18.7.x branches.
  • Key zero-day CVE-2026-20700 (dyld PAC bypass) and companion flaws like CVE-2025-14174 were reported to Apple in late 2025 and fully closed in iOS 26.3.1 alongside 18.7.6.
  • Threat clusters include UNC6353 deploying GHOSTBLADE against Ukrainian targets and PARS Defense customers using GHOSTSABER variants regionally.
  • Recommendation remains updating to the newest iOS builds or enabling Lockdown Mode, as Google has integrated protections and collaborated on IOC sharing.
Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: crypto securitygoogle

Related Posts

Cambodia Senate Passes Tough New Law Targeting Technology-Based Fraud
Scams & Fraud

Cambodia Targets Online and Crypto Scams with Tough New Legal Measures

by Saravana Kumar Mahendran
April 4, 2026

Cambodia’s Senate gave final unanimous approval on April 3 to a sweeping new law targeting technology-based fraud, introducing severe prison...

Read moreDetails
X Introduces Auto-Lock Feature to Stop Crypto Scams on First-Time Posts

X Introduces Auto-Lock Feature to Stop Crypto Scams on First-Time Posts

April 3, 2026
Google Warns Quantum Computers Could Break Crypto Security Faster Than Expected

Google Warns Quantum Computers Could Break Crypto Security in the Future

March 31, 2026
Google security update

Google Chrome Security Update High-Severity Gemini AI Vulnerability Patched

March 3, 2026
Next Post
Hong Kong Crypto Scam

Hong Kong Crypto Scam: Retiree Loses HK$6.6 Million in Multi-Stage Fraud

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Philadelphia Musician G. Love Loses $424K in Bitcoin to Fake Ledger App on Apple App Store
  • US Government Transfers 2.4 BTC Worth $177K to Coinbase
  • Federal court stops Arizona crackdown on Kalshi’s event contracts

Categories

  • AI × Crypto
  • Data & Dashboards
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.