SlowMist CISO: Full-Chain iOS Exploit Can Steal Crypto Wallet Private Keys and Seed Phrases
AI مارکیٹ کا خلاصہ
SlowMist’s CISO warned that an operational fullchain iOS exploit can silently extract private keys and seed phrases from mobile wallets after a Safari visit, impacting iOS 13–26.5. The ability to reach Keychain and wallet data without user input heightens near-term self-custody risk, potentially accelerating precautionary fund movements and increasing security-driven friction for retail crypto users. The disclosure reinforces broader concerns around mobile-first wallet compromise vectors.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-1.06%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
SlowMist Chief Information Security Officer 23pds issued an urgent alert on Sept. 19, urging iPhone users to update immediately after confirming attackers have put a full-chain iOS exploit into active use. The chain can quietly extract private keys and mnemonic seed phrases from crypto wallets, posing a major risk to self-custodied assets on mobile devices.
According to the disclosure posted on X, the affected range spans iOS 13 through iOS 26.5, though 23pds noted the upper bound is still awaiting final confirmation.
How the chain works
The attack is triggered when a victim visits a malicious webpage in Safari, typically via social engineering or a watering-hole link. The page abuses a memory-corruption flaw in WebKit and JavaScriptCore to gain arbitrary read/write at the JavaScript layer. It then bypasses Pointer Authentication Codes to achieve native code execution, escapes the WebContent sandbox, and escalates to kernel-level root privileges. With that access, an attacker can read the device Keychain and extract wallet app data, including private keys and recovery phrases.
Unlike typical phishing that relies on tricking users into manually entering a seed phrase, this method can succeed with no user action beyond opening a link.
Who is at risk
Because the exploit pulls keys directly from the device, a compromised wallet can't be restored through a password reset. Anyone who obtains the keys can transfer the funds. The risk is especially severe for self-custody users, since device-level key theft leaves no exchange-side recovery path.
The warning comes as concerns rise over mobile and app-store threats targeting retail crypto holders. It also follows a recent case in which Apple was accused of leaving a fake Bitcoin wallet app on the App Store after an $875,000 theft was reported.
What users should do
SlowMist recommends updating iOS to the latest version immediately and avoiding unsolicited Safari links. Users who held a hot wallet on a potentially vulnerable device are advised to generate new keys on a clean, fully updated device and move funds.
SlowMist has not yet released a detailed formal advisory; at the time of writing, 23pds' post remains the primary public disclosure.