• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases

Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases

10/10/2026
Distributed Ledger Technology

Ledger probes $86 million wallet drains tied to one Southeast Asian reseller

10/10/2026
Crypto vc funding

Spiko and Nous Research each raise $90M in crypto’s $380M funding week

10/10/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases

Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases

10/10/2026
Distributed Ledger Technology

Ledger probes $86 million wallet drains tied to one Southeast Asian reseller

10/10/2026
Crypto vc funding

Spiko and Nous Research each raise $90M in crypto’s $380M funding week

10/10/2026
Saturday, October 10, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases

Researchers have identified servers hosting the DarkSword and Coruna hacking tools, raising concerns that users running vulnerable iOS versions could lose cryptocurrency and sensitive personal information.

by Moses Edozie
37 minutes ago
in Crypto News
Reading Time: 5 mins read
0
Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases

Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases

Share on FacebookShare on Twitter

Censys researchers say they found five exposed servers running an operational iPhone exploitation platform that searches victims’ Photos and Notes for crypto recovery phrases, with the DarkSword and Coruna toolkits still staged for use against unpatched devices. The firm reported the findings on October 9, 2026.

The campaign combines DarkSword’s exploitation capabilities with Coruna malware, which collects cryptocurrency wallet information and searches personal files for recovery phrases that could allow attackers to access victims’ funds.

The findings highlight the continuing risks facing cryptocurrency users who have not installed security updates addressing the vulnerabilities exploited by the tools. Researchers identified several cryptocurrency applications among the targets, including Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, Uniswap, Bitpie, imToken and OKEx.

Although Apple addressed the vulnerabilities used by DarkSword in iOS 26.3, devices running earlier software versions may remain exposed. The discovery also underscores how exploit tools can continue circulating after security researchers disclose their capabilities and software vendors release patches.

DarkSword spyware targets major cryptocurrency wallets

According to Censys, researchers identified multiple servers containing directories associated with the deployment of DarkSword and Coruna. The infrastructure suggests that the tools remain available for use against vulnerable devices, even months after their capabilities became public.

DarkSword exploits vulnerabilities in Apple’s WebKit browser engine and JavaScriptCore, which processes JavaScript code. The attack chain can use these weaknesses to compromise parts of the iOS operating system, including SpringBoard, the component responsible for managing the Home Screen and launching applications.

Coruna serves a different purpose within the reported attack chain. Its malware payload focuses on collecting information that could help attackers gain access to cryptocurrency wallets.

The distinction is important because exploiting a device and stealing cryptocurrency are separate stages of an attack. DarkSword provides capabilities for compromising vulnerable software, while the associated payload can collect information that may enable financial theft.

The applications identified by researchers span several established cryptocurrency wallet providers and trading platforms. They include Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, Uniswap, Bitpie, imToken and OKEx.

The presence of these applications on the target list does not mean their providers’ systems have been breached. Instead, the threat involves attackers attempting to compromise individual devices and obtain information stored on them.

For cryptocurrency users, the potential consequences extend beyond the immediate theft of wallet credentials. Information collected from a compromised iPhone could help attackers identify accounts, recover wallets or obtain other sensitive information that facilitates unauthorised access.

Recovery phrases expose users to cryptocurrency theft

One of the most concerning capabilities associated with the DarkSword spyware campaign is its reported collection of cryptocurrency wallet recovery phrases.

Recovery phrases, commonly generated when users create self-custody wallets, allow them to restore access to their cryptocurrency holdings. Depending on the wallet’s configuration, anyone who obtains the complete phrase may be able to restore the wallet on another device and control its assets.

Censys researchers said the exploit searches users’ Photos and Notes applications for BIP39 recovery phrases.

BIP39 is a widely used standard for generating mnemonic word sequences that can serve as a backup for cryptocurrency wallets. Users sometimes save these words in screenshots, photographs, documents or personal notes, creating opportunities for attackers who gain access to those files.

The collection of this information means a successful attack could have consequences even after the malware is removed. If attackers obtain a valid recovery phrase, uninstalling a malicious component or updating the operating system does not automatically invalidate the compromised wallet credentials.

The DarkSword spyware threat therefore extends beyond the immediate security of an iPhone. It also raises questions about how cryptocurrency users store sensitive backup information and whether they rely on a single device to protect access to their digital assets.

Earlier, Kaspersky exposed OkoBot, a 20-module malware framework draining crypto wallets via GitHub

Users should avoid storing recovery phrases in ordinary photographs, screenshots, email accounts or cloud-synchronised notes. For substantial cryptocurrency holdings, secure offline storage can reduce the risk of exposing recovery information through a compromised device.

Anyone who suspects that a recovery phrase has been stolen should treat the associated wallet as potentially compromised and consider transferring funds to a newly secured wallet generated in a trusted environment. Such a transfer should only be undertaken after carefully verifying the destination and securing the new recovery phrase.

Older iOS versions remain vulnerable to DarkSword spyware

The latest findings revive concerns first raised earlier in 2026, when security researchers disclosed details of the DarkSword exploit and its ability to compromise vulnerable iPhones.

According to Macworld’s October 9 report, Apple addressed the security flaws exploited by DarkSword in iOS 26.3. Users running older releases of iOS 26, iOS 18 and earlier versions may remain vulnerable if their devices have not received the relevant security fixes.

The findings do not mean that every iPhone running an older operating system has been compromised. Rather, unpatched devices may remain susceptible to attacks that exploit the affected vulnerabilities.

Apple’s security documentation confirms that iOS 26.3 included fixes for security issues affecting supported devices. Users can consult the company’s official iOS 26.3 security documentation to review the published security information.

Updating the operating system remains the most important immediate precaution for users whose devices support the relevant security fixes.

To check for available updates, iPhone users can open Settings, select General, and tap Software Update. Installing the latest compatible release helps ensure that known vulnerabilities addressed by Apple are no longer available as attack paths.

Apple also provides Background Security Improvements, which can deliver certain security protections separately from standard operating system updates. Users can check the feature under Settings, then Privacy & Security.

However, installing updates does not reverse information that may already have been stolen. Cryptocurrency holders should also review wallet activity, assess whether sensitive credentials have been exposed and take appropriate steps to secure compromised accounts.

Crypto holders urged to strengthen iPhone security

The continuing circulation of DarkSword and Coruna highlights a broader challenge for mobile security: publishing information about an exploit and releasing a patch do not immediately eliminate the threat.

Devices that remain unpatched can continue to provide opportunities for attackers, while the availability of previously disclosed tools may allow additional operators to reuse existing capabilities.

For cryptocurrency users, the risks are particularly significant because wallet recovery information can provide direct access to digital assets. Unlike some traditional financial transactions, cryptocurrency transfers may be difficult or impossible to reverse once confirmed on a blockchain.

The DarkSword spyware findings also reinforce the need to separate device security from wallet security. Keeping an iPhone updated reduces exposure to known software vulnerabilities, but users should also protect recovery phrases, avoid suspicious links and downloads, and regularly review wallet transactions for unauthorised activity.

Researchers’ identification of deployment directories provides evidence that infrastructure associated with the tools remains available. However, the discovery alone does not establish that every identified server is actively compromising devices or that every targeted wallet has suffered a loss.

The immediate priority for users is to ensure their devices are running supported, patched software and to avoid keeping sensitive wallet credentials in locations that malware could access.

As the investigation continues, the key concern is whether the operators behind the DarkSword and Coruna tools will continue adapting their infrastructure and targeting devices whose owners have not installed available security updates.

Source; DarkSword/Coruna Open Directory Finding Report

Tags: . crypto newsCrypto hackerscrypto Securitycrypto seed phrasescrypto wallet theftCryptocurrency NewscybersecurityDarkSwordexposed serversiOS securityiPhone malware
Share197Tweet123
Moses Edozie

Moses Edozie

Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases

Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases

10/10/2026
Distributed Ledger Technology

Ledger probes $86 million wallet drains tied to one Southeast Asian reseller

10/10/2026
Crypto vc funding

Spiko and Nous Research each raise $90M in crypto’s $380M funding week

10/10/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.