SlowMist security chief 23pds is warning that iPhones may be vulnerable to a new Safari zero-day capable of exposing crypto wallet credentials, private keys and Keychain data, a claim that has drawn attention from Ledger CTO Charles Guillemet but remains unconfirmed by Apple, Google or iVerify as of September 22, 2026.
However, the claimed vulnerability affecting iOS 26.5 has not been independently confirmed by Apple, Google or iVerify, while the previously documented DarkSword exploit chain was patched in earlier iOS releases.
Safari zero-day warning puts crypto wallets under scrutiny
The latest concern centers on claims that attackers have developed an exploit chain capable of moving from Safari’s WebKit and JavaScriptCore components through the browser sandbox and into deeper parts of iOS. According to reporting on the SlowMist warning, the alleged chain could ultimately expose private keys, mnemonic recovery phrases and information stored in Apple’s Keychain.
That makes the Safari zero-day particularly relevant to cryptocurrency users who keep wallet credentials, screenshots, notes or cloud-synchronized copies of recovery phrases on their phones. A successful compromise of an iPhone can potentially turn information stored locally into a direct security problem for a self-custody wallet.
SlowMist’s warning reportedly listed devices running iOS 13 through iOS 26.5 as potentially affected. The claim, however, needs to be separated from the earlier DarkSword research. The Safari zero-day described in March involved a documented six-vulnerability chain affecting specific iOS 18 versions, and researchers said those vulnerabilities had subsequently been patched.
DarkSword showed how Safari could become an entry point
Google Threat Intelligence Group, Lookout and iVerify disclosed DarkSword in March 2026 after observing attacks dating back to November 2025. Researchers described a full-chain iOS exploit that could begin with a malicious webpage and progress through multiple security layers.
Lookout said DarkSword targeted iPhones running iOS 18.4 through 18.6.2 and was designed to extract sensitive information, including credentials and cryptocurrency wallets. The company described the attack as a “hit-and-run” operation because data could be collected quickly before the malware attempted to remove evidence.
“DarkSword, a sophisticated, full iOS exploit chain and infostealer,” — Lookout, in its March 18 security disclosure.
iVerify separately said the exploit chain comprised six vulnerabilities and could move from WebKit into deeper parts of the operating system. The company reported that the vulnerabilities were patched progressively, with the final fixes arriving in iOS 26.3.
“The second mass attack disclosed in two weeks proves what many of us have been saying, that mobile attacks are widespread and no longer something businesses and governments can ignore,” — Rocky Cole, co-founder and COO of iVerify.
The earlier Safari zero-day activity therefore provides important context for the current warning. It demonstrates that malicious web content can serve as the starting point for a much broader device compromise when multiple vulnerabilities are chained together.
Latest iOS 26.5 claim remains unverified
The main uncertainty surrounding the current Safari zero-day alert is whether the older DarkSword chain has actually been adapted to compromise newer iOS releases.
Google Threat Intelligence said all vulnerabilities used in DarkSword had been patched by iOS 26.3 and urged users to update their devices. Lookout likewise said devices running iOS 18.7.3 or later, and iOS 26.3 or later, were not susceptible to the documented DarkSword vulnerabilities.
Apple’s subsequent security releases have also addressed additional WebKit flaws. Its September security documentation lists multiple WebKit vulnerabilities affecting iPhones, including issues involving memory corruption, malicious web content and sensitive information disclosure. Apple advises users to install security updates but generally does not discuss or confirm security issues until an investigation has taken place and patches are available.
This distinction matters because the current Safari zero-day warning does not come with a publicly documented CVE, exploit sample or independent technical confirmation showing that iOS 26.5 remains vulnerable to the same DarkSword vulnerabilities. Security reporting has consequently treated the newer claim as an alert that warrants attention rather than as proof that every updated iPhone can currently be compromised.
Crypto users urged to reduce exposed wallet data
For crypto users, the Safari zero-day discussion highlights a broader security issue: the concentration of sensitive wallet information on general-purpose devices.
Ledger CTO Charles Guillemet warned cryptocurrency holders about the consequences of storing recovery information on an iPhone.
“In plaintext, you visit a website and lose your crypto,” — Charles Guillemet, Ledger CTO, in a post on X.
Guillemet has urged users to keep iOS updated and reconsider storing seed phrases or other wallet credentials in screenshots, notes or cloud-synchronized files. If an attacker gains sufficiently deep access to a device, those locations can provide additional targets beyond the wallet application itself.
For now, the documented DarkSword vulnerabilities have been patched in supported iOS releases, while the newer claim concerning iOS 26.5 remains unverified. The practical response is therefore straightforward: install the latest available Apple security update, avoid suspicious links and keep recovery phrases away from ordinary phone storage where possible.