'Visit Website and Lose Your Crypto': Ledger Exec Issues Warning About Safari Attack

요약:How the attack worksUpdate your iPhoneLedger Chief Technology Officer Charles Guillemet has warned cryptocurrency holders about a sophisticated iPhone

  • How the attack works
  • Update your iPhone

Ledger Chief Technology Officer Charles Guillemet has warned cryptocurrency holders about a sophisticated iPhone attack that can compromise a victims device via a malicious page in the Safari browser.

The warning pertains to DarkSword, an iOS exploit chain that is being used in real-world attacks.

The malware can break through layers of Apples security protections before gaining deep access to an iPhone.

Bitcoin Reclaims Key Weekly Level for First Time in 45 Weeks

Zcash (ZEC), Hyperliquid (HYPE), Avalanche (AVAX) and Shiba Inu (SHIB) Price Analysis for September 21: Pivotal Moment for Bullish Market

“In plaintext, you visit a website and lose your crypto,” Guillemet wrote on X.

He urged users who keep cryptocurrency seed phrases or other sensitive wallet information on an iPhone to reconsider that setup, recommending a hardware wallet and, crucially, updating iOS.

You Might Also Like

Google Threat Intelligence Group disclosed DarkSword in March. Multiple threat actors have exploited the vulnerability since at least November 2025.

Researchers identified campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.

The iOS exploit chain can steal sensitive information, including credentials and cryptocurrency wallet data, in a very quick manner.

How the attack works

A normal website opened in Safari does not have any meaningful access to the rest of an iPhone. Web content is usually isolated within Apples browser sandbox.

DarkSword gets around those protections by chaining multiple vulnerabilities.

It targets JavaScriptCore, the JavaScript engine used by Safari, to gain control inside the browser process, bypasses Apple‘s Pointer Authentication Codes, or PAC, a security feature intended to make it much harder for attackers to hijack program execution, and eventually escapes Safari’s sandbox. Finally, it exploits the iOS kernel, the core part of the operating system, collecting keychains, messages, contacts, files, location information, and, of course, crypto wallet data.

Guillemet specifically warned that attackers could use such access to extract wallet information. Keeping a recovery phrase in screenshots, notes, or cloud-synced files is extremely dangerous.

Update your iPhone

The vulnerabilities in the DarkSword chain disclosed by Google are no longer unpatched zero-days.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

XRP 보유자, 바이낸스로 663% 토큰 이동…거의 매도 안 됐다

다음

Strategy, 7,600만 달러에 비트코인 950개 매입하고 STRC 1억 7,400만 달러어치 재매입