'Visit Website and Lose Your Crypto': Ledger Exec Issues Warning About Safari Attack

Lời nói đầu:How the attack worksUpdate your iPhoneLedger Chief Technology Officer Charles Guillemet has warned cryptocurrency holders about a sophisticated iPhone

  • How the attack works
  • Update your iPhone

Ledger Chief Technology Officer Charles Guillemet has warned cryptocurrency holders about a sophisticated iPhone attack that can compromise a victims device via a malicious page in the Safari browser.

The warning pertains to DarkSword, an iOS exploit chain that is being used in real-world attacks.

The malware can break through layers of Apples security protections before gaining deep access to an iPhone.

Bitcoin Reclaims Key Weekly Level for First Time in 45 Weeks

Zcash (ZEC), Hyperliquid (HYPE), Avalanche (AVAX) and Shiba Inu (SHIB) Price Analysis for September 21: Pivotal Moment for Bullish Market

“In plaintext, you visit a website and lose your crypto,” Guillemet wrote on X.

He urged users who keep cryptocurrency seed phrases or other sensitive wallet information on an iPhone to reconsider that setup, recommending a hardware wallet and, crucially, updating iOS.

You Might Also Like

Google Threat Intelligence Group disclosed DarkSword in March. Multiple threat actors have exploited the vulnerability since at least November 2025.

Researchers identified campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.

The iOS exploit chain can steal sensitive information, including credentials and cryptocurrency wallet data, in a very quick manner.

How the attack works

A normal website opened in Safari does not have any meaningful access to the rest of an iPhone. Web content is usually isolated within Apples browser sandbox.

DarkSword gets around those protections by chaining multiple vulnerabilities.

It targets JavaScriptCore, the JavaScript engine used by Safari, to gain control inside the browser process, bypasses Apple‘s Pointer Authentication Codes, or PAC, a security feature intended to make it much harder for attackers to hijack program execution, and eventually escapes Safari’s sandbox. Finally, it exploits the iOS kernel, the core part of the operating system, collecting keychains, messages, contacts, files, location information, and, of course, crypto wallet data.

Guillemet specifically warned that attackers could use such access to extract wallet information. Keeping a recovery phrase in screenshots, notes, or cloud-synced files is extremely dangerous.

Update your iPhone

The vulnerabilities in the DarkSword chain disclosed by Google are no longer unpatched zero-days.

Miễn trừ trách nhiệm

Các ý kiến ​​trong bài viết này chỉ thể hiện quan điểm cá nhân của tác giả và không phải lời khuyên đầu tư. Thông tin trong bài viết mang tính tham khảo và không đảm bảo tính chính xác tuyệt đối. Nền tảng không chịu trách nhiệm cho bất kỳ quyết định đầu tư nào được đưa ra dựa trên nội dung này.
Bài viết trước

Nhà đầu tư nhỏ lẻ XRP chuyển 663% token lên Binance nhưng gần như không bán

Bài tiếp theo

MicroStrategy kết thúc hai tuần tạm dừng với 950 Bitcoin: Động cơ mua vào đang chững lại?