A warning has emerged that crypto wallet information could be stolen simply by opening a malicious web page in Safari on an iPhone.
On Sept. 21 local time, blockchain outlet U.Today reported that Ledger Chief Technology Officer Charles Guillemet said an iOS attack chain called “Darksword” targeting iPhone users is being used in real attacks and urged crypto holders to be cautious.
Guillemet wrote on X, formerly Twitter, that the threat means, in plain terms, “you lose cryptocurrency by visiting a website.” He said users who store seed phrases or sensitive wallet-related information on an iPhone should review how they store it. He recommended using a hardware wallet and stressed the importance of updating iOS to the latest version.
The attack is described as bypassing Safari’s typical isolation architecture through a chained set of vulnerabilities. Web pages normally operate only in a restricted environment within the browser, but Darksword is known to first target Safari’s JavaScript engine, JavaScriptCore, then proceed through bypassing Apple’s Pointer Authentication Code security mechanism, escaping the Safari sandbox and penetrating the iOS kernel.
In the process, attackers can access wallet data along with the device’s keychain, messages, contacts, files and location information. Guillemet warned that attackers can use those privileges to extract wallet information. He also said storing recovery phrases as screenshots, notes or files synced to the cloud is very risky.
Darksword is an iOS vulnerability chain disclosed in March by Google Threat Intelligence Group. The vulnerabilities were assessed to have been exploited by multiple threat actors since at least November 2025. Researchers also identified attack campaigns targeting users in Saudi Arabia, Turkey, Malaysia and Ukraine.
The attacks are also fast. Researchers believed the iOS attack chain can steal sensitive information such as credentials and crypto wallet data in a very short time. The warning says that the more wallet recovery information is stored on an iPhone, the wider the damage could be, and that it could spread beyond simple phishing into a device security issue.
However, six Darksword-related vulnerabilities disclosed by Google do not remain unpatched zero-day issues. Google said all flaws were fixed by the time iOS 26.3 was released. That was why it urged users to update their devices quickly.
Apple has also continued to issue additional security patches. The recently released iOS 26.6.1 fixed several separate WebKit vulnerabilities. As a result, keeping iOS up to date and storing sensitive information separately are emerging as key countermeasures for users who also use iPhones to store crypto wallet information.