Active iPhone Exploit Targets Crypto Wallets and Recovery Phrases
A security threat targeting older Apple (AAPL) iPhone models remains active, exposing cryptocurrency holders to potential theft. Cybercriminals are using an exploit kit called DarkSword to install Coruna malware on vulnerable devices. This malicious software specifically targets major digital wallets, including Coinbase (COIN), MetaMask, Uniswap, and Trust Wallet, to extract sensitive credential data.
The exploit functions by taking advantage of security flaws in Apple's WebKit and JavaScriptCore systems. Once a device is compromised, the malware can search through saved photos and notes to locate BIP39 recovery phrases. Because these phrases allow hackers to recreate and access wallets from any device, users risk losing their digital assets even if they retain possession of their physical phones.
Security patches have already been released to address these vulnerabilities. The security flaws are resolved in iOS version 26.3, but devices running iOS 26.2 or older, including older versions of iOS 18, remain at risk. Investors should ensure their mobile operating systems are fully updated to the latest version to protect their funds.
Key points
- An active exploit kit known as DarkSword is deploying malware to steal sensitive data from cryptocurrency wallets on older iPhones.
- The Coruna malware scans compromised devices for BIP39 wallet recovery phrases stored in photos and notes.
- Targeted wallet applications include Coinbase, MetaMask, Uniswap, Trust Wallet, and several others.
- Apple has already patched the security vulnerabilities in its iOS 26.3 operating system update.
- Devices running iOS 26.2 and older remain vulnerable to the attack if they have not been updated.
Written by our AI from expert market sources across the web. It can contain mistakes: check the facts before acting on them. Write-ups powered by the free AI API at FreeTheAI.org
How we writeDisclaimerQuestions and answers
Which crypto wallets are affected by the iPhone exploit?
The exploit targets popular wallet applications including Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, Uniswap, Bitpie, imToken, and OKEx.
How does the malware steal cryptocurrency?
The malware accesses wallet application data and scans the device's photos and notes for BIP39 recovery phrases, which can be used to hijack the wallets.
How can iPhone users protect their cryptocurrency?
Users should update their iPhones to iOS 26.3 or higher, as Apple has already patched the vulnerabilities exploited by this hacking kit.
