Suspected US government tool leak! Google reveals new type of cryptocurrency scam iPhone attack chain

UNI-0.51%

Google Reveals Cryptocurrency Scam

The Google Threat Intelligence Group (GTIG) released a report on Wednesday revealing that a new iPhone vulnerability exploitation toolkit called Coruna has been deployed in large-scale cryptocurrency scam operations. Security firm iVerify disclosed that Coruna may originate from the U.S. government and was repurposed by adversaries and cybercriminal groups after losing control.

Technical Analysis of the Coruna Toolkit: How It Targets and Steals Crypto Wallets

Coruna Toolkit Technical Details
(Source: Mandiant)

Coruna employs JavaScript technology to fingerprint iOS devices accessing fake websites, automatically deploying exploit code once the target version is identified. Once the device is compromised, the toolkit systematically searches for the following sensitive information:

Crypto Mnemonics: Locally stored text containing keywords like “backup phrase” and “seed phrase”

Popular Crypto Applications: Targeting decentralized wallet apps such as Uniswap and MetaMask to extract keys or account data

Financial Account Information: Simultaneously searching for bank accounts and other sensitive payment data

GTIG confirmed that Coruna is incompatible with the latest iOS versions and strongly recommends all iPhone users update their systems immediately. Those unable to upgrade should enable Apple’s “Lockdown Mode,” which Apple states can effectively defend against highly sophisticated targeted attacks.

From Intelligence Operations to Crypto Scam Websites: Two Propagation Paths of Coruna

GTIG’s tracking shows that Coruna has gone through two distinct phases of use. Initially, suspected Russian intelligence used compromised Ukrainian websites to target specific geographic iPhone users, exhibiting typical intelligence-gathering behavior.

In December 2025, GTIG discovered the same JavaScript framework within a large network of fake Chinese financial websites, including a counterfeit site mimicking the cryptocurrency exchange WEEX. When iOS users visit these fake sites, the toolkit automatically extracts financial information in the background, prioritizing crypto wallet mnemonics, posing a direct threat to assets and transforming the original intelligence tool into a large-scale cryptocurrency scam operation.

Attribution Controversy: Is It a U.S. Government Tool or Commercial Spyware?

The most debated aspect of this incident is Coruna’s potential origin. iVerify co-founder Rocky Cole told WIRED that the toolkit “is highly complex, developed at a cost of millions of dollars, and features modules publicly attributed to the U.S. government,” suggesting this may be “the first case of a U.S. government tool being hijacked and exploited by adversaries and cybercriminal groups.”

However, Kaspersky’s chief security researcher disagrees, stating that “no evidence of actual code reuse has been found in the published reports” to support this attribution. GTIG also did not disclose the identity of the initial monitoring client using Coruna, leaving the attribution question unresolved for now.

Frequently Asked Questions

Does the Coruna toolkit affect the latest iPhone versions?

GTIG confirms that all five exploit chains of Coruna target iOS versions 13.0 to 17.2.1, which are incompatible with the current latest iOS system. All iPhone users should update their systems immediately. Those unable to upgrade should enable “Lockdown Mode” to reduce risk.

How did Google discover Coruna being used in crypto scams?

In February 2025, GTIG identified parts of the toolkit’s code, tracing it back to the same JavaScript framework on compromised Ukrainian websites. Later, it was fully deployed across a large network of fake Chinese websites mimicking WEEX, confirming the toolkit’s transition from intelligence gathering to large-scale crypto scam tool.

How can I protect my crypto mnemonics from being stolen by such tools?

Besides updating iOS immediately, it is recommended to store mnemonics offline on cold storage devices (like hardware wallets or paper backups). Avoid storing mnemonics in plaintext on any internet-connected device, and verify the authenticity of all crypto-related websites to prevent visiting untrusted financial sites.

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Geopolitical tensions drive crude oil to fluctuate at high levels, with Gate crude oil contracts reaching a 24-hour trading volume of $85.14 million.

International crude oil prices are fluctuating at high levels under the influence of the US, Israel, and Iran situations. Brent crude oil is currently at $84.28. The Gate platform has launched its first commodity contract, offering 24/7 trading and high leverage services to meet users' asset allocation needs.

GateNews4m ago

Iranian cryptocurrency trading volume plummets 80%, geopolitical shocks severely impact the market

Recently, Iran's cryptocurrency market trading volume has plummeted by approximately 80%, attracting global attention. Geopolitical factors such as reports of airstrikes by the US and Israel have caused investors to worry about network disruptions and economic chaos, leading traders to reduce risk and suspend trading. Despite the volatility, Iran's cryptocurrency remains an important tool for cross-border payments. Analysts believe that this incident demonstrates the increasing impact of localized conflicts on digital markets, and market participants will continue to monitor the development of the situation and its effect on digital asset liquidity in the coming weeks.

GateNews1h ago

Why did Bitcoin decouple from Wall Street during the global conflict?

Bitcoin hits a new high of $73,000 amid turbulence on Wall Street. Analysts believe that after a period of adjustment, Bitcoin has entered oversold territory, and geopolitical conflicts are prompting investors to refocus on this borderless safe-haven asset. Despite rising risk aversion in the market, Bitcoin's rally contrasts sharply with the performance of other risk assets.

PANews1h ago

UK reviews cryptocurrency gambling payments to promote legal digital asset betting and consumer protection

The UK Gambling Commission is reviewing the use of cryptocurrency payments on licensed gambling platforms, aiming to provide players with more payment options while ensuring consumer protection. As demand for crypto gambling increases, regulators hope to guide players away from high-risk platforms through the legalization of crypto payments and plan to introduce more comprehensive regulatory frameworks between 2026 and 2027.

GateNews1h ago

Bitcoin ETF capital inflow reaches $155 million. Can BTC price continue its rebound to $80,000?

Bitcoin regains upward momentum after experiencing geopolitical fluctuations, with ETF inflows of approximately $155 million per day fueling the rebound. Currently trading at $72,500, it is challenging the resistance levels between $73,000 and $75,000. Institutional capital returning, improved market sentiment, and positive technical indicators support a short-term rebound for Bitcoin, but the stability of the $70,000 support level should be monitored.

GateNews2h ago

Bitcoin breaks through $72,000, driving the crypto market higher; Ethereum, Solana, and XRP all rise collectively.

The Middle East situation has eased, global risk asset sentiment has improved, and the cryptocurrency market has strengthened. Bitcoin broke through $72,000, reaching a new high for the period, and other mainstream digital assets also generally rose. Analysts believe that the rebound was driven by a return of market risk appetite and capital inflows.

GateNews2h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)