SlowMist: The DarkSword attack program has been leaked in the wild, and older iOS users’ cryptocurrency wallets face serious risks


On May 15, SlowMist’s Yuánzōng said on social media that the high-risk iOS attack framework DarkSword has been publicly leaked via channels such as GitHub, and is being used for large-scale theft attacks targeting people who hold cryptocurrency wallets. The attack program targets devices running iOS 18.4 to 18.7, using malicious web pages to exploit vulnerabilities in the Safari browser to achieve remote code execution, thereby stealing users’ sensitive data.
The leak of DarkSword is yet another public disclosure of a systematic threat to iOS devices after the “Coruna” attack suite. Similar to “Coruna” disclosed by Google in March 2026, this attack also exploits Safari browser vulnerabilities to perform remote code execution against older iOS versions (18.4–18.7), with the targets clearly aimed at cryptocurrency wallet users.
{spot}(ETHUSDT)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned