Google reveals iPhone cryptocurrency attack toolkit "Coruna," capable of stealing seed phrases and wallet information

March 5 News: Google Threat Intelligence Group (GTIG) recently released a security report stating that researchers have discovered a new iPhone exploit toolkit called “Coruna,” used to steal cryptocurrency wallet mnemonics and financial information. The toolkit targets devices running iOS 13.0 to 17.2.1 and launches targeted attacks through multiple exploit chains, drawing significant attention in the mobile security field.

The report shows that “Coruna” contains five complete iOS exploit chains, involving a total of 23 security vulnerabilities, some of which have never been publicly disclosed before. Google researchers said they first identified related attack activity in February 2025 and found that the tool was initially suspected to be used by Russian espionage groups for cyberattacks against Ukrainian users. It was later used to impersonate financial and crypto-related websites to trick users into revealing information.

The attack mainly relies on malicious web pages delivering exploit code. When iPhone users visit specific sites, JavaScript frameworks on the pages perform device fingerprinting, verify the system version, and then load the corresponding exploit chain. Researchers found the same framework on multiple compromised Ukrainian websites and noted that the attack code was only sent to iPhones in certain regions.

In December 2025, the team further detected the same framework on numerous fake Chinese-language websites related to financial services, including counterfeit crypto platform pages. Once victims access these sites on iOS devices, the tools scan for sensitive information such as mnemonic phrases, backup words, or bank account details, and attempt to read data from common crypto wallet apps to gain control of digital assets.

Google states that this exploit toolkit currently cannot run on the latest iOS versions, and recommends iPhone users upgrade their systems promptly. If upgrading is not possible, users can enable Apple’s “Lockdown Mode” to defend against complex network attacks.

Meanwhile, discussions about the origin of “Coruna” have also sparked controversy. Rocky Cole, co-founder of mobile security firm iVerify, told media that the tool is highly complex, with development costs possibly reaching millions of dollars, and shares some modules similar to those used in U.S. government cyber tools. However, Kaspersky security experts said there is currently not enough evidence to directly link its code to any known tools.

Security experts warn that cryptocurrency users should be vigilant against phishing pages and update their devices promptly when using mobile wallets or visiting related websites to reduce the risk of mnemonic leaks and digital asset theft.

View Original
Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Suspected US government tool leak! Google reveals new type of cryptocurrency scam iPhone attack chain

Google Threat Intelligence Team Report Reveals New iPhone Exploit Kit Coruna Used in Large-Scale Cryptocurrency Scams. The toolkit uses JavaScript fingerprinting technology to identify iOS devices and steal crypto seed phrases and financial account information. All iPhone users are advised to update their systems immediately to prevent infection. The origin of Coruna is controversial, suspected to be linked to the U.S. government, but no definitive evidence has been provided.

MarketWhisper43m ago

Google Warning: Beware of Cryptocurrency Scams Using New iPhone Vulnerability Toolkits

Google Threat Intelligence Team reports the discovery of an iOS exploit kit called "Coruna," targeting iOS versions 13.0 to 17.2.1 on iPhones, capable of stealing encrypted wallet seed phrases. The kit contains multiple vulnerability chains and has been suspected of being used by Russian espionage groups to attack Ukrainian users. iPhone users are advised to update to the latest iOS version to enhance security.

GateNews1h ago

Cryptocurrency holder suffers $24 million violent robbery, offers a 10% bounty to recover stolen funds

A cryptocurrency holder reported being attacked on social media, losing approximately $24 million worth of crypto assets. The attacker used violence to threaten and force the transfer of funds. The incident has garnered widespread attention, and blockchain security companies are tracking the stolen funds. This event highlights the rising risk of physical attacks in the crypto space.

GateNews1h ago

Russian court sentences three knife-wielding robbers for cryptocurrency heist: sentenced to five years in prison

The Omsk City Court in Russia sentenced three young men to five years in prison for holding a knife and robbing cryptocurrency holders. They used violence and threats to force victims to hand over assets, but ultimately gained no profit and fled after neighbors noticed. This case reflects an increase in violent crimes targeting crypto assets worldwide, and Russia is strengthening its crackdown on such crimes.

GateNews1h ago

$4 Billion DeFi Yield Vault Collapse Follow-up: MEV Capital Assets Shrink by 80%, Decentralized Leverage Strategy Risks Reconsidered

MEV Capital suffered a severe blow due to involvement in deUSD leverage strategies, with assets shrinking from $1.5 billion to $300 million, a decline of nearly 80%. This DeFi crisis was caused by complex lending relationships among yield treasury tokens, leading to multiple project failures and massive capital evaporation. The industry is working to shift towards more stable asset structures, but risks still remain.

GateNews2h ago

Canadian police warn of "cryptocurrency recovery scams": scammers impersonate RCMP to target victims again

Canadian police issue a warning about a "recovery scam" targeting cryptocurrency scam victims. Scammers impersonate police or lawyers, promising to help recover stolen assets, but in reality, they are conducting a secondary scam. Victims should stay vigilant, verify information sources, and avoid falling for the scam again.

GateNews2h ago
Comment
0/400
No comments
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)