markets

SlowMist Probes iPhone Safari Exploit Tied to Crypto Theft

Summarized from Cointelegraph

Security firm SlowMist is investigating a Safari-based iOS attack that may have enabled cryptocurrency theft, though the theft remains unconfirmed.

SlowMist Probes iPhone Safari Exploit Tied to Crypto Theft

Blockchain security firm SlowMist is examining a potentially serious vulnerability in Apple's Safari browser that researchers believe could be linked to cryptocurrency theft, though the firm has stopped short of confirming any funds were actually stolen. The cautious posture reflects the difficulty of attributing on-chain losses to specific exploit vectors, particularly in cases where user behavior and software flaws may overlap.

The analyzed malicious Safari sample appears to target devices running iOS versions 18.4 through 18.6.2, exploiting flaws that Apple had previously patched in earlier update cycles. That detail alone is significant: it suggests affected users may have been running outdated software, underscoring a persistent and underappreciated risk in the crypto community where hardware wallet assumptions can breed complacency about mobile device hygiene.

Read more Deere Stock Trades Near Fair Value as Business Mix Shifts →

Critically, whether the exploit remains effective against iOS 26.5 — Apple's more recent release — has not yet been verified by SlowMist's researchers. That uncertainty matters both for users trying to assess their current exposure and for the broader security community attempting to scope the campaign's potential reach. Until testing is complete, users on any iOS version should treat the risk as live.

The episode reinforces a pattern security researchers have long warned about: crypto holders are disproportionately attractive targets for browser-based exploits because a single compromised session can expose wallet seed phrases or drain connected decentralized finance applications. Mobile browsers, often granted sweeping permissions, represent one of the softest attack surfaces in an otherwise hardware-hardened ecosystem.

SlowMist has not yet released a full technical disclosure, and the investigation appears ongoing. Users holding significant crypto assets on mobile devices are advised to update to the latest iOS version available and audit which sites and apps have active wallet connections. Continue reading at Cointelegraph.

Frequently Asked Questions

Q.Which iOS versions are affected by the Safari exploit SlowMist is investigating?

The malicious Safari sample analyzed by SlowMist targets devices running iOS versions 18.4 through 18.6.2, using flaws that Apple had previously patched.

Q.Has SlowMist confirmed that cryptocurrency was actually stolen in this attack?

No. As of the latest reporting, SlowMist has not confirmed that any crypto theft occurred, and the investigation remains ongoing.

Q.Does the Safari exploit work on iOS 26.5?

That has not yet been verified. SlowMist researchers have not confirmed whether the exploit is effective against iOS 26.5, leaving its reach on newer software versions uncertain.

More in markets →