The situation

Real talk: the plot has thickened around those scary rumors of iPhone Safari exploits stealing crypto. If your feed is currently blowing up with warnings about a "massive" hack affecting iOS 13 through 26.5, take a breath. The security pros over at SlowMist just dropped some clarity, and it’s giving a much different vibe than the panic online.

Fact vs. hype

SlowMist confirmed they analyzed a specific Safari exploit chain linked to a malicious webpage—basically, a site offering "free" virtual private servers that drops code the second you load the page. Here is the breakdown:

  • No confirmed bags lost: Despite the noise, SlowMist has not actually linked this specific exploit to any confirmed cases of stolen crypto.
  • The scope: The tech is only proven to target iOS 18.4 through 18.6.2. Any claims about the entire range of iOS 13 to 26.5 are still super preliminary.
  • It's old news: The vulnerabilities being used here were actually already patched by Apple.

This whole thing is separate from the FomoPeek investigation and uses techniques from an exploit chain called "DarkSword" that’s been around since late 2025.

Stay safe out there

Even though the Degen-level fear might be overblown, security is never a L. If you’re worried your seed phrases or keys might be compromised, don’t play around. Move your assets to a brand-new wallet on a clean device immediately.

For everyone else, keep your OS updated to the latest version. If you’re feeling extra paranoid, you can toggle on Apple’s Lockdown Mode, though SlowMist notes they haven't verified if it 100% kills this specific threat.

Why it matters

Staying on-chain means taking your own security seriously. While this specific exploit hasn't been confirmed to drain wallets, it proves that browser-based attacks can reach your device’s Keychain. Always treat your seed phrases like digital gold and stop clicking on sketchy links—even if they promise a free VPS.