Ledger CTO warns of DarkSword iOS exploit stealing crypto wallet data

Editorial illustration: A black angular blade cracks a glowing blue barrier inside a cutaway smartphone, with a Safari compass icon above and a brown wallet holding cards below.

In brief

  • DarkSword iOS exploit chain active since November 2025, targeting crypto holders in Saudi Arabia, Turkey, Malaysia, and Ukraine
  • Malicious Safari pages can compromise iPhones and steal cryptocurrency wallet data through exploit chain
  • DarkSword bypasses Apple security to access keychains, messages, and crypto wallets via six chained vulnerabilities
  • Google Threat Intelligence disclosed DarkSword in March; all flaws patched in iOS 26.3
  • Crypto users storing seed phrases on iPhones should update iOS immediately and reconsider device storage

The DarkSword Chain

DarkSword chains multiple vulnerabilities to bypass Apple's security protections. The exploit targets JavaScriptCore, the JavaScript engine used by Safari, to gain control inside the browser process. It then bypasses Apple's Pointer Authentication Codes (PAC), a security feature intended to make it harder for attackers to hijack program execution.

The chain doesn't stop there. DarkSword eventually escapes Safari's sandbox and exploits the iOS kernel, the core part of the operating system. Once inside, attackers gain sweeping access to sensitive data.

What's at Risk

DarkSword can collect keychains, messages, contacts, files, location information, and cryptocurrency wallet data. Guillemet specifically warned that attackers could use such access to extract wallet information.

This threat is particularly acute for crypto holders who store recovery phrases or seed phrases on their iPhones. Keeping a recovery phrase in screenshots, notes, or cloud-synced files is extremely dangerous. Guillemet urged users who keep cryptocurrency seed phrases or other sensitive wallet information on an iPhone to reconsider that setup and update iOS.

Timeline and Patches

Multiple threat actors have exploited the vulnerability since at least November 2025. Google Threat Intelligence Group disclosed DarkSword in March.

The good news: all six flaws in the DarkSword chain had been fixed by the release of iOS 26.3. Apple's recent iOS 26.6.1 update addresses a number of separate WebKit vulnerabilities as well. Users should update their devices immediately to patch these vulnerabilities and protect their crypto holdings.