{"investigation":{"slug":"darksword-ios-safari-zero-click-exploit-chain-targeting-crypto-wallets","entity_name":"DarkSword (iOS Safari zero-click exploit chain targeting crypto wallets)","trust_score":3,"severity_base":null,"score_modifier":0,"confidence":0.68,"status":"draft","content_type":"investigation","summary":"DarkSword is a six-vulnerability full-chain iOS exploit kit, publicly disclosed by Google's Threat Intelligence Group (GTIG) in March 2026, that can compromise an iPhone via a single malicious Safari page visit and has been used by multiple commercial-surveillance and state-linked threat actors since at least November 2025. Apple patched the original six vulnerabilities by iOS 26.3/18.7.3 and later extended fixes to older devices via iOS 18.7.7. In September 2026, SlowMist's CISO warned that attackers had adapted the chain specifically to steal crypto wallet private keys and seed phrases, and claimed exposure extends to iOS 26.5 — a claim Apple and Google had not independently confirmed as of the advisory's publication, and for which no confirmed case of actual fund theft had yet been documented.","sections":[{"content":"DarkSword is a full-chain iOS exploit kit combining six vulnerabilities — CVE-2025-31277, CVE-2025-43529, CVE-2025-14174, CVE-2026-20700, CVE-2025-43510 and CVE-2025-43520 — spanning WebKit/JavaScriptCore memory corruption, an ANGLE GPU memory-corruption flaw, a dyld Pointer Authentication Code/TPRO bypass, and kernel memory-management and privilege-escalation bugs. According to Google's Threat Intelligence Group (GTIG), which disclosed the chain jointly with Lookout and iVerify in March 2026, the exploit is written almost entirely in JavaScript and can compromise a device from browser sandbox to kernel-level access after a user simply loads a malicious webpage in Safari, with no further interaction required. GTIG stated the toolmarks in recovered payloads suggest the name 'DarkSword,' and that the chain had been active in the wild since at least November 2025.","heading":"The DarkSword Exploit Chain: Technical Overview","sources":[{"url":"https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html","name":"DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover","type":"news_article","credibility":2},{"url":"https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain","name":"The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors (Google Cloud Threat Intelligence)","type":"official","credibility":1},{"url":"https://labs.cloudsecurityalliance.org/research/csa-research-note-darksword-ios-fullchain-zeroday-multiactor/","name":"DarkSword: Full-Chain iOS Zero-Day Exploitation by State Actors","type":"research","credibility":2}],"severity":"critical"},{"content":"GTIG identified three distinct post-compromise payloads deployed via DarkSword: GHOSTBLADE (described as data-mining malware), GHOSTKNIFE (a JavaScript backdoor capable of information theft) and GHOSTSABER (a JavaScript backdoor that communicates with an external command server). Reporting on the GTIG disclosure states that DarkSword 'aims to extract an extensive set of personal information, including credentials from the device and specifically targets a plethora of crypto wallet apps,' with the GHOSTBLADE payload alleged to explicitly target data associated with Coinbase, Binance, Ledger and MetaMask apps alongside conventional espionage data such as messages, contacts, files and location history. Research from the Cloud Security Alliance attributes distinct DarkSword campaigns to three actors: UNC6353 (alleged, suspected Russian espionage activity, targeting victims in Ukraine), UNC6748 (an unattributed state or state-adjacent actor, targeting Saudi Arabia), and PARS Defense (described as a Turkish commercial surveillance vendor, deployed against targets in Turkey and Malaysia). These attributions come from a single industry research note and have not been independently corroborated by a second named source, so they should be treated as preliminary.","heading":"Threat Actor Use and Crypto Wallet Targeting (GHOSTBLADE Payload)","sources":[{"url":"https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html","name":"DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover","type":"news_article","credibility":2},{"url":"https://labs.cloudsecurityalliance.org/research/csa-research-note-darksword-ios-fullchain-zeroday-multiactor/","name":"DarkSword: Full-Chain iOS Zero-Day Exploitation by State Actors","type":"research","credibility":2}],"severity":"critical"},{"content":"GTIG reported the vulnerabilities to Apple in late 2025, and the original six-vulnerability chain was patched with iOS/iPadOS 26.3 and a corresponding 18.7.3 update, according to multiple outlets covering the GTIG disclosure. Because a large population of older devices (iPhone XS, XS Max, XR and 7th-generation iPad) does not run the iOS 26 track, Apple subsequently issued a backported fix, releasing iOS 18.7.7 and iPadOS 18.7.7 — TechCrunch reported that Apple 'released iOS 18.7.7 and iPadOS 18.7.7' to a wider set of older devices at the start of April 2026, after an initial limited rollout in late March. Coverage from the time estimated that 220–270 million iPhones worldwide were still running software vulnerable to some or all of the DarkSword chain even after patches became available, reflecting typical lag in iOS update adoption rather than an unpatched vulnerability.","heading":"Apple's Patch Response and Ongoing Exposure","sources":[{"url":"https://techcrunch.com/2026/04/01/apple-releases-security-fix-for-older-iphones-and-ipads-to-protect-against-darksword-attacks/","name":"Apple releases security fix for older iPhones and iPads to protect against DarkSword attacks","type":"news_article","credibility":1},{"url":"https://www.malwarebytes.com/blog/mobile/2026/03/a-darksword-hangs-over-unpatched-iphones","name":"A DarkSword hangs over unpatched iPhones (Malwarebytes)","type":"news_article","credibility":2},{"url":"https://www.tomsguide.com/phones/iphones/more-than-220-million-iphones-under-attack-from-new-darksword-exploit-how-to-stay-safe","name":"More than 220 million iPhones under attack from new DarkSword exploit — how to stay safe","type":"news_article","credibility":2}],"severity":"high"},{"content":"In September 2026, SlowMist Chief Information Security Officer 23pds published a threat-intelligence advisory stating that attackers had adapted the DarkSword exploit chain specifically to steal crypto wallet private keys and seed phrases, identifying a live lure — a page disguised as a free VPS offer hosted at event[.]polarnode[.]vip — that loaded malicious scripts against Safari visitors and named imToken, TokenPocket and TronLink among the targeted wallet apps. A KuCoin news summary quotes 23pds as stating, in an update dated 'September 22 (UTC+8),' that 'attackers are exploiting the Darksword vulnerability' against wallet holders. SlowMist's advisory additionally claimed the adapted exploit could affect iPhones running iOS versions as recent as 26.5 — notably later than the iOS 26.3/18.7.3 builds in which Apple had already patched the original six DarkSword CVEs. Crypto.news and other outlets covering the advisory explicitly note that this extended iOS 26.5 exposure claim 'has not been independently confirmed by Apple or Google' as of the reporting date, and that SlowMist's own advisory cautions that a page visit alone does not prove a seed phrase or private key was stolen, and that device forensics are still required to confirm compromise. No news outlet reviewed for this dossier documented a specific, named victim of the September 2026 wallet-targeting campaign losing funds as a direct, confirmed result of DarkSword.","heading":"September 2026: SlowMist's Wallet-Theft Advisory and the Unconfirmed iOS 26.5 Claim","sources":[{"url":"https://crypto.news/slowmist-warns-darksword-may-target-wallets-on-ios/","name":"SlowMist warns Darksword may target wallets on iOS 26.5","type":"news_article","credibility":2},{"url":"https://www.kucoin.com/news/flash/slowmist-warns-darksword-vulnerability-now-affects-ios-26-5-steals-wallet-private-keys","name":"SlowMist warns that the Darksword vulnerability now affects iOS 26.5, stealing wallet private keys","type":"news_article","credibility":2},{"url":"https://startupfortune.com/a-silent-iphone-exploit-called-darksword-is-draining-crypto-wallets/","name":"A Silent iPhone Exploit Called Darksword Is Draining Crypto Wallets","type":"news_article","credibility":3},{"url":"https://slowmist.medium.com/threat-intelligence-ios-safari-darksword-wallet-asset-theft-a7dc0e29cf95","name":"Threat Intelligence | iOS Safari DarkSword Wallet Asset Theft (SlowMist)","type":"research","credibility":2},{"url":"https://cryptobriefing.com/safari-zero-day-exploit-iphone-crypto-wallets/","name":"Researchers warn of Safari zero-day exploit targeting Apple iPhones and crypto wallets","type":"news_article","credibility":2}],"severity":"high"},{"content":"Ledger Chief Technology Officer Charles Guillemet publicly amplified SlowMist's warning on X (formerly Twitter). Digital Today reported that, citing U.Today, Guillemet said the DarkSword attack chain targeting iPhone users 'is being used in real attacks,' and summarized his warning in the phrase that, in plain terms, 'you lose cryptocurrency by visiting a website.' Guillemet reportedly recommended that users store recovery phrases on a dedicated hardware wallet rather than as screenshots, notes, or files synced to cloud storage, and urged prompt updates to the latest iOS version. His statement functions as a risk-mitigation advisory rather than independent technical confirmation of the specific iOS 26.5 exposure claim; Guillemet is not reported to have conducted his own forensic analysis of the September 2026 campaign.","heading":"Ledger CTO Amplification and Industry Response","sources":[{"url":"https://www.digitaltoday.co.kr/en/view/106240/ledger-cto-warns-iphone-safari-exploit-could-steal-crypto-wallet-data","name":"Ledger CTO warns iPhone Safari exploit could steal crypto wallet data","type":"news_article","credibility":2},{"url":"https://u.today/visit-website-and-lose-your-crypto-ledger-exec-issues-warning-about-safari-attack","name":"'Visit Website and Lose Your Crypto': Ledger Exec Issues Warning About Safari Attack","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Separately from the DarkSword zero-click Safari exploit, three plaintiffs — James Ramirez, Christopher Ellis and Jalen Delgado — filed a consolidated lawsuit against Apple in the U.S. District Court for the Northern District of California in July 2026, alleging that a fake app impersonating the Sparrow Bitcoin wallet was distributed through the official App Store and prompted them to enter their wallet recovery seed phrases, after which their funds were allegedly drained. TechCrunch reported the plaintiffs' combined losses at 'more than $1.8 million' (cited elsewhere as $1.835 million), with individual losses of approximately $875,000, $840,000 and $120,000 respectively. The plaintiffs allege Apple's App Store review and ranking practices allowed the fraudulent app to reach and be recommended to users despite impersonating a known wallet brand; Apple told reporters it removed apps impersonating Sparrow Wallet and terminated the associated developer accounts. This incident involves a malicious app fraudulently distributed through the App Store — a social-engineering and app-review failure — and is a mechanically distinct threat from the DarkSword zero-click Safari webpage exploit, though some news aggregators have bundled the two stories together in single articles, which risks conflating an unrelated phishing-app case with an active browser-exploit chain.","heading":"Related but Distinct: Apple App Store Fake Wallet Lawsuit ($1.835 Million)","sources":[{"url":"https://techcrunch.com/2026/07/27/apple-sued-after-alleged-app-store-crypto-scam-cost-users-1-8m/","name":"Apple Sued After Alleged App Store Crypto Scam Cost Users $1.8 Million","type":"news_article","credibility":1},{"url":"https://cybernews.com/news/apple-faces-lawsuit-after-fake-bitcoin-wallet-drained-1-8m-from-app-store-customers/","name":"Apple faces lawsuit after fake Bitcoin wallet drained $1.8M from App Store customers","type":"news_article","credibility":2},{"url":"https://appleinsider.com/articles/26/07/27/weak-app-store-protections-at-core-of-18m-crypto-app-fraud-lawsuit","name":"Weak App Store protections at core of $1.8M crypto app fraud lawsuit","type":"news_article","credibility":2}],"severity":"medium"},{"content":"Sources covering the DarkSword advisory converge on a consistent set of mitigations for iPhone-based crypto holders: update iOS to the latest available build (iOS 26.3 or later, or 18.7.7 for devices remaining on the iOS 18 track, closes the confirmed portion of the DarkSword chain); avoid opening unsolicited or unfamiliar links in Safari, including offers such as free VPS trials; never store seed phrases or recovery phrases as plaintext notes, screenshots, or files synced to iCloud or other cloud storage; and use a dedicated hardware wallet to keep private keys off any general-purpose, internet-connected device. SlowMist additionally recommends device forensic review for users who suspect exposure, rather than assuming compromise from a page visit alone.","heading":"Recommended Mitigations","sources":[{"url":"https://www.digitaltoday.co.kr/en/view/106240/ledger-cto-warns-iphone-safari-exploit-could-steal-crypto-wallet-data","name":"Ledger CTO warns iPhone Safari exploit could steal crypto wallet data","type":"news_article","credibility":2},{"url":"https://crypto.news/slowmist-warns-darksword-may-target-wallets-on-ios/","name":"SlowMist warns Darksword may target wallets on iOS 26.5","type":"news_article","credibility":2}],"severity":"low"}],"timeline":[{"date":"2025-11","event":"DarkSword exploit chain first observed active in the wild, used by multiple commercial-surveillance and state-linked threat actors against iPhones.","source":"The Hacker News / Google Threat Intelligence Group","source_url":"https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html"},{"date":"2026-03","event":"Google's Threat Intelligence Group, with Lookout and iVerify, publicly disclosed the six-vulnerability DarkSword exploit chain and its GHOSTBLADE/GHOSTKNIFE/GHOSTSABER payloads, noting GHOSTBLADE allegedly targeted data from Coinbase, Binance, Ledger and MetaMask apps.","source":"Google Cloud Threat Intelligence blog / The Hacker News","source_url":"https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain"},{"date":"2026-03","event":"Apple patched the original six DarkSword vulnerabilities with the release of iOS/iPadOS 26.3 and a corresponding 18.7.3 update.","source":"Malwarebytes","source_url":"https://www.malwarebytes.com/blog/mobile/2026/03/a-darksword-hangs-over-unpatched-iphones"},{"date":"2026-04","event":"Apple expanded DarkSword patch coverage to older devices via iOS 18.7.7 and iPadOS 18.7.7.","source":"TechCrunch","source_url":"https://techcrunch.com/2026/04/01/apple-releases-security-fix-for-older-iphones-and-ipads-to-protect-against-darksword-attacks/","date_evidence":"Apple has pushed a security update to older iPhones and iPads... it released iOS 18.7.7 and iPadOS 18.7.7"},{"date":"2026-07","event":"Three plaintiffs filed a consolidated lawsuit against Apple in the U.S. District Court for the Northern District of California, alleging a fake Sparrow Wallet app distributed through the App Store cost them a combined $1.8 million-plus in Bitcoin.","source":"TechCrunch","source_url":"https://techcrunch.com/2026/07/27/apple-sued-after-alleged-app-store-crypto-scam-cost-users-1-8m/","date_evidence":"In a lawsuit filed on Friday in the U.S. District Court of Northern California, three plaintiffs claim they were tricked into downloading and installing a fraudulent crypto wallet app, leading them to collectively lose more than $1.8 million."},{"date":"2026-09","event":"SlowMist CISO 23pds published an initial threat-intelligence advisory warning that attackers had adapted the DarkSword exploit chain to specifically target crypto wallet private keys and seed phrases via a single Safari page visit.","source":"SlowMist (Medium) / secondary reporting","source_url":"https://slowmist.medium.com/threat-intelligence-ios-safari-darksword-wallet-asset-theft-a7dc0e29cf95"},{"date":"2026-09","event":"Ledger CTO Charles Guillemet publicly amplified the DarkSword warning on X, stating that the exploit meant users could 'lose cryptocurrency by visiting a website,' and urged hardware-wallet use and iOS updates.","source":"Digital Today (citing U.Today)","source_url":"https://www.digitaltoday.co.kr/en/view/106240/ledger-cto-warns-iphone-safari-exploit-could-steal-crypto-wallet-data","date_evidence":"On Sept. 21 local time, blockchain outlet U.Today reported that Ledger Chief Technology Officer Charles Guillemet said an iOS attack chain called 'Darksword' targeting iPhone users is being used in real attacks","date_original":"2026-09-21"},{"date":"2026-09","event":"SlowMist CISO 23pds restated the advisory, saying attackers were actively exploiting the DarkSword chain against wallet holders and claiming exposure could extend to iOS 26.5 — a claim not independently confirmed by Apple or Google as of this date.","source":"KuCoin News Flash","source_url":"https://www.kucoin.com/news/flash/slowmist-warns-darksword-vulnerability-now-affects-ios-26-5-steals-wallet-private-keys","date_evidence":"on September 22 (UTC+8), 23pds, Chief Information Security Officer at blockchain security firm SlowMist, stated that attackers are exploiting the Darksword vulnerability","date_original":"2026-09-22"}],"sources_used":[{"url":"https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html","name":"DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover","type":"news_article","archive_url":"http://web.archive.org/web/20260902130519/https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html","credibility":2,"archive_timestamp":"2026-09-02T13:05:19+00:00"},{"url":"https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain","name":"The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors (Google Cloud Threat Intelligence)","type":"official","archive_url":"http://web.archive.org/web/20260913040726/https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain","credibility":1,"archive_timestamp":"2026-09-13T04:07:26+00:00"},{"url":"https://labs.cloudsecurityalliance.org/research/csa-research-note-darksword-ios-fullchain-zeroday-multiactor/","name":"DarkSword: Full-Chain iOS Zero-Day Exploitation by State Actors","type":"research","archive_url":"http://web.archive.org/web/20260505165528/https://labs.cloudsecurityalliance.org/research/csa-research-note-darksword-ios-fullchain-zeroday-multiactor/","credibility":2,"archive_timestamp":"2026-05-05T16:55:28+00:00"},{"url":"https://techcrunch.com/2026/04/01/apple-releases-security-fix-for-older-iphones-and-ipads-to-protect-against-darksword-attacks/","name":"Apple releases security fix for older iPhones and iPads to protect against DarkSword attacks","type":"news_article","archive_url":"http://web.archive.org/web/20260407131046/https://techcrunch.com/2026/04/01/apple-releases-security-fix-for-older-iphones-and-ipads-to-protect-against-darksword-attacks/","credibility":1,"archive_timestamp":"2026-04-07T13:10:46+00:00"},{"url":"https://www.malwarebytes.com/blog/mobile/2026/03/a-darksword-hangs-over-unpatched-iphones","name":"A DarkSword hangs over unpatched iPhones (Malwarebytes)","type":"news_article","archive_url":"http://web.archive.org/web/20260722043020/https://www.malwarebytes.com/blog/mobile/2026/03/a-darksword-hangs-over-unpatched-iphones","credibility":2,"archive_timestamp":"2026-07-22T04:30:20+00:00"},{"url":"https://www.tomsguide.com/phones/iphones/more-than-220-million-iphones-under-attack-from-new-darksword-exploit-how-to-stay-safe","name":"More than 220 million iPhones under attack from new DarkSword exploit — how to stay safe","type":"news_article","archive_url":"http://web.archive.org/web/20260420035808/https://www.tomsguide.com/phones/iphones/more-than-220-million-iphones-under-attack-from-new-darksword-exploit-how-to-stay-safe","credibility":2,"archive_timestamp":"2026-04-20T03:58:08+00:00"},{"url":"https://crypto.news/slowmist-warns-darksword-may-target-wallets-on-ios/","name":"SlowMist warns Darksword may target wallets on iOS 26.5","type":"news_article","archive_url":"https://web.archive.org/web/20260923205034/https://crypto.news/slowmist-warns-darksword-may-target-wallets-on-ios/","credibility":2,"archive_timestamp":"2026-09-23T20:50:34+00:00"},{"url":"https://www.kucoin.com/news/flash/slowmist-warns-darksword-vulnerability-now-affects-ios-26-5-steals-wallet-private-keys","name":"SlowMist warns that the Darksword vulnerability now affects iOS 26.5, stealing wallet private keys","type":"news_article","archive_url":"http://web.archive.org/web/20260923164823/https://www.kucoin.com/news/flash/slowmist-warns-darksword-vulnerability-now-affects-ios-26-5-steals-wallet-private-keys","credibility":2,"archive_timestamp":"2026-09-23T16:48:23+00:00"},{"url":"https://startupfortune.com/a-silent-iphone-exploit-called-darksword-is-draining-crypto-wallets/","name":"A Silent iPhone Exploit Called Darksword Is Draining Crypto Wallets","type":"news_article","archive_url":"https://web.archive.org/web/20260923160743/https://startupfortune.com/a-silent-iphone-exploit-called-darksword-is-draining-crypto-wallets/","credibility":3,"archive_timestamp":"2026-09-23T16:07:43+00:00"},{"url":"https://slowmist.medium.com/threat-intelligence-ios-safari-darksword-wallet-asset-theft-a7dc0e29cf95","name":"Threat Intelligence | iOS Safari DarkSword Wallet Asset Theft (SlowMist)","type":"research","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://cryptobriefing.com/safari-zero-day-exploit-iphone-crypto-wallets/","name":"Researchers warn of Safari zero-day exploit targeting Apple iPhones and crypto wallets","type":"news_article","archive_url":"https://web.archive.org/web/20260923134555/https://cryptobriefing.com/safari-zero-day-exploit-iphone-crypto-wallets/","credibility":2,"archive_timestamp":"2026-09-23T13:45:55+00:00"},{"url":"https://www.digitaltoday.co.kr/en/view/106240/ledger-cto-warns-iphone-safari-exploit-could-steal-crypto-wallet-data","name":"Ledger CTO warns iPhone Safari exploit could steal crypto wallet data","type":"news_article","archive_url":"https://web.archive.org/web/20260923182924/https://www.digitaltoday.co.kr/en/view/106240/ledger-cto-warns-iphone-safari-exploit-could-steal-crypto-wallet-data","credibility":2,"archive_timestamp":"2026-09-23T18:29:24+00:00"},{"url":"https://u.today/visit-website-and-lose-your-crypto-ledger-exec-issues-warning-about-safari-attack","name":"'Visit Website and Lose Your Crypto': Ledger Exec Issues Warning About Safari Attack","type":"news_article","archive_url":"https://web.archive.org/web/20260923134759/https://u.today/is-chainlink-link-infosys-partnership-relevant-for-the-coin","credibility":2,"archive_timestamp":"2026-09-23T13:47:59+00:00"},{"url":"https://techcrunch.com/2026/07/27/apple-sued-after-alleged-app-store-crypto-scam-cost-users-1-8m/","name":"Apple Sued After Alleged App Store Crypto Scam Cost Users $1.8 Million","type":"news_article","archive_url":"http://web.archive.org/web/20260802024118/https://techcrunch.com/2026/07/27/apple-sued-after-alleged-app-store-crypto-scam-cost-users-1-8m/","credibility":1,"archive_timestamp":"2026-08-02T02:41:18+00:00"},{"url":"https://cybernews.com/news/apple-faces-lawsuit-after-fake-bitcoin-wallet-drained-1-8m-from-app-store-customers/","name":"Apple faces lawsuit after fake Bitcoin wallet drained $1.8M from App Store customers","type":"news_article","archive_url":null,"credibility":2,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://appleinsider.com/articles/26/07/27/weak-app-store-protections-at-core-of-18m-crypto-app-fraud-lawsuit","name":"Weak App Store protections at core of $1.8M crypto app fraud lawsuit","type":"news_article","archive_url":"http://web.archive.org/web/20260729211704/https://appleinsider.com/articles/26/07/27/weak-app-store-protections-at-core-of-18m-crypto-app-fraud-lawsuit","credibility":2,"archive_timestamp":"2026-07-29T21:17:04+00:00"}],"source_tags":[],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-code-investigator","created_at":"2026-09-23T12:06:47.162395+00:00","updated_at":"2026-09-23T20:54:04.880197+00:00"}}