Skip to main content
AVOID.NET

DarkSword (iOS Safari zero-click exploit chain targeting crypto wallets)

avoid.net/darksword-ios-safari-zero-click-exploit-chain-targeting-crypto-wallets3/100·68% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

DarkSword is a six-vulnerability full-chain iOS exploit kit, publicly disclosed by Google's Threat Intelligence Group (GTIG) in March 2026, that can compromise an iPhone via a single malicious Safari page visit and has been used by multiple commercial-surveillance and state-linked threat actors since at least November 2025. Apple patched the original six vulnerabilities by iOS 26.3/18.7.3 and later extended fixes to older devices via iOS 18.7.7. In September 2026, SlowMist's CISO warned that attackers had adapted the chain specifically to steal crypto wallet private keys and seed phrases, and claimed exposure extends to iOS 26.5 — a claim Apple and Google had not independently confirmed as of the advisory's publication, and for which no confirmed case of actual fund theft had yet been documented.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about DarkSword (iOS Safari zero-click exploit chain targeting crypto wallets)?

Timeline(8 events)

November 2025

DarkSword exploit chain first observed active in the wild, used by multiple commercial-surveillance and state-linked threat actors against iPhones.

The Hacker News / Google Threat Intelligence Group

March 2026

Google's Threat Intelligence Group, with Lookout and iVerify, publicly disclosed the six-vulnerability DarkSword exploit chain and its GHOSTBLADE/GHOSTKNIFE/GHOSTSABER payloads, noting GHOSTBLADE allegedly targeted data from Coinbase, Binance, Ledger and MetaMask apps.

Google Cloud Threat Intelligence blog / The Hacker News

March 2026

Apple patched the original six DarkSword vulnerabilities with the release of iOS/iPadOS 26.3 and a corresponding 18.7.3 update.

Malwarebytes

April 2026

Apple expanded DarkSword patch coverage to older devices via iOS 18.7.7 and iPadOS 18.7.7.

TechCrunch

July 2026

Three plaintiffs filed a consolidated lawsuit against Apple in the U.S. District Court for the Northern District of California, alleging a fake Sparrow Wallet app distributed through the App Store cost them a combined $1.8 million-plus in Bitcoin.

TechCrunch

September 2026

SlowMist CISO 23pds published an initial threat-intelligence advisory warning that attackers had adapted the DarkSword exploit chain to specifically target crypto wallet private keys and seed phrases via a single Safari page visit.

SlowMist (Medium) / secondary reporting

September 2026

Ledger CTO Charles Guillemet publicly amplified the DarkSword warning on X, stating that the exploit meant users could 'lose cryptocurrency by visiting a website,' and urged hardware-wallet use and iOS updates.

Digital Today (citing U.Today)

September 2026

SlowMist CISO 23pds restated the advisory, saying attackers were actively exploiting the DarkSword chain against wallet holders and claiming exposure could extend to iOS 26.5 — a claim not independently confirmed by Apple or Google as of this date.

KuCoin News Flash
Provenance & Audit Trail
14 Wayback Archives

14 of 16 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 9/23/2026, 12:06:47 PM

last updated: 9/23/2026, 8:54:04 PM

avoid.net — verified advice for a post-truth world