Ad
COINTURK NEWSCOINTURK NEWSCOINTURK NEWS
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Search
© 2024 COINTURK NEWS. All Rights Reserved.
Reading: Ledger CTO urges crypto holders to update iPhones after DarkSword exploit revealed
Share
Font ResizerAa
COINTURK NEWSCOINTURK NEWS
Font ResizerAa
Search
  • Crypto Tracker App
  • Bitcoin
  • Altcoin
  • Ethereum
  • Advertise
  • Contact
  • TURTURTUR
  • ESESES
Follow US
© 2025 >> COINTURK NEWS
Powered by LK SOFTWARE
COINTURK NEWS > Cryptocurrency News > Ledger CTO urges crypto holders to update iPhones after DarkSword exploit revealed
Cryptocurrency News

Ledger CTO urges crypto holders to update iPhones after DarkSword exploit revealed

In Brief

  • ⚡ Ledger CTO warns iPhone users about DarkSword exploit that targets $BTC wallets.

  • 🔒 The attack lets hackers steal crypto just by visiting a malicious Safari page.

  • 💡 Vulnerabilities have now been patched in iOS 26.3 and above.

  • 📱 Apple and Google urge users to update devices to protect digital assets.
İlayda Peker
İlayda Peker 5 hours ago
Share
SHARE

Ledger Chief Technology Officer Charles Guillemet has issued a strong warning to cryptocurrency users about a critical iPhone security threat. Guillemet advised anyone storing seed phrases or sensitive wallet data on an iPhone to reconsider their approach, citing a newly uncovered type of attack that puts digital assets at risk.

Contents
DarkSword iOS exploit poses major security riskTechnical details and attack methodApple and Google response

DarkSword iOS exploit poses major security risk

The concern centers on DarkSword, a sophisticated iOS exploit chain identified by security researchers and highlighted by Google’s Threat Intelligence Group. This exploit takes advantage of multiple vulnerabilities in Apple’s mobile operating system, enabling attackers to penetrate several layers of security protocols.

“In plaintext, you visit a website and lose your crypto,” Guillemet wrote on X, emphasizing how a single malicious website visit through Safari could be enough for cybercriminals to compromise a victim’s entire device and access their digital funds. He recommended the use of hardware wallets and stressed the importance of keeping iOS updated to prevent such attacks.

In plaintext, you visit a website and lose your crypto. Keeping recovery phrases in screenshots, notes, or cloud-synced files is extremely dangerous.

DarkSword’s impact is already widespread. Security teams have tracked active malware campaigns exploiting these vulnerabilities since at least November 2025, with targets identified in Saudi Arabia, Turkey, Malaysia, and Ukraine. The malware is capable of stealing sensitive data such as credentials, keychains, messages, contact lists, and most critically, information related to cryptocurrency wallets within seconds of infection.

Technical details and attack method

A typical website accessed through Safari remains confined to Apple’s browser sandbox, restricting its ability to interact with other parts of the iPhone. However, DarkSword circumvents these protections by chaining together several flaws.

The attack begins by targeting Safari’s JavaScriptCore engine, allowing malicious code to gain control inside the browser. It then bypasses Pointer Authentication Codes (PAC), a security feature in iOS designed to prevent attackers from hijacking the execution of programs. By sidestepping PAC, the attack further escapes Safari’s sandbox and exploits vulnerabilities in the iOS kernel, the fundamental component of the mobile operating system.

With full kernel access, an attacker can retrieve sensitive personal information and specifically extract wallet recovery phrases or private keys stored in screenshots, notes, or cloud storage. Guillemet underscored the severe risk of leaving such details accessible on an iPhone.

Mini dictionary: Pointer Authentication Codes (PAC), a security mechanism in Apple’s processors that restricts attackers from gaining control over program execution in iOS by authenticating pointers, making exploitation more challenging.

Apple and Google response

Google Threat Intelligence Group first disclosed the existence of the DarkSword exploit chain in March and confirmed that multiple criminal groups had abused it in targeted attacks. Google reported that all six vulnerabilities exploited by DarkSword were fixed in the release of iOS 26.3. Users are strongly encouraged to update their devices to this version or newer as soon as possible.

Apple has continued to roll out additional security patches. The most recent update, iOS 26.6.1, addresses new vulnerabilities in WebKit, the underlying engine behind Safari, further strengthening the platform’s defenses against such sophisticated threats.

Google and Apple confirmed that the DarkSword vulnerabilities were patched in iOS 26.3, with extra security improvements arriving in the latest iOS 26.6.1 update.

iOS VersionStatus of DarkSword ExploitAdditional Security Fixes
iOS 26.2 and earlierVulnerableNot protected from DarkSword
iOS 26.3PatchedDarkSword vulnerabilities fixed
iOS 26.6.1PatchedAdditional WebKit vulnerabilities resolved

Ledger, founded in 2014, is a leading provider of hardware wallets and digital security solutions for cryptocurrency assets. Charles Guillemet, as CTO, has repeatedly advocated for best practices in safeguarding private keys from digital threats.

You can follow our news on X, Telegram, Facebook & Coinmarketcap

You Might Also Like

Apple and Google seek stablecoin experts, signal crypto ambitions in payments

Russian central bank targets legal crypto industry framework by end of 2026

Long-term investor lists 134 Ripple partners, banks like HSBC and Santander included

Egrag Crypto presents $589 target as technical coordinate for XRP

France hit by €40,000 crypto home invasion as ‘wrench attacks’ surge 12x

İlayda Peker 21 September, 2026 - 6:30 pm 21 September, 2026 - 6:30 pm
Share This Article
Facebook Twitter
Share
İlayda Peker
By İlayda Peker
Follow:
The author, who holds a degree in International Relations and Political Science, has 10 years of experience as a writer and editor in the fields of cryptocurrency, blockchain technologies, and digital asset markets.While at COINTURK, he has published over 8,500 news articles, analyses, essays, and reports on Bitcoin, altcoins, cryptocurrency markets, the blockchain ecosystem, digital asset regulations, and global financial developments. Closely following market movements and industry developments, the author addresses the complex world of cryptocurrency in a clear and reader-friendly manner.An avid reader, the author also evaluates the impact of international developments on financial markets and the digital asset ecosystem.
Previous Article Solana, Sui, Avalanche, Dogecoin and Ethereum rally as traders rotate into altcoins
Next Article Strategy boosts BTC holdings to 846,000, repurchases $174 million in STRC shares
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

8.1k Like
21.1k Follow
1.1k Follow

Latest News

Bitcoin reclaims $85,000 after 62,335 smaller wallets exit during shakeout
Bitcoin (BTC)
Ondo Finance launches direct stock-to-token conversion for institutions
Ondo
//

COINTURK was launched in March 2014 by a group of technology enthusiasts who believe that Bitcoin will be as important as the internet in the world of the future thanks to the amazing technology underlying it.

CRYPTOCURRENCY LIVE PRICES

  • Bitcoin (BTC) Live Price
  • Ethereum (ETH) Live Price
  • Ripple (XRP) Live Price
  • Solana (SOL) Live Price
  • Dogecoin (DOGE) Live Price
  • Cardano (ADA) Live Price
  • Chainlink (LINK) Live Price

OUR PARTNERS

  • COINMARKETCAP
  • COINGECKO
  • BITCOINHABER
  • BH NEWS
  • NEWSLINKER

OUR COMPANY

  • About Us
  • Cookie Policy
  • Advertising
  • Contact
COINTURK NEWSCOINTURK NEWS
Follow US
COINTURK NEWS 2026
Welcome Back!

Sign in to your account

Lost your password?