A newly discovered DarkSword vulnerability chain in older Apple iOS versions specifically targets encrypted applications and private data, posing serious risksA newly discovered DarkSword vulnerability chain in older Apple iOS versions specifically targets encrypted applications and private data, posing serious risks

DarkSword iOS Vulnerability Chain Targets Encrypted Apps and Private Data

2026/03/20 21:01
5 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

A newly disclosed iOS exploit chain called DarkSword is targeting encrypted applications and private data on millions of Apple devices, with crypto wallet and exchange apps among its primary targets. Discovered by Google’s Threat Intelligence Group (GTIG) and confirmed by security firms Lookout and iVerify, the vulnerability chain affects unpatched iOS versions 18.4 through 18.7 and has been active since at least November 2025.

Six Chained Vulnerabilities, Three Zero-Days

DarkSword is not a single flaw. It chains six separate vulnerabilities, three of which were zero-days at the time of discovery: CVE-2025-31277, CVE-2025-43529, CVE-2025-14174, CVE-2025-43510, CVE-2025-43520, and CVE-2026-20700. Together, these exploits allow full device compromise in a sequence that escalates from initial browser access to deep system-level control.

A vulnerability “chain” differs from a single exploit in that each link handles a different layer of iOS security. One CVE may break out of the Safari sandbox, another escalates kernel privileges, and another disables code-signing checks. Chaining them produces a full compromise that no single vulnerability could achieve alone.

The attack begins when a user visits a compromised legitimate website using Safari. A malicious iFrame delivers the JavaScript-based exploit, requiring no interaction beyond loading the page. This “watering hole” approach makes DarkSword particularly dangerous, as victims have no way to distinguish a compromised site from a safe one.

Once a device is compromised, three distinct malware families are deployed: GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. According to GTIG’s published research, multiple commercial surveillance vendors and suspected state-sponsored actors have been observed using DarkSword in distinct campaigns since November 2025.

At least three threat actors have been identified. UNC6748 operates from Saudi Arabia, UNC6353 is a suspected Russian espionage group that incorporated DarkSword into watering hole campaigns targeting Ukraine, and PARS Defense is a Turkish commercial surveillance vendor. Confirmed targets span Saudi Arabia, Turkey, Malaysia, and Ukraine.

Why Crypto Wallets and Exchange Apps Face Direct Risk

What sets DarkSword apart from generic iOS exploits is its explicit targeting of cryptocurrency applications. The exploit specifically goes after six major exchange apps: Coinbase, Binance, Kraken, KuCoin, OKX, and MEXC. Seven wallet apps are also targeted: Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe.

Mobile crypto wallets rely on iOS data protection APIs and the Secure Enclave to isolate private keys, seed phrases, and authentication tokens within encrypted app sandboxes. A successful chain exploit bypasses these protections entirely, allowing attackers to extract data that is normally inaccessible even to other apps on the same device.

The risk compounds for users who store 2FA apps, password managers, or exchange API keys on the same device. DarkSword also harvests email, iCloud files, SMS and iMessage content, Wi-Fi passwords, Safari cookies, Telegram and WhatsApp chat logs, and geolocation data. The disclosure comes amid a period of heightened regulatory activity around crypto security standards, adding urgency to the mobile threat landscape.

Lookout Security described DarkSword’s operational method as a “hit-and-run” approach, collecting and exfiltrating targeted data within seconds or at most minutes, followed by cleanup. This means affected users may never realize their device was compromised.

An estimated 221 to 270 million devices are running affected iOS versions. Older iPhone models that cannot upgrade beyond iOS 18.x are permanently stuck on vulnerable software unless Apple backports specific patches. No confirmed dollar-value losses from crypto wallet targeting have been published, but the harvesting of private keys and exchange credentials poses clear theft risk.

What Crypto Holders Should Do Right Now

Apple has patched all six CVEs. Users should update immediately to iOS 26.3.1 or iOS 18.7.6, depending on device compatibility. Checking your current version takes seconds: go to Settings, then General, then Software Update.

If your device no longer receives iOS updates, move significant crypto holdings to a hardware wallet that is not connected to the compromised device. With DApp revenue declining across major chains and broader market uncertainty, securing existing holdings takes priority over active trading on vulnerable devices.

Avoid storing seed phrases, private keys, or recovery codes in note apps, screenshots, or iCloud storage on any mobile device. These are among the data categories DarkSword specifically targets.

For high-risk users, Apple’s Lockdown Mode (available on iOS 16 and later) restricts certain app capabilities and hardens the attack surface. While it limits some functionality, it blocks several of the vectors DarkSword exploits, including malicious web content delivery.

Google has added DarkSword delivery domains to Safe Browsing, which provides a layer of protection for Chrome and Safari users. However, this only covers known domains, and new delivery infrastructure could emerge. Users tracking Bitcoin ETF flows and broader market signals should be equally attentive to the security of the devices they trade from.

GTIG noted that “the use of both DarkSword and Coruna by a variety of actors demonstrates the ongoing risk of exploit proliferation.” Coruna, a related but separate exploit kit, targets even older iOS versions from 13.0 through 17.2.1, broadening the total population of vulnerable devices.

With the Fear and Greed Index at 11, reflecting extreme fear across crypto markets, the timing of this disclosure adds another pressure point for holders already navigating volatile conditions. Securing mobile devices is now as critical as securing wallets themselves.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

The post Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment? appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 17:39 Is dogecoin really fading? As traders hunt the best crypto to buy now and weigh 2025 picks, Dogecoin (DOGE) still owns the meme coin spotlight, yet upside looks capped, today’s Dogecoin price prediction says as much. Attention is shifting to projects that blend culture with real on-chain tools. Buyers searching “best crypto to buy now” want shipped products, audits, and transparent tokenomics. That frames the true matchup: dogecoin vs. Pepeto. Enter Pepeto (PEPETO), an Ethereum-based memecoin with working rails: PepetoSwap, a zero-fee DEX, plus Pepeto Bridge for smooth cross-chain moves. By fusing story with tools people can use now, and speaking directly to crypto presale 2025 demand, Pepeto puts utility, clarity, and distribution in front. In a market where legacy meme coin leaders risk drifting on sentiment, Pepeto’s execution gives it a real seat in the “best crypto to buy now” debate. First, a quick look at why dogecoin may be losing altitude. Dogecoin Price Prediction: Is Doge Really Fading? Remember when dogecoin made crypto feel simple? In 2013, DOGE turned a meme into money and a loose forum into a movement. A decade on, the nonstop momentum has cooled; the backdrop is different, and the market is far more selective. With DOGE circling ~$0.268, the tape reads bearish-to-neutral for the next few weeks: hold the $0.26 shelf on daily closes and expect choppy range-trading toward $0.29–$0.30 where rallies keep stalling; lose $0.26 decisively and momentum often bleeds into $0.245 with risk of a deeper probe toward $0.22–$0.21; reclaim $0.30 on a clean daily close and the downside bias is likely neutralized, opening room for a squeeze into the low-$0.30s. Source: CoinMarketcap / TradingView Beyond the dogecoin price prediction, DOGE still centers on payments and lacks native smart contracts; ZK-proof verification is proposed,…
Share
BitcoinEthereumNews2025/09/18 00:14
Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45
The Role of Reference Points in Achieving Equilibrium Efficiency in Fair and Socially Just Economies

The Role of Reference Points in Achieving Equilibrium Efficiency in Fair and Socially Just Economies

This article explores how a simple change in the reference point can achieve a Pareto-efficient equilibrium in both free and fair economies and those with social justice.
Share
Hackernoon2025/09/17 22:30