The post Google warns over 200 million iPhone crypto wallets at risk appeared on BitcoinEthereumNews.com. Google just disclosed a vulnerability that targets iPhoneThe post Google warns over 200 million iPhone crypto wallets at risk appeared on BitcoinEthereumNews.com. Google just disclosed a vulnerability that targets iPhone

Google warns over 200 million iPhone crypto wallets at risk

2026/03/21 02:27
2 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

Google just disclosed a vulnerability that targets iPhone crypto wallets and could have affected an estimated 270 million Apple devices.

The DarkSword exploit, which strings together multiple zero-day vulnerabilities, is still live today and affects iPhones running iOS 18.4 through 18.7, updates that were released between April and September last year.

Up-to-date Apple devices use iOS 26.3.1. However, because many people don’t automatically upgrade, 24% of all iPhones still use iOS 18 according to Apple’s own data.

DarkSword allows hackers to orchestrate six vulnerabilities together to silently compromise devices, dump their Keychain databases, and vacuum up crypto wallet data. 

Frequently targeted apps by DarkSword hackers include crypto wallets MetaMask, Phantom, and dozens of others by Coinbase, Ledger, and more. Visiting a poisoned website in Safari is all it takes to trigger the attack.

Google’s Threat Intelligence Group has observed Russian state-linked hackers, a Turkish surveillance vendor, and another threat cluster wielding DarkSword against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.

Read more: Legacy DeFi platforms lose $27M as hacking spree continues into 2026

Zero-day access to iPhone crypto wallet files

DarkSword isn’t a keylogger or clipboard sniffer; it gains kernel-level access, then injects JavaScript into privileged iOS system processes to pillage the device.

The sinister toolkit hunts specifically for crypto wallet files, scanning for apps matching terms like “metamask,” “ledger,” “trezor,” “phantom,” “coinbase,” “binance,” and “kraken.” It grabs whatever wallet data it finds.

It can also pull the device’s Keychain database which is an Apple system-level storage service for passwords. 

DarkSword can also access WiFi passwords, iCloud data, Safari cookies, iMessages, WhatsApp histories, call logs, location histories, photos, and encryption keys protecting stored credentials called keybags.

Read more: Venus Protocol hacker lost $4.7M after nine months of planning

All six vulnerabilities have now received patches if an iPhone user upgrades their operating system.

Apple addressed most in iOS 18.7.2 and 18.7.3. However, if their passwords, files, or crypto wallet data have already been stolen, all of those credentials and personal security implications would have to be re-secured.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/google-warns-over-200-million-iphone-crypto-wallets-at-risk/

Opportunità di mercato
Logo Ucan fix life in1day
Valore Ucan fix life in1day (1)
$0.0003283
$0.0003283$0.0003283
+0.67%
USD
Grafico dei prezzi in tempo reale di Ucan fix life in1day (1)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.