BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Ledger CTO urges crypto holders to update iPhones after DarkSword exploit revealed

Ledger Chief Technology Officer Charles Guillemet has issued a strong warning to cryptocurrency users about a critical iPhone security threat. Guillemet advised anyone storing seed phrases or

AnonymousCryptoCompass newsroom
September 21, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.

Ledger Chief Technology Officer Charles Guillemet has issued a strong warning to cryptocurrency users about a critical iPhone security threat. Guillemet advised anyone storing seed phrases or sensitive wallet data on an iPhone to reconsider their approach, citing a newly uncovered type of attack that puts digital assets at risk.

DarkSword iOS exploit poses major security risk

The concern centers on DarkSword, a sophisticated iOS exploit chain identified by security researchers and highlighted by Google’s Threat Intelligence Group. This exploit takes advantage of multiple vulnerabilities in Apple’s mobile operating system, enabling attackers to penetrate several layers of security protocols.

“In plaintext, you visit a website and lose your crypto,” Guillemet wrote on X, emphasizing how a single malicious website visit through Safari could be enough for cybercriminals to compromise a victim’s entire device and access their digital funds. He recommended the use of hardware wallets and stressed the importance of keeping iOS updated to prevent such attacks.

In plaintext, you visit a website and lose your crypto. Keeping recovery phrases in screenshots, notes, or cloud-synced files is extremely dangerous.

DarkSword’s impact is already widespread. Security teams have tracked active malware campaigns exploiting these vulnerabilities since at least November 2025, with targets identified in Saudi Arabia, Turkey, Malaysia, and Ukraine. The malware is capable of stealing sensitive data such as credentials, keychains, messages, contact lists, and most critically, information related to cryptocurrency wallets within seconds of infection.

Technical details and attack method

A typical website accessed through Safari remains confined to Apple’s browser sandbox, restricting its ability to interact with other parts of the iPhone. However, DarkSword circumvents these protections by chaining together several flaws.

The attack begins by targeting Safari’s JavaScriptCore engine, allowing malicious code to gain control inside the browser. It then bypasses Pointer Authentication Codes (PAC), a security feature in iOS designed to prevent attackers from hijacking the execution of programs. By sidestepping PAC, the attack further escapes Safari’s sandbox and exploits vulnerabilities in the iOS kernel, the fundamental component of the mobile operating system.

With full kernel access, an attacker can retrieve sensitive personal information and specifically extract wallet recovery phrases or private keys stored in screenshots, notes, or cloud storage. Guillemet underscored the severe risk of leaving such details accessible on an iPhone.

Mini dictionary: Pointer Authentication Codes (PAC), a security mechanism in Apple’s processors that restricts attackers from gaining control over program execution in iOS by authenticating pointers, making exploitation more challenging.

Apple and Google response

Google Threat Intelligence Group first disclosed the existence of the DarkSword exploit chain in March and confirmed that multiple criminal groups had abused it in targeted attacks. Google reported that all six vulnerabilities exploited by DarkSword were fixed in the release of iOS 26.3. Users are strongly encouraged to update their devices to this version or newer as soon as possible.

Apple has continued to roll out additional security patches. The most recent update, iOS 26.6.1, addresses new vulnerabilities in WebKit, the underlying engine behind Safari, further strengthening the platform’s defenses against such sophisticated threats.

Google and Apple confirmed that the DarkSword vulnerabilities were patched in iOS 26.3, with extra security improvements arriving in the latest iOS 26.6.1 update.

iOS Version Status of DarkSword Exploit Additional Security Fixes iOS 26.2 and earlier Vulnerable Not protected from DarkSword iOS 26.3 Patched DarkSword vulnerabilities fixed iOS 26.6.1 Patched Additional WebKit vulnerabilities resolved

Ledger, founded in 2014, is a leading provider of hardware wallets and digital security solutions for cryptocurrency assets. Charles Guillemet, as CTO, has repeatedly advocated for best practices in safeguarding private keys from digital threats.

The post Ledger CTO urges crypto holders to update iPhones after DarkSword exploit revealed appeared first on COINTURK NEWS.