BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

SlowMist CISO Warns of Full-Chain iOS Exploit Stealing Crypto Wallet Keys

SlowMist Chief Information Security Officer 23pds issued an urgent warning on September 19, telling iPhone users to update their devices immediately after confirming that attackers have opera

AnonymousCryptoCompass newsroom
September 20, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for policy coverage.
malware-virus-hack

SlowMist Chief Information Security Officer 23pds issued an urgent warning on September 19, telling iPhone users to update their devices immediately after confirming that attackers have operationalized a full-chain iOS exploit capable of silently draining private keys and mnemonic seed phrases from crypto wallets. The disclosure, posted to X by the researcher, spans devices running iOS 13 through iOS 26.5 and represents a serious threat to self-custodied assets held in mobile wallets.

How the exploit chain works

The attack opens when a target visits a malicious webpage in Safari, typically reached through social engineering or a watering-hole link. The page exploits a memory-corruption bug in WebKit and JavaScriptCore to obtain arbitrary read and write access at the JavaScript layer. From there the chain bypasses Pointer Authentication Codes to gain native code execution, escapes the WebContent sandbox, and escalates to kernel-level root privileges — enough to read the device Keychain and pull wallet application data, including private keys and recovery phrases. Unlike a conventional phishing page that tricks a user into typing a seed phrase, this chain requires no action beyond visiting a link, which is why the warning is so urgent.

Who is affected

23pds said the affected range runs from iOS 13 through iOS 26.5, while noting that the upper bound is still pending final confirmation. Because the exploit extracts keys directly from the device, a compromised wallet cannot be recovered through a password reset — anyone holding the extracted keys can move the funds. The threat is most acute for self-custody users, since a key stolen at the device level leaves no exchange-side recovery mechanism. The warning lands against a backdrop of mounting mobile and app-store threats to retail crypto holders, including a recent case in which Apple was accused of keeping a fake Bitcoin wallet live on its App Store after an $875,000 theft was reported.

What users should do

SlowMist’s guidance is blunt: update iOS to the latest version immediately, avoid clicking unsolicited links in Safari, and, for anyone who used a vulnerable device to hold a hot wallet, generate new keys on a clean, updated device and move funds. The incident follows a pattern of mobile-first and phishing attacks aimed directly at crypto users, a tactic security firms have repeatedly flagged. SlowMist has not yet published a longer formal advisory, leaving the researcher’s post as the primary public disclosure at the time of writing.