Darksword iOS exploit can steal crypto wallet keys

Security firm SlowMist warns a new Darksword iOS exploit can extract private keys from crypto wallets on iPhones and iPads.

SlowMist published an advisory describing a new iOS exploit called Darksword that can extract private keys from crypto wallets on iPhones and iPads. If an attacker obtains those keys they can sign transactions and transfer funds without the owner’s consent.

The advisory explains Darksword does not break cryptography itself. Instead it targets conditions where wallet apps use private keys in device memory, allowing an attacker to read or intercept keys while they are used. The exploit can export seed phrases and private keys or sign transactions on behalf of the user.

Delivery methods depend on the device model, iOS version and the wallet app. The advisory lists possible vectors including malicious apps, compromised web content and other methods that run code or manipulate memory on an iOS device.

The firm identified the issue after investigating reports of unauthorized transactions and unusual app behavior in some mobile wallet setups. The initial notice did not name every affected wallet. SlowMist is coordinating with wallet developers and platform vendors and sharing technical details with partners under responsible-disclosure guidelines.

The advisory warns success depends on multiple factors and that not all iOS devices or wallet apps will be vulnerable. The notice does not attribute the exploit to a particular actor or link it to prior campaigns.

For users, the advisory recommends updating wallet apps and iOS when vendors release patches, removing untrusted apps, avoiding unknown links and attachments, and reviewing recent transactions for unauthorized activity. For users with significant holdings, it recommends moving assets to hardware wallets or other cold storage until fixes are available and considering new wallet seeds if compromise is suspected.

For developers, the advisory recommends minimizing how long private keys remain in device memory, using secure enclaves and hardened storage APIs where available, adding transaction confirmation that requires out-of-band verification, and auditing third-party libraries and in-app components. SlowMist is sharing indicators of compromise and mitigation guidance with affected projects and infrastructure providers.

Private keys are cryptographic credentials that prove ownership of cryptocurrency. If an attacker obtains a private key or seed phrase they can create valid transaction signatures and move funds; blockchain transactions are irreversible.

Users who believe they may have been affected should move remaining funds to new keys created on a secure device or hardware wallet and contact their wallet provider for guidance. Developers and security teams are expected to release patches and updated best practices as more technical details are confirmed.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author