Apple patches iOS flaw used to steal crypto wallet keys
Security & Exploits ·
A newly issued iOS update is believed to close a zero-day hole that attackers used to lift private keys and wallet data from targeted iPhones.
Apple has pushed out what is described as an important security patch, and the company has said it is aware of a report suggesting the flaw was exploited in what it calls extremely sophisticated attacks aimed at specific individuals, according to a post on x.com. The issue is said to affect versions of iOS released before iOS 27, meaning a broad swath of devices could have been exposed prior to the fix.
Details shared about how the exploit worked describe a multi-stage chain rather than a single flaw. A victim would click a malicious link, which led to a webpage opened in Safari; there, a memory-corruption bug in WebKit or JavaScriptCore gave attackers read and write access at the JavaScript layer. From that foothold, the attackers reportedly bypassed pointer authentication protections to gain native code execution, then broke out of the WebContent sandbox and escalated privileges at the kernel level to obtain root access. That level of control would let an attacker reach into the device's Keychain and pull out stored wallet credentials, including private keys and mnemonic phrases.
The range of affected software is described as running from iOS 13 through iOS 26.5, though that scope is still pending confirmation. A separate report covering the same event corroborates the core claim, describing the update as a critical patch for a zero-day that had been actively used to drain crypto wallets on iOS devices, per wublockchain.xyz.
The disclosure follows an earlier warning urging iPhone users to update promptly, suggesting awareness of the exploit predates the formal patch release. Because the described attack chain requires no user action beyond clicking a link and opening it in Safari, wallet holders who delayed updating would have remained exposed during that window.
What remains unclear is the precise final version range confirmed as vulnerable, the number of individuals or wallets actually affected, and whether Apple will publish a formal advisory with a CVE identifier and technical details. It is also not yet established how widely the exploit was distributed beyond the sophisticated, targeted attacks referenced, or whether other platforms sharing WebKit components face related exposure. Users are advised to install the latest iOS update as a precaution while further confirmation is awaited.