The post Google warns over 200 million iPhone crypto wallets at risk appeared on BitcoinEthereumNews.com. Google just disclosed a vulnerability that targets iPhoneThe post Google warns over 200 million iPhone crypto wallets at risk appeared on BitcoinEthereumNews.com. Google just disclosed a vulnerability that targets iPhone

Google warns over 200 million iPhone crypto wallets at risk

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

Google just disclosed a vulnerability that targets iPhone crypto wallets and could have affected an estimated 270 million Apple devices.

The DarkSword exploit, which strings together multiple zero-day vulnerabilities, is still live today and affects iPhones running iOS 18.4 through 18.7, updates that were released between April and September last year.

Up-to-date Apple devices use iOS 26.3.1. However, because many people don’t automatically upgrade, 24% of all iPhones still use iOS 18 according to Apple’s own data.

DarkSword allows hackers to orchestrate six vulnerabilities together to silently compromise devices, dump their Keychain databases, and vacuum up crypto wallet data. 

Frequently targeted apps by DarkSword hackers include crypto wallets MetaMask, Phantom, and dozens of others by Coinbase, Ledger, and more. Visiting a poisoned website in Safari is all it takes to trigger the attack.

Google’s Threat Intelligence Group has observed Russian state-linked hackers, a Turkish surveillance vendor, and another threat cluster wielding DarkSword against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.

Read more: Legacy DeFi platforms lose $27M as hacking spree continues into 2026

Zero-day access to iPhone crypto wallet files

DarkSword isn’t a keylogger or clipboard sniffer; it gains kernel-level access, then injects JavaScript into privileged iOS system processes to pillage the device.

The sinister toolkit hunts specifically for crypto wallet files, scanning for apps matching terms like “metamask,” “ledger,” “trezor,” “phantom,” “coinbase,” “binance,” and “kraken.” It grabs whatever wallet data it finds.

It can also pull the device’s Keychain database which is an Apple system-level storage service for passwords. 

DarkSword can also access WiFi passwords, iCloud data, Safari cookies, iMessages, WhatsApp histories, call logs, location histories, photos, and encryption keys protecting stored credentials called keybags.

Read more: Venus Protocol hacker lost $4.7M after nine months of planning

All six vulnerabilities have now received patches if an iPhone user upgrades their operating system.

Apple addressed most in iOS 18.7.2 and 18.7.3. However, if their passwords, files, or crypto wallet data have already been stolen, all of those credentials and personal security implications would have to be re-secured.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/google-warns-over-200-million-iphone-crypto-wallets-at-risk/

Market Opportunity
Ucan fix life in1day Logo
Ucan fix life in1day Price(1)
$0.0004745
$0.0004745$0.0004745
+31.29%
USD
Ucan fix life in1day (1) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40
BitGo receives approval from Germany’s BaFIN to offer regulated cryptocurrency trading in Europe

BitGo receives approval from Germany’s BaFIN to offer regulated cryptocurrency trading in Europe

PANews reported on September 18th that digital asset infrastructure company BitGo recently received a license renewal from Germany's Federal Financial Supervisory Authority (BaFin), enabling it to provide cryptocurrency services to European investors. The company stated that its local subsidiary, BitGo Europe, now offers custody, staking, transfer, and trading services. Institutional clients will also have access to an over-the-counter (OTC) trading desk and multiple liquidity trading venues. This renewal expands BitGo's existing Markets in Crypto-Assets (MiCA) license issued by BaFin, adding trading services to its existing custody, transfer, and staking services. BitGo received its initial MiCA license in May 2025, which allowed it to provide specific services to traditional institutions and cryptocurrency-native companies in the EU.
Share
PANews2025/09/18 08:43
WADESK Just Dropped the Ultimate WASender Free Tool for Marketers

WADESK Just Dropped the Ultimate WASender Free Tool for Marketers

Marketing budgets are tight these days. If you are like most small business owners or digital marketers, you are constantly juggling five different expensive subscriptions
Share
Techbullion2026/03/24 18:46