iOS exploit toolkit still targeting crypto wallets, researchers say

Security researchers at Censys report that the DarkSword exploit and Coruna malware are still being used together against iPhones. The attack targets WebKit and JavaScriptCore to reach SpringBoard, while Coruna steals cryptocurrency wallet data and searches Photos and Notes for BIP39 recovery phrases. Vulnerabilities were fixed in iOS 26.3, so users on older iOS 26, iOS 18, and earlier releases remain at risk and should update.
Censys researchers say the DarkSword/Coruna combination remains active. DarkSword uses flaws in WebKit and JavaScriptCore to reach SpringBoard, which handles app launching and the Home screen. Coruna then acts as the payload, seeking cryptocurrency wallet data.
The campaign targets multiple wallet apps, including MetaMask, Trust Wallet, Coinbase, and others. It also scans Photos and Notes for BIP39 backup phrases. Apple addressed the exploited flaws in iOS 26.3; the current release is iOS 27.0.1. Devices on iOS 26.2 or earlier, including iOS 18 and older, may still be exposed.
iPhone users who hold crypto and delay updates could face wallet theft, loss of funds, and exposure of recovery phrases. The targeting of popular wallet apps may erode trust in mobile finance and encourage faster patching. Because exploits rely on older iOS versions, impact may concentrate among users unable or unwilling to upgrade, potentially widening security gaps.