iOS wallet security isn’t just “scaremongering” this time—criminal networks in the grey and black markets have already connected the chain.
Misty Cloud’s Chief Information Security Officer, 23pds, said in a post on X that the attack path can begin with extracting a private key and seed phrase from a clicked link. It then continues when Safari visits a webpage, using WebKit/JSC memory corruption to gain JavaScript-layer read/write capabilities. Next, it bypasses PAC, escapes the WebContent sandbox, and ultimately escalates privileges to obtain root access, then exfiltrates the Keychain and wallet data. Affected versions are iOS 13 through 26.5.
These risks don’t map directly to a single cryptocurrency, but they will increase the self-custody pressure on mobile crypto holders, and they won’t immediately change the BTC and ETH trends. A realistic scenario is continuing to use a mobile wallet to click on unknown links; another scenario is keeping high-value assets on mobile. Do you prefer to “upgrade the system first,” or to “move large amounts of assets to a hardware wallet or a cold wallet” first?
Source: PANews
Figure 1: iOS wallet security risks heat up · Partial screenshot of the source page
Image source: https://www.panewslab.com/zh/articles/01a0b944-dc0b-7425-8c59-3d26313565d5
Misty Cloud’s Chief Information Security Officer, 23pds, said in a post on X that the attack path can begin with extracting a private key and seed phrase from a clicked link. It then continues when Safari visits a webpage, using WebKit/JSC memory corruption to gain JavaScript-layer read/write capabilities. Next, it bypasses PAC, escapes the WebContent sandbox, and ultimately escalates privileges to obtain root access, then exfiltrates the Keychain and wallet data. Affected versions are iOS 13 through 26.5.
These risks don’t map directly to a single cryptocurrency, but they will increase the self-custody pressure on mobile crypto holders, and they won’t immediately change the BTC and ETH trends. A realistic scenario is continuing to use a mobile wallet to click on unknown links; another scenario is keeping high-value assets on mobile. Do you prefer to “upgrade the system first,” or to “move large amounts of assets to a hardware wallet or a cold wallet” first?
Source: PANews
Figure 1: iOS wallet security risks heat up · Partial screenshot of the source page
Image source: https://www.panewslab.com/zh/articles/01a0b944-dc0b-7425-8c59-3d26313565d5
