This is a hard warning for all iPhone users:
① iOS Safari is not “default security.” Zero-day vulnerabilities continue to be discovered in the WebKit engine, including JS memory-reading attacks;
② For crypto users: don’t import/view recovery phrases (seed phrases) in iPhone Safari. For important actions, use a hardware wallet or a standalone signing device;
③ A lesson for crypto wallet developers: wallet apps should proactively detect WebView/Safari calls and forcibly block sensitive operations, rather than relying on system-level fallback protections.
The security of crypto assets requires dedicated tools—don’t trust the default security of any consumer-grade operating system.
Wake-up call 🚨🚨🚨
① iOS Safari is not “default security.” Zero-day vulnerabilities continue to be discovered in the WebKit engine, including JS memory-reading attacks;
② For crypto users: don’t import/view recovery phrases (seed phrases) in iPhone Safari. For important actions, use a hardware wallet or a standalone signing device;
③ A lesson for crypto wallet developers: wallet apps should proactively detect WebView/Safari calls and forcibly block sensitive operations, rather than relying on system-level fallback protections.
The security of crypto assets requires dedicated tools—don’t trust the default security of any consumer-grade operating system.
Wake-up call 🚨🚨🚨