SlowMist Chief Information Security Officer 23pds issued an urgent warning on September 19, telling iPhone users to update their devices immediately after confirming that attackers have operationalized a full-chain iOS exploit capable of silently draining private keys and mnemonic seed phrases from crypto wallets. The disclosure, posted to X by the researcher, spans devices running iOS 13 through iOS 26.5 and represents a serious threat to self-custodied assets held in mobile wallets.
How the exploit chain works
The attack opens when a target visits a malicious webpage in Safari, typically reached through social engineering or a watering-hole link. The page exploits a memory-corruption bug in WebKit and JavaScriptCore to obtain arbitrary…






