High Other security Source: SlowMist Medium

Threat Intelligence | iOS Safari DarkSword Wallet Asset Theft

A campaign targeting iPhones running iOS 18.4-18.6.2 via Safari is exploiting vulnerabilities consistent with the DarkSword lineage to steal files, Keychain data, and keyboard input, specifically targeting imToken, TokenPocket, and TronLink wallet applications. This campaign reuses previously disclosed vulnerabilities.

Protocols
imToken, TokenPocket, TronLink
Confidence
High
First seen
4 Sep 2026, 10:30 UTC

Read the original report ↗ (opens in a new tab)