DarkSword (iOS Safari zero-click exploit chain targeting crypto wallets)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
DarkSword is a six-vulnerability full-chain iOS exploit kit, publicly disclosed by Google's Threat Intelligence Group (GTIG) in March 2026, that can compromise an iPhone via a single malicious Safari page visit and has been used by multiple commercial-surveillance and state-linked threat actors since at least November 2025. Apple patched the original six vulnerabilities by iOS 26.3/18.7.3 and later extended fixes to older devices via iOS 18.7.7. In September 2026, SlowMist's CISO warned that attackers had adapted the chain specifically to steal crypto wallet private keys and seed phrases, and claimed exposure extends to iOS 26.5 — a claim Apple and Google had not independently confirmed as of the advisory's publication, and for which no confirmed case of actual fund theft had yet been documented.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(8 events)
November 2025
DarkSword exploit chain first observed active in the wild, used by multiple commercial-surveillance and state-linked threat actors against iPhones.
The Hacker News / Google Threat Intelligence GroupMarch 2026
Google's Threat Intelligence Group, with Lookout and iVerify, publicly disclosed the six-vulnerability DarkSword exploit chain and its GHOSTBLADE/GHOSTKNIFE/GHOSTSABER payloads, noting GHOSTBLADE allegedly targeted data from Coinbase, Binance, Ledger and MetaMask apps.
Google Cloud Threat Intelligence blog / The Hacker NewsMarch 2026
Apple patched the original six DarkSword vulnerabilities with the release of iOS/iPadOS 26.3 and a corresponding 18.7.3 update.
MalwarebytesApril 2026
Apple expanded DarkSword patch coverage to older devices via iOS 18.7.7 and iPadOS 18.7.7.
TechCrunchJuly 2026
Three plaintiffs filed a consolidated lawsuit against Apple in the U.S. District Court for the Northern District of California, alleging a fake Sparrow Wallet app distributed through the App Store cost them a combined $1.8 million-plus in Bitcoin.
TechCrunchSeptember 2026
SlowMist CISO 23pds published an initial threat-intelligence advisory warning that attackers had adapted the DarkSword exploit chain to specifically target crypto wallet private keys and seed phrases via a single Safari page visit.
SlowMist (Medium) / secondary reportingSeptember 2026
Ledger CTO Charles Guillemet publicly amplified the DarkSword warning on X, stating that the exploit meant users could 'lose cryptocurrency by visiting a website,' and urged hardware-wallet use and iOS updates.
Digital Today (citing U.Today)September 2026
SlowMist CISO 23pds restated the advisory, saying attackers were actively exploiting the DarkSword chain against wallet holders and claiming exposure could extend to iOS 26.5 — a claim not independently confirmed by Apple or Google as of this date.
KuCoin News Flashmodel: claude-code-investigator
generated: 9/23/2026, 12:06:47 PM
last updated: 9/23/2026, 8:54:04 PM
avoid.net — verified advice for a post-truth world