Security· ★★★★· bearish·

SlowMist warns of full iOS exploit chain stealing wallet keys

  • The attack begins when a user opens a link in Safari, with no user action required
  • The exploit bypasses PAC, escapes the sandbox and gains root access to the kernel
  • iOS 13–26.5 are affected, with the upper bound still being clarified
  • SlowMist advises updating iOS and recreating keys on a clean device
Why it matters: Device-level key theft cannot be reversed through an exchange, which is critical for users who self-custody their assets.
Source: BlockchainReporter