Open account

'Visit Website and Lose Your Crypto': Ledger Exec Issues Warning About Safari Attack

Ledger Chief Technology Officer Charles Guillemet has issued a security warning to cryptocurrency holders regarding DarkSword, a sophisticated iOS exploit chain that compromises iPhones via malicious web pages accessed through Apple's Safari browser. The exploit chain allows attackers to bypass built-in security protections, escape browser sandboxing, and gain access to the iOS kernel, potentially enabling the theft of sensitive data, credentials, and stored cryptocurrency wallet recovery phrases. Originally disclosed by the Google Threat Intelligence Group in March, DarkSword has been actively exploited in the wild since at least November 2025, targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. The sophisticated malware specifically targets Safari's JavaScriptCore engine and circumvents Apple's Pointer Authentication Codes (PAC) to escalate privileges. While Google confirmed that the six core vulnerabilities in the chain were addressed starting in the iOS 26.3 release, security experts emphasize the critical importance of keeping Apple devices updated to the latest software versions to protect digital assets against ongoing WebKit and kernel-level threats.

Category

Apple

Sentiment

Bearish

Event

Security incident

Reading time

1 min