iPhone Hacking Toolkit Is Still Stealing Crypto Wallets, Censys Warns
Published October 11, 2026, 05:30 PKT. Based on reporting by Macworld and The Bit Gazette, with research findings from Censys and threat analysis from Malwarebytes.
Security researchers at Censys have found five exposed servers running an operational iPhone exploitation platform built on the DarkSword and Coruna toolkits, months after the attack tools were first disclosed. The finding, reported on October 9, 2026, shows the DarkSword and Coruna toolkits are still staged for use against unpatched devices and are configured to steal cryptocurrency wallets.
DarkSword and Coruna work as a pair. According to Macworld's October 9 report, DarkSword attacks Apple's WebKit and JavaScriptCore components to gain access to SpringBoard, the iOS layer that manages app launch and the home screen. Coruna is the payload: it steals information from crypto wallet apps and scans the device's Photos and Notes for BIP39 recovery phrases, the seed phrases that give criminals full access to a wallet's funds.
Five live servers, nine targeted wallets
Censys researchers discovered several servers with DarkSword and Coruna deployment directories still active, The Bit Gazette reported. The targeted wallet apps include Bitpie, Coinbase, Exodus, imToken, MetaMask, Phantom, Trust Wallet, Uniswap and OKEx, according to Macworld's account of the Censys research.
The threat goes beyond wallet apps. Censys found that the malware's main purpose is wallet theft, but it also mines the victim's Photos and Notes for recovery phrases, which means a screenshot of a seed phrase saved to a photo library is enough to hand a wallet to the attacker.
Fake iPhone Duo preorder watering holes
The exploit is also being delivered through fake shopping pages. Malwarebytes found fraudulent pages imitating Apple's branding to advertise preorders for a fictional "iPhone Duo," with wrong device sizes, colors Apple does not offer, and a countdown timer that resets on every reload, eSecurity Planet reported. The preorder form is a distraction: a hidden frame checks the visitor's iOS version in the background, and the page pushes iPhone users into Safari, the browser the exploit chain targets.
Malwarebytes found that a successful attack against an unpatched device can attempt to access Apple Notes, installed-app information, saved credentials and cryptocurrency wallets, plus messages, contacts, call history, voicemail, email, calendars, photos and cached location data. No download, form submission or tap is needed for the attack to begin.
Only unpatched iPhones are exposed
Apple has already fixed every vulnerability the DarkSword chain uses. The holes were patched in iOS 26.3, and the current release is iOS 27.0.1, according to Macworld. Only devices running iOS 26.2 and below, including older versions of iOS 18, remain vulnerable, and only if their owners have not installed the security updates.
Users can update in Settings, then General, then Software Update. Apple also offers immediate security patches through Background Security Improvements, found under Settings, then Privacy and Security, at the bottom of the page. Anyone with crypto on an iPhone should also keep recovery phrases offline and out of photos and notes entirely, since that habit protects against this class of attack regardless of the device.
This article is news reporting and is not investment advice.
Sources
- Macworld (Roman Loyola), "DarkSword and Coruna iOS exploits continue to attack crypto wallets" (Oct. 9, 2026), primary source
- Censys, security research findings on DarkSword and Coruna deployment servers, primary source
- The Bit Gazette, "Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases" (Oct. 10, 2026), secondary source
- eSecurity Planet, "Fake iPhone Duo Preorders Launch DarkSword Exploit Attempts" (Oct. 9, 2026), secondary source citing Malwarebytes
MABOnChain Daily Brief
The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.
Prefer chat? Join us on Telegram
Keep reading
Robinhood Chain Transactions Fall 42% as Memecoin Frenzy Fades
Robinhood Chain averaged 6.2 million daily transactions during Oct. 2-8, down 42% from mid-September, as the memecoin trading that drove its record fee days cooled. Deposits held above $1 billion while spot volume fell 21%, according to CoinDesk's analysis of growthepie and DefiLlama data.
Justin Sun Says TRON's Post-Quantum Cryptography Is Live on Testnet
TRON founder Justin Sun said on October 10 that the network's post-quantum cryptography is now running on testnet and is ready to move to mainnet at any time, positioning TRON to be among the few major blockchains to reach quantum resistance before Q-Day, with no mainnet launch date announced.
Tether Froze $1.45M in THORChain's TRON Vaults, Stalling Cross-Chain Swaps for Two Hours
Tether blocklisted four of THORChain's six TRON vaults on October 9, freezing about $1.45 million in USDT and halting cross-chain swaps for nearly two hours before reversing the freeze, a reminder that a stablecoin issuer can override a decentralized exchange without warning.


