MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / Scam Alerts / iPhone Hacking Toolkit Is Still Stealing Crypto Wallets, Censys Warns
Scam Alerts

iPhone Hacking Toolkit Is Still Stealing Crypto Wallets, Censys Warns

By MABOnChain Desk · Published · Updated · 5 min read

Editorial digital-art illustration of a giant glowing smartphone being cracked open by red serpent-like code streams and skeletal digital tentacles reaching from shadowy server racks, ghostly seed-phrase words floating out of the wallet screen into a hacker's net, small coins and shield icons scattered below, dramatic red and cyan lighting on deep navy black.

Published October 11, 2026, 05:30 PKT. Based on reporting by Macworld and The Bit Gazette, with research findings from Censys and threat analysis from Malwarebytes.

Security researchers at Censys have found five exposed servers running an operational iPhone exploitation platform built on the DarkSword and Coruna toolkits, months after the attack tools were first disclosed. The finding, reported on October 9, 2026, shows the DarkSword and Coruna toolkits are still staged for use against unpatched devices and are configured to steal cryptocurrency wallets.

DarkSword and Coruna work as a pair. According to Macworld's October 9 report, DarkSword attacks Apple's WebKit and JavaScriptCore components to gain access to SpringBoard, the iOS layer that manages app launch and the home screen. Coruna is the payload: it steals information from crypto wallet apps and scans the device's Photos and Notes for BIP39 recovery phrases, the seed phrases that give criminals full access to a wallet's funds.

Five live servers, nine targeted wallets

Censys researchers discovered several servers with DarkSword and Coruna deployment directories still active, The Bit Gazette reported. The targeted wallet apps include Bitpie, Coinbase, Exodus, imToken, MetaMask, Phantom, Trust Wallet, Uniswap and OKEx, according to Macworld's account of the Censys research.

The threat goes beyond wallet apps. Censys found that the malware's main purpose is wallet theft, but it also mines the victim's Photos and Notes for recovery phrases, which means a screenshot of a seed phrase saved to a photo library is enough to hand a wallet to the attacker.

Fake iPhone Duo preorder watering holes

The exploit is also being delivered through fake shopping pages. Malwarebytes found fraudulent pages imitating Apple's branding to advertise preorders for a fictional "iPhone Duo," with wrong device sizes, colors Apple does not offer, and a countdown timer that resets on every reload, eSecurity Planet reported. The preorder form is a distraction: a hidden frame checks the visitor's iOS version in the background, and the page pushes iPhone users into Safari, the browser the exploit chain targets.

Malwarebytes found that a successful attack against an unpatched device can attempt to access Apple Notes, installed-app information, saved credentials and cryptocurrency wallets, plus messages, contacts, call history, voicemail, email, calendars, photos and cached location data. No download, form submission or tap is needed for the attack to begin.

Only unpatched iPhones are exposed

Apple has already fixed every vulnerability the DarkSword chain uses. The holes were patched in iOS 26.3, and the current release is iOS 27.0.1, according to Macworld. Only devices running iOS 26.2 and below, including older versions of iOS 18, remain vulnerable, and only if their owners have not installed the security updates.

Users can update in Settings, then General, then Software Update. Apple also offers immediate security patches through Background Security Improvements, found under Settings, then Privacy and Security, at the bottom of the page. Anyone with crypto on an iPhone should also keep recovery phrases offline and out of photos and notes entirely, since that habit protects against this class of attack regardless of the device.

This article is news reporting and is not investment advice.

Sources

  • Macworld (Roman Loyola), "DarkSword and Coruna iOS exploits continue to attack crypto wallets" (Oct. 9, 2026), primary source
  • Censys, security research findings on DarkSword and Coruna deployment servers, primary source
  • The Bit Gazette, "Exposed servers reveal DarkSword toolkit built to steal iPhone crypto seed phrases" (Oct. 10, 2026), secondary source
  • eSecurity Planet, "Fake iPhone Duo Preorders Launch DarkSword Exploit Attempts" (Oct. 9, 2026), secondary source citing Malwarebytes
Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading

Markets

Robinhood Chain Transactions Fall 42% as Memecoin Frenzy Fades

October 10, 2026 · 5 min read

Robinhood Chain averaged 6.2 million daily transactions during Oct. 2-8, down 42% from mid-September, as the memecoin trading that drove its record fee days cooled. Deposits held above $1 billion while spot volume fell 21%, according to CoinDesk's analysis of growthepie and DefiLlama data.

Web3

Justin Sun Says TRON's Post-Quantum Cryptography Is Live on Testnet

October 10, 2026 · 5 min read

TRON founder Justin Sun said on October 10 that the network's post-quantum cryptography is now running on testnet and is ready to move to mainnet at any time, positioning TRON to be among the few major blockchains to reach quantum resistance before Q-Day, with no mainnet launch date announced.