Mark RadarMARK RADAR
EN
Event File CRYPTO Cryptocurrency Wallets

DarkSword iOS Exploit Targets Crypto Wallets as Mobile Attacks Turn Financially Motivated

7 reports · First detected 2026-03-19 · Last active 2026-03-23

High-end iOS exploits were once used mainly for government surveillance and intelligence gathering. Smartphones now hold identity credentials, communications and crypto assets, making them a direct avenue for monetization. Google's Threat Intelligence Group (GTIG), Lookout and iVerify said DarkSword can silently compromise an iPhone when a user visits a hacked website, stealing private keys, wallets and login credentials. The campaign underscores a shift in attackers' motives toward financial crime.

GTIG, Lookout and iVerify disclosed DarkSword on March 18–19, 2026. The attacks date to November 2025, targeted four countries and chained six vulnerabilities affecting iOS 18.4 through 18.7. Apple fixed all the flaws in iOS 26.3 and released iOS/iPadOS 18.7.7 on March 24 to protect older devices. No victim count or value of stolen assets has been disclosed to date.

All Coverage

7 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR