Blockchain security firm SlowMist says it has not yet confirmed any actual cryptocurrency theft stemming from a recently analyzed attack targeting Apple's Safari browser on iPhones, tempering alarm over the exploit.
What the Attack Targets
The malicious Safari sample examined by researchers is designed to affect iPhones running iOS versions 18.4 through 18.6.2. According to SlowMist's analysis, the exploit leverages security flaws that Apple has already addressed in prior software updates, meaning devices kept current should be shielded from the technique.
That detail is central to the firm's cautious messaging. Rather than describing an active, widespread threat capable of draining wallets, the analysis points to an attack vector reliant on vulnerabilities that have since been patched.
No confirmed crypto theft has yet been linked to the Safari exploit, according to SlowMist.
Unverified on Newer Systems
Crucially, the sample's effectiveness against newer software remains unproven. SlowMist noted that whether the exploit works on iOS 26.5 has not been verified, leaving open questions about how relevant the threat is to users on the latest releases.
The firm's stance underscores a broader challenge in crypto security reporting, where early samples and proof-of-concept exploits can circulate before their real-world impact is established. Confirming actual losses often requires tracing on-chain movements and victim reports, neither of which SlowMist has said it has documented in this case.
For iPhone owners who manage digital assets, the practical takeaway centers on basic security hygiene:
- Keep iOS updated to the latest available version
- Be cautious when interacting with unfamiliar links in Safari
- Use hardware wallets or dedicated devices for significant holdings
Why Caution Matters
Security researchers frequently publish findings on potential attack methods to raise awareness and encourage patching, but not every disclosed sample translates into confirmed victims. SlowMist's decision to hold off on declaring theft reflects an evidence-based approach amid heightened concern over mobile-based crypto attacks.
Until further verification emerges, the analyzed Safari sample appears to represent a demonstration of previously patched weaknesses rather than proof of an ongoing campaign siphoning funds from users' devices.
