Safari Attack Targets iOS 18.4–18.6.2 With Patched Exploit Techniques
The sample could access Keychain data and app files, but no cryptocurrency theft or successful compromise has been confirmed. Its effectiveness on iOS 26.5 remains unverified.

An iPhone Safari attack has not been linked to a confirmed cryptocurrency theft, although the analyzed sample could access data that may include wallet credentials.
The sample targets iOS 18.4–18.6.2 and reuses techniques from the previously disclosed DarkSword exploit chain. Apple had previously fixed and publicly documented the security flaws exploited by the malicious code. Claims that the activity affects iOS 13 through iOS 26.5 remain preliminary, with no reproducible technical evidence establishing that iOS 26.5 is affected.
The malicious Safari page advertised a free virtual private server service and could load exploit code when opened on an iPhone without necessarily requiring another click. The sample included a component designed to access Apple’s Keychain, decrypt stored information and read app files and shared app data.
That access could expose information held by cryptocurrency wallet applications, potentially including private keys or seed phrases. However, the sample demonstrated collection capability and its intended targets; it did not prove successful extraction from every targeted wallet.
The full exploit chain was not executed on a real victim device, so no specific person has been independently confirmed as successfully compromised by this sample.
The campaign, identified as WYINCC, is separate from an earlier TokenPost report on FomoPeek as distinct from FOMO’s official iOS app. FomoPeek was a malicious application previously linked to cryptocurrency wallet credential risks.
Users should install the latest available iOS security updates and avoid suspicious links. Apple’s Lockdown Mode may provide an additional defense for people facing elevated risks, although it has not been confirmed to completely block this Safari attack.
Anyone who believes a wallet key or seed phrase may have been exposed should move assets to a newly generated wallet on a clean device.


