iPhone spyware hunts crypto wallets every 15 seconds

iEXExchanger
iPhone spyware hunts crypto wallets every 15 seconds

Security researchers at iVerify and Censys uncovered P7 DarkSword, iPhone spyware that scans devices for crypto wallets and exfiltrates passwords, recovery phrases and notes every 15 seconds.

Two separate security research teams — iVerify and Censys — have uncovered iPhone spyware built specifically to go after crypto wallets. The platform is called P7 DarkSword, and the module that actually drains wallets has its own name: Coruna.

iVerify found the infection in August on the phone of an employee at a financial institution, then published its findings on October 8. Around the same time, Censys stumbled onto an exposed attacker server holding 11 real victim seed phrases, 179 folders of stolen device data, and 75 operator accounts. That setup looks less like a one-off hack and more like a commercial platform running an affiliate program.

The attack chain needs two steps. First, a victim has to get infected — through a phishing link or a malicious ad exploiting bugs in WebKit and JavaScriptCore. That lets the attacker break out of Safari's sandbox, reach the iOS kernel, and plant theft modules directly inside wallet apps already sitting on the phone.

Censys counted 18 modules tuned for different wallets, including MetaMask, Trust Wallet, Coinbase, Phantom, Exodus, imToken, Bitpie and BitKeep. The malware scans Notes and photos for strings that match the BIP39 format used for wallet recovery phrases, while separately pulling passwords out of Keychain, Apple's built-in credential store. It phones home to attacker servers every 15 seconds.

Earlier DarkSword variants were tied to commercial surveillance vendors and suspected state clients, with past targets including journalists and activists in Saudi Arabia, Turkey, Malaysia and Ukraine. The pivot toward crypto theft is the new twist here: tools built for watching people are now being monetized to steal their money directly.

Researchers stopped short of naming who runs the P7 branch. The infrastructure traces back to Tencent hosting and servers in Shenyang, which isn't the same thing as pinning this on the Chinese state — attribution is still an open question. There's no confirmed tally yet of total victims or stolen funds beyond what turned up on that one exposed server. Updating to iOS 18.7.7 or later closes the known vulnerabilities in the attack chain; Apple recommends Lockdown Mode for anyone who can't update right away.

Questions and answers

Frequently asked questions about this article

What is P7 DarkSword and how does it get onto an iPhone?

It's a version of the DarkSword spyware platform with a dedicated module called Coruna, built specifically to go after crypto wallets. Infection requires an initial step: the victim must click a phishing link or a malicious ad that exploits WebKit and JavaScriptCore bugs to break out of Safari's sandbox.

Which crypto wallets are at risk?

Censys found 18 modules tuned for different apps, including MetaMask, Trust Wallet, Coinbase, Phantom, Exodus, imToken, Bitpie and BitKeep. The malware scans Notes and photos for BIP39-format recovery phrases and also pulls passwords from Keychain.

How can I protect my iPhone and crypto wallet?

Update to iOS 18.7.7 or later — it closes the vulnerabilities the attack chain relies on. If an update isn't available, Apple recommends turning on Lockdown Mode. Avoid clicking suspicious links or ad banners, especially on a phone with wallet apps installed.

Is this a mass attack on all iPhone owners?

There's no confirmed evidence of infection at mass scale — only the contents of the one exposed server with data from 11 victims are known so far. Infection requires that first step, a click on a malicious link or ad, so it isn't a zero-click attack, though the full scope of the campaign remains unclear.