Two separate security research teams — iVerify and Censys — have uncovered iPhone spyware built specifically to go after crypto wallets. The platform is called P7 DarkSword, and the module that actually drains wallets has its own name: Coruna.
iVerify found the infection in August on the phone of an employee at a financial institution, then published its findings on October 8. Around the same time, Censys stumbled onto an exposed attacker server holding 11 real victim seed phrases, 179 folders of stolen device data, and 75 operator accounts. That setup looks less like a one-off hack and more like a commercial platform running an affiliate program.
The attack chain needs two steps. First, a victim has to get infected — through a phishing link or a malicious ad exploiting bugs in WebKit and JavaScriptCore. That lets the attacker break out of Safari's sandbox, reach the iOS kernel, and plant theft modules directly inside wallet apps already sitting on the phone.
Censys counted 18 modules tuned for different wallets, including MetaMask, Trust Wallet, Coinbase, Phantom, Exodus, imToken, Bitpie and BitKeep. The malware scans Notes and photos for strings that match the BIP39 format used for wallet recovery phrases, while separately pulling passwords out of Keychain, Apple's built-in credential store. It phones home to attacker servers every 15 seconds.
Earlier DarkSword variants were tied to commercial surveillance vendors and suspected state clients, with past targets including journalists and activists in Saudi Arabia, Turkey, Malaysia and Ukraine. The pivot toward crypto theft is the new twist here: tools built for watching people are now being monetized to steal their money directly.
Researchers stopped short of naming who runs the P7 branch. The infrastructure traces back to Tencent hosting and servers in Shenyang, which isn't the same thing as pinning this on the Chinese state — attribution is still an open question. There's no confirmed tally yet of total victims or stolen funds beyond what turned up on that one exposed server. Updating to iOS 18.7.7 or later closes the known vulnerabilities in the attack chain; Apple recommends Lockdown Mode for anyone who can't update right away.



