EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

SlowMist CISO警告:全链条iOS漏洞窃取加密钱包密钥

2026-09-20 20:22:19
Bookmark

SlowMist Chief Information Security Officer issues an urgent warning: iOS users need to update their devices immediately to prevent private keys from being stolen.

On September 19, SlowMist Chief Information Security Officer 23ps issued an urgent warning. After confirming that attackers had exploited a complete chain of iOS vulnerabilities and were able to quietly steal private keys and mnemonics in encrypted wallets, he called on iPhone users to immediately update their devices. The disclosure was released by researchers on the X platform and involved devices running iOS 13 to iOS 26.5, posing a serious threat to self-managed assets stored in mobile wallets.

How the vulnerability chain works

The attack begins when the target user accesses malicious web pages in Safari, usually through social engineering or "puddle" links. This page exploits memory corruption vulnerabilities in WebKit and JavaScriptCore to gain arbitrary read and write permissions at the JavaScript level. Subsequently, the attack chain bypasses Pointer Authentication Codes to gain native code execution privileges, breaks through the WebContent sandbox restrictions, and elevates privileges to kernel-level root privileges. This sequence of operations is enough to read the device's keychain and extract wallet application data, including private keys and recovery phrases.

Unlike traditional phishing pages that trick users into manually entering mnemonic words, this chain of attacks requires no user action and is triggered by just clicking a link, which is why the warning is so urgent.

Affected scope and risks

23pds指出,受影响的系统版本范围为iOS 13至iOS 26.5,同时表示上限版本仍需最终确认。由于该漏洞直接从设备中提取密钥,一旦钱包被攻破,无法通过密码重置来恢复——任何持有提取出的密钥的人都可以转移资金。对于自托管用户而言,威胁最为严峻,因为在设备层面窃取的密钥使得交易所侧的恢复机制完全失效。

这一警告的背景是零售加密货币持有者面临的移动设备和应用商店威胁日益增加。此前曾有一起案例,苹果公司因一起87.5万美元的盗窃案而被指控在其App Store上保留了一个虚假的比特币钱包。

用户应采取的措施

慢雾的建议非常明确:立即将iOS更新至最新版本;避免点击Safari中收到的不明链接;对于曾在易受攻击的设备上使用过热钱包的用户,应在干净且已更新的设备上生成新密钥并转移资金。

此类事件遵循了针对加密货币用户的移动端优先和网络钓鱼攻击的模式,安全公司曾多次对此类战术发出警示。截至目前,慢雾尚未发布更详细的正式咨询报告,因此研究人员的帖子仍是目前主要的公开披露信息。

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP