A newly uncovered iPhone exploit known as DarkSword is drawing widespread attention online after cybersecurity researchers revealed it could silently access sensitive user data — including crypto wallets, messages and photos — through Apple’s Safari browser.
The threat, first detailed in a BleepingComputer report and backed by findings from Google’s Threat Intelligence Group, Lookout and iVerify, targets devices running iOS 18.4 through 18.7, a range that still accounts for an estimated hundreds of millions of active iPhones worldwide.
Unlike traditional hacks that require downloads or user interaction, DarkSword operates through what experts call a “zero-click” or drive-by attack. In many cases, simply visiting a compromised website in Safari is enough to trigger the exploit.
Researchers say the attack begins when a user lands on a hacked or malicious site, where hidden JavaScript code executes inside Safari. From there, DarkSword chains together six separate software vulnerabilities to break out of Apple’s security protections.
The process ultimately allows attackers to gain deep system-level access, meaning they can move beyond apps and into the core of the device itself.
Once inside, the exploit deploys data-stealing components — including a module known as GHOSTBLADE — that can quickly extract information and send it to external servers, often within seconds.
The scope of data targeted has raised particular concern, especially among users who store financial information on their phones.
According to researchers, DarkSword is capable of accessing:
- Saved passwords and login credentials
- Cryptocurrency wallet data, including private keys
- Text messages and iMessages
- Photos, media files and health data
- Contacts, call logs and location history
The emphasis on crypto-related data has made the exploit especially alarming for users managing digital assets on mobile wallets.
Investigators say DarkSword has already been used by multiple groups, ranging from state-linked actors to financially motivated hackers.
Early activity has been tied to a suspected Russia-linked group targeting Ukrainian websites, while other campaigns have reportedly focused on users in regions including the Middle East and Southeast Asia. Researchers also noted signs that cybercriminals are using the exploit specifically for cryptocurrency theft.
The broader concern is how quickly tools like DarkSword can spread once they are discovered or sold, turning advanced exploits into widely accessible hacking kits.
Apple has since patched the vulnerabilities tied to DarkSword in iOS 26.3.1 and later updates, effectively blocking known versions of the attack.
Still, experts warn that users who haven’t updated their devices remain vulnerable.
Security recommendations include:
- Updating to the latest iOS version
- Enabling Lockdown Mode for added protection
- Using stronger passcodes and biometric security
- Moving large crypto holdings to hardware wallets
- Avoiding suspicious links and unfamiliar websites
News of the exploit quickly spread across social media, where reactions ranged from concern to humor. Some users joked about older iPhones struggling to keep up with updates, while others shared practical advice on securing digital assets and avoiding risky browsing behavior.
While DarkSword itself has been addressed through software updates, cybersecurity experts say the incident underscores a larger issue: outdated devices continue to be one of the easiest entry points for attackers.
As mobile threats become more sophisticated, simply keeping software up to date may be one of the most effective defenses users have.


