Live iOS Safari Exploit Is Draining Crypto Wallets
A live iOS exploit chain is stealing cryptocurrency straight from iPhones, and one of the industry's most prominent security voices is telling holders to get their keys off the device now. On September 21, Charles Guillemet, chief technology officer at Ledger, warned that two exploit kits known as Coruna and DarkSword are being used in the wild to drain wallets after a single tap in Safari.
Guillemet described the full attack path. A victim is socially engineered into opening a link in Safari, which triggers a WebKit and JavaScriptCore memory corruption bug, followed by a pointer authentication bypass, a sandbox escape, and finally kernel and root access. The attacker then reads the iOS Keychain and wallet storage and exfiltrates seed phrases and private keys. "In plaintext, you visit a website and lose your crypto," he wrote, urging anyone who keeps a seed phrase on an iPhone to "treat this as a wake-up" and move to a hardware wallet.
The two kits were first documented in March by Google's Threat Intelligence Group. Coruna, disclosed on March 3, bundles 23 exploits spanning iOS 13.0 through 17.2.1, and a later build was modified specifically to drain crypto wallets. DarkSword, detailed on March 18, chains six vulnerabilities, three of them zero-days, into a no-click takeover of iOS 18.4 through 18.7. Researchers described the infection as silent: an invisible frame on a compromised but legitimate website loads code that fingerprints the phone and runs the chain in seconds, then wipes forensic traces.

The alarming shift is who now holds these tools. Originally nation-state-grade spyware, the kits have reportedly been adopted by financially motivated crews that plant fake gambling and cryptocurrency sites to harvest wallet data, putting espionage-tier exploitation to work on ordinary theft.
The scale of that theft is already large. Wallet-drainer operations stole close to $494 million from more than 332,000 addresses in 2024, according to Scam Sniffer, and roughly $83.85 million in 2025 as attackers shifted toward fewer but higher-value targets. A phone-resident exploit that needs only a single click removes the last friction from that model.
The defensive advice is consistent. Update iOS immediately, since each kit depends on specific bugs that patched versions close. Avoid opening unfamiliar links in Safari on any device that is not current. Above all, do not store seed phrases or private keys on an internet-connected phone. A hardware wallet keeps the keys in a separate device that never exposes them to a browser, so even a fully compromised handset cannot sign a transaction or surrender the recovery phrase.
The gap between a routine web click and an emptied wallet has narrowed to one tap. Once the keys leave the phone, the funds are gone.



