Security research firm SlowMist remains unable to confirm whether a recently discovered Safari vulnerability on iPhones has led to actual cryptocurrency theft. The firm analyzed malicious code that exploits previously patched security flaws in Apple's browser across iOS versions 18.4 through 18.6.2, but the attack's real-world impact on crypto holdings stays unclear.

The vulnerability chain targets older iOS iterations using known exploits that Apple had already addressed in previous security patches. This approach suggests attackers recycled existing vulnerabilities rather than deploying zero-day attacks. SlowMist's inability to verify theft does not mean losses did not occur. It reflects the difficulty in attributing crypto movements to specific breach vectors, particularly when victims may not report compromises or when stolen funds move quickly through mixing services and bridge protocols.

The threat model here involves Safari's attack surface on iOS devices. Many cryptocurrency users access wallets, exchanges, and DeFi protocols through mobile browsers rather than native apps. A compromised browser with access to authentication cookies, private keys in browser storage, or session tokens creates direct pathways to user funds. The fact that the malware targets multiple iOS versions simultaneously indicates a broad targeting campaign rather than a narrowly focused attack.

What stands out: SlowMist explicitly notes uncertainty about whether the exploit functions on iOS 26.5. This version discrepancy matters because it reveals either incomplete threat intelligence or genuine technical barriers preventing exploitation on the latest iOS release. If the exploit fails on current versions, the attack window closes as users update devices. If it works but SlowMist cannot confirm it, the threat persists undetected.

The use of previously patched vulnerabilities rather than zero-days points to a specific attacker profile. Nation-state actors and sophisticated APT groups typically hoard zero-day exploits for high-value targets. This campaign appears more consistent with criminal groups or lower-tier threat actors recycling known CVEs against less security-conscious users. These groups exploit the gap between patch release dates and actual user adoption rates. Many iOS users delay updates, leaving their devices vulnerable to months-old attacks.

Cryptocurrency holders face a practical problem: browser-based interactions with wallets and exchanges remain endemic across mobile crypto usage. Hardware wallets mitigate this risk, but most retail users manage assets through web interfaces on their phones. A compromised Safari instance could harvest credentials, inject malicious code into transaction flows, or redirect users to phishing sites during critical financial operations.

SlowMist's open acknowledgment of unconfirmed theft carries weight in the security research community. The firm operates with methodological rigor, refusing to claim compromise confirmation without evidence. Other researchers and security vendors should examine similar Safari samples to establish whether this represents isolated technical discovery or an active campaign causing real losses.

The incident highlights ongoing iOS security tensions. Apple maintains strict app store controls but cannot prevent browser-based attacks without fundamentally limiting Safari functionality. Users who require access to crypto services face persistent trade-offs between convenience and security. Until SlowMist or others provide confirmed attribution of stolen assets to this specific exploit chain, the attack remains a theoretical threat with unknown real-world casualties.