Glass Ledger

iPhone Wallet Key Theft: What To Do, In Order

A full-chain iOS exploit can silently pull crypto wallet keys from Safari alone. Here is the order of checks and fixes to run right now.

Escalation ladder diagram showing an iOS exploit chain climbing from a Safari page through a PAC bypass to kernel root and Keychain key extraction

On September 19, security firm SlowMist's chief information security officer, known publicly as 23pds, told iPhone users to stop what they were doing and update their devices. His team had confirmed a live iPhone crypto wallet exploit: a full-chain iOS attack capable of silently pulling private keys and mnemonic seed phrases out of crypto wallet apps. No phishing message, no fake support call, no typed-in seed phrase required. Visiting the wrong web page in Safari was enough.

That single detail is why this iPhone crypto wallet exploit is worth fifteen minutes of a Saturday. Most wallet-draining stories involve a victim who was tricked into doing something. This one does not. Below is the order to work through, because some of these steps matter more than others and doing them out of sequence wastes the time that matters most.

First: Check whether this iPhone crypto wallet exploit affects you

The exploit chain is reported to target iOS versions 13 through 26.5, which is effectively every iPhone still receiving any kind of support and plenty that no longer do. One caveat belongs up front: 23pds flagged the upper bound of that range as still pending final confirmation, and at least one early relay of the same warning put the ceiling at iOS 16.5 instead. Treat the wide range as the cautious assumption rather than a settled fact. The attack begins with a memory-corruption bug in WebKit and JavaScriptCore, the engines that render web pages and run JavaScript in Safari and in any app using Apple's required WebView. That bug hands the attacker arbitrary read and write access at the JavaScript layer, which sounds abstract until you know what it leads to next.

If you have ever opened a crypto wallet app, a wallet browser extension synced through Safari, or an exchange app on an iPhone, you are in the exposed population. It does not matter whether the wallet itself has a bug. The exploit does not attack the wallet software. It attacks the operating system underneath it, then reads whatever the wallet has stored.

Then: Update iOS immediately, before anything else on this list

From that JavaScript-layer foothold, the chain bypasses Apple's Pointer Authentication Codes, a hardware-level defense meant to stop exactly this kind of memory manipulation. From there it escapes Safari's WebContent sandbox and escalates to kernel-level root access, the same privilege level as the operating system itself. At that point the device's Keychain, the encrypted store where iOS keeps passwords and often the local data wallet apps rely on, is readable. So is anything a wallet app cached in plain memory.

Updating is SlowMist's own first instruction, and it is the right first move, but it is worth being precise about what it buys. Apple has not publicly tied a specific security update to this chain, and if the reported upper bound holds, the newest release sits inside the affected range rather than outside it. What an update reliably does is close whichever stages of a chain like this Apple has already patched, which is a real reduction in exposure and costs nothing. What it does not do is guarantee immunity to a chain whose full scope the researcher has not finished confirming. That gap is exactly why the remaining steps on this list are not optional.

The entry point for this chain is a malicious web page, typically reached through a link sent via social engineering or planted on a compromised legitimate site, sometimes called a watering-hole attack. Until you have confirmed your update installed cleanly, treat any unsolicited link in a DM, group chat, or comment thread as radioactive, even one that looks like it came from someone you know. Group chats and comment sections are exactly where these links get seeded, because a familiar sender bypasses the skepticism a stranger would trigger.

This is a temporary precaution, not a lifestyle change. Once your device is patched against the disclosed chain, ordinary browsing risk returns to its normal baseline. The elevated risk window is now, while the exploit is fresh and unpatched devices are still common.

Finally: If you held a hot wallet on a vulnerable device, move funds to fresh keys

This is the step people skip because it is the most annoying, and it is also the one that actually matters if you were exposed before patching. Updating iOS today does not retroactively protect a private key that may have already been read by an attacker who compromised your device last week. If you kept meaningful funds in a hot wallet on an iPhone that has not been updated recently, the safe assumption is that the key material should be treated as burned. Generate a new wallet on a clean, freshly updated device, and move funds to the new address rather than hoping the old one was never touched.

This is exactly the argument for keeping any funds you are not actively spending off a hot wallet entirely. Solo mining rewards through NexusPool's non-custodial setup pay directly to whatever address you configure, which can be a hardware wallet or cold storage address that never touches an iPhone's Safari browser at all. NexusPool holds nothing in between, so there is no pool-side custodial balance for this kind of exploit to reach, and how that payout path is built is documented rather than simply promised. That protection stops at the pool's own design. It says nothing about the security of whatever wallet or device you point your payouts at, which remains entirely your responsibility to secure.

What the iPhone crypto wallet exploit does not change about mining odds

None of this changes how solo mining works. Your odds of finding a block are set by your hashrate divided by the network's total hashrate, identical for every miner on that chain, and no pool, exploit, or security practice changes that math. This post is not investment advice and mining is not a guaranteed return. What is actually controllable is where the payout for a found block goes and how well you protect whatever wallet receives it, which is where this exploit lives. NexusPool's signed Glass Ledger receipts let you verify pool-side work and payouts independent of trust in the operator, but a signed receipt cannot fix a compromised phone.

For a technical walkthrough of the exploit chain itself, including the specific WebKit and JavaScriptCore bugs involved, Phemex's coverage of the disclosure lays out the stages in more depth than fits here.

Recap, in order

Check your iOS version and whether you run any wallet app on it. Update immediately, before doing anything else. Avoid unfamiliar Safari links for the next few days while the disclosed chain is fresh. If you had a hot wallet on an unpatched device, treat those keys as compromised and move to new ones on a clean device. None of this requires urgency for its own sake, but it does require doing it in this order, because updating first closes the door the other steps are trying to protect.

Trust nothing. Verify that the device holding your keys is actually the one you think it is.