Researchers expose live iPhone exploit platform harvesting crypto wallet recovery phrases

Researchers at Censys have uncovered live, exposed infrastructure running DarkSword and Coruna, a commercial iOS exploitation platform built specifically to extract cryptocurrency wallet recovery phrases from iPhones. The discovery, reported October 7-8 and detailed by Cyber Security News and Cyberpress, revealed five open servers handling delivery, staging, analysis, and control functions for what researchers describe as an "exploitation-as-a-service" operation.
DarkSword is not new — Google's Threat Intelligence Group and mobile security firm iVerify first documented the exploit chain in March 2026, when it was found chaining six vulnerabilities, three of them zero-days, to achieve remote code execution on vulnerable iPhones. What's new is the scale and specificity of the wallet-theft tooling built on top of it, and the fact that researchers found the operator's infrastructure still live and exposed when they looked.
The exploit chain itself attacks WebKit and JavaScriptCore to escape Safari's sandbox, escalates to kernel-level access, then injects its payload into SpringBoard — the iOS process that controls the home screen and app launches. From there, a SpringBoard-level coordinator watches for cryptocurrency wallet apps to open and injects a matching theft module into the running app, limited to one injection attempt every three seconds per app to avoid detection.
The theft mechanics are narrowly targeted: the implant searches Photos and Apple Notes for text matching the BIP39 standard used for wallet recovery phrases, and only exfiltrates strings that pass a checksum validation — filtering out random text and minimizing the data sent back to attacker servers. Researchers identified 18 wallet-specific modules in the exposed kit, targeting MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, imToken, and Bitpie, among others. A separate cluster of 22 in-the-wild samples added BitKeep as a 19th target.
A captured copy of the production environment contained 11 stolen recovery phrases, 179 device loot directories, and more than 75 operator accounts in the control panel — which supports commission rates, device quotas, and victim management for what appears to be a reseller-style operation. Censys was careful to note the data doesn't establish a confirmed victim count or total stolen cryptocurrency value; the loot directories don't all represent successful compromises.
Attribution remains unconfirmed. Censys linked the exposed infrastructure to hosting and a self-signed certificate authority tied to networks in China, including Tencent-linked hosting and systems in Shenyang, but stopped short of naming a specific threat group. A separate cluster of in-the-wild samples used different, hardcoded command-and-control infrastructure, suggesting multiple operators may be using the same underlying exploit tooling independently.
One detail is worth treating with caution rather than alarm: development files referenced CVE-2026-31001, a JavaScriptCore flaw targeting iOS 26, but researchers found the sandbox-escape and kernel-privilege components for that chain were incomplete placeholders — unfinished work, not a deployed attack. The exploit chains actually found in active use target older iOS versions that Apple has already patched in current releases.
For iPhone users holding cryptocurrency, the practical takeaway is specific: never store a wallet recovery phrase as a photo or a note on your phone. The entire theft mechanism in this campaign depends on exactly that habit. A phrase written on paper, or stored in a hardware wallet, is invisible to this style of attack regardless of whether a device is otherwise compromised.
Reported by Cyber Security News and Cyberpress, based on research from Censys.
Originally reported by Cyber Security News (Censys research). Read the original article for additional details.
View original source