Security firm SlowMist stated it has not independently confirmed any victim compromised by the specific Safari attack sample analyzed, countering reports that linked the vulnerability to immediate cryptocurrency losses. While multiple alerts urged iPhone users to update devices due to risks of exposed private keys and seed phrases across iOS 13 through 26.5, SlowMist clarified that its strongest technical evidence covers only iOS 18.4 through 18.6.2. The company advised treating the broader version range as preliminary until reproducible technical evidence exists for newer versions like iOS 26.5.
The attack reuses techniques from the DarkSword exploit chain, disclosed by Google Threat Intelligence Group in March, and is distinct from other investigations such as FomoPeek. SlowMist’s MistEye team identified the activity in early May and published analysis of the WYINCC campaign on Sept. 4, detailing a malicious webpage that loads exploit code without requiring user interaction. Although the sample includes components designed to access Apple’s Keychain and potentially expose crypto wallet data, SlowMist noted that the vulnerabilities were already patched by Apple. The firm emphasized that while the code demonstrates collection capabilities, it does not prove successful extraction from every targeted wallet, recommending users install updates, consider Lockdown Mode, and move assets if compromise is suspected.
The discrepancy between broad public warnings and SlowMist’s narrower technical confirmation highlights the critical importance of distinguishing between theoretical vulnerability ranges and verified exploitation vectors. By clarifying that the "iOS 13 to 26.5" scope is preliminary and that their evidence specifically supports iOS 18.4 through 18.6.2, SlowMist mitigates unnecessary panic among users with older or very new devices who may be outside the confirmed risk window. This precision matters because it shifts the focus from blanket device retirement or extreme caution to targeted patching and behavioral hygiene, ensuring resources are allocated where actual threat intelligence points rather than where speculative headlines suggest.
From an operational security perspective, the case underscores the persistent risk of zero-click exploits leveraging previously patched vulnerabilities through social engineering campaigns like the WYINCC VPS lure. Even though Apple had addressed the underlying flaws, the existence of a functional exploit chain capable of accessing Keychain data demonstrates that legacy malware can remain potent against unpatched systems. The recommendation to use Lockdown Mode as a defense, coupled with the advice to migrate assets to clean devices upon suspicion, reflects a pragmatic approach to residual risk management. It suggests that while infrastructure-level patches are essential, institutional and individual actors must maintain robust incident response protocols that assume potential exposure even when direct theft is not yet confirmed.


