Security firm SlowMist stated it has not independently confirmed any victim compromised by the specific Safari attack sample analyzed, countering reports that linked the vulnerability to immediate cryptocurrency losses. While multiple alerts urged iPhone users to update devices due to risks of exposed private keys and seed phrases across iOS 13 through 26.5, SlowMist clarified that its strongest technical evidence covers only iOS 18.4 through 18.6.2. The company advised treating the broader version range as preliminary until reproducible technical evidence exists for newer versions like iOS 26.5.

The attack reuses techniques from the DarkSword exploit chain, disclosed by Google Threat Intelligence Group in March, and is distinct from other investigations such as FomoPeek. SlowMist’s MistEye team identified the activity in early May and published analysis of the WYINCC campaign on Sept. 4, detailing a malicious webpage that loads exploit code without requiring user interaction. Although the sample includes components designed to access Apple’s Keychain and potentially expose crypto wallet data, SlowMist noted that the vulnerabilities were already patched by Apple. The firm emphasized that while the code demonstrates collection capabilities, it does not prove successful extraction from every targeted wallet, recommending users install updates, consider Lockdown Mode, and move assets if compromise is suspected.