Darksword iphone exploit hunts crypto wallets in 18.4–18.6.2, 270 million devices still naked

Two weeks after Coruna bled bank apps dry, a nastierkit called Darksword is sliding through the same zero-day wound in iOS 18.4–18.6.2, emptying MetaMask, Trust and Coinbase wallets while Apple insists the patch has already shipped.

The malware that laughs at the update prompt

Google TAG, iVerify and Lookout traced the first wave to Saudi finance officers, Turkish crypto influencers, Malaysian opposition staffers and a handful of Ukrainian NGOs. The infection chain is almost insultingly simple: a LinkedIn recruiter, an iMessage from a hijacked friend, or a missed-call notification lures the target to a domain that looks like Apple’s own enterprise-signing portal. One tap and Darksword sideloads a weaponized TestFlight build that survives reboots and hides inside the iOS VPN daemon. Once resident, it scrapes seed phrases, cookies and Face ID templates, then radios everything to a bulletproof host in Moldova before the victim finishes coffee.

Apple’s response arrived in six identical paragraphs mailed to every outlet: “These exploits target outdated software; users should update to iOS 26 or later.” The boilerplate ignored the obvious—26 is unavailable on iPhone X, XS and XR, the same models that still dominate secondary markets in the four countries under fire. Security engineers at iVerify ran the numbers: roughly 270 million iPhones boot a vulnerable fork every morning. Even in the US, 12 percent of active devices remain frozen on 18.6.2, either because carriers throttle the download or because users fear the performance hit.

Market price for a phone-sized nuclear bomb

Market price for a phone-sized nuclear bomb

Rocky Cole, iVerify COO, told Coastal Code the going rate for a chain that defeats PAC and AMFI now sits around eight million dollars, down from twenty-five in 2023. “Demand is no longer limited to NSO and Candiru,” he said. “Private equity shops, ransomware cartels and even OnlyFans pirates want in.” The drop in cost explains why two unrelated exploit packs surfaced inside a month; supply is catching up with appetite.

Apple has quietly blacklisted the command-and-control domains through Safari Safe Browsing, but that only protects the browser. If the victim grants a profile or accepts a TestFlight invitation, the malware gains root-equivalent entitlements and Safe Browsing never enters the chat. Cupertino’s next move is a mandatory notarization scan for all ad-hoc provisioning certificates, yet the change is parked behind iOS 27, still in beta.

Until then, the only real defense is surgical hygiene: kill TestFlight invites you didn’t request, delete configuration profiles that mention “VPN management,” and, if you’re parking more than beer money in crypto, move the seed to a separate hardware wallet. The 270 million figure is not a rounding error; it is the entire population of Indonesia, all holding glass slabs that silently broadcast private keys to Moldovan servers. Apple patched the hole, but the herd never updates—so the hole stays open.