If you hold crypto on an iPhone, you should know about this one.

Two iPhone hacking tools called DarkSword and Coruna are still being used to steal crypto wallet data. This isn’t old news. Researchers at Censys found that the tools are still active against iPhones running iOS 26.2 and earlier. The new findings came out just days ago.

Here’s what’s going on, in plain words.

What are DarkSword and Coruna?

They’re two different tools that work as a team.

DarkSword is the door opener. It attacks parts of Safari’s engine (WebKit and JavaScriptCore) to get deeper into the iPhone. Coruna is what comes in after. Coruna is the payload that goes after the crypto wallet information.

Think of it like a burglary. DarkSword picks the lock. Coruna walks in and grabs the valuables.

Where did they come from?

They’ve been around for a while, and they’ve changed hands.

Google’s Threat Intelligence Group first reported Coruna in February. It targets iPhones running iOS 13.0 through 17.2.1, and it packs 23 exploits across five full attack chains. Government-backed attackers used it first, in attacks on Ukrainian users. Later, Chinese scam websites used the full kit on fake finance and crypto sites.

DarkSword came a few weeks later. Lookout found it, and it has been used since late 2025 by several groups, including surveillance vendors and likely nation-state actors. Google’s March analysis described six vulnerabilities in the DarkSword chain, aimed at iOS 18.4 to 18.7.

So this started as spy tech. Now it’s being used for plain old money theft.

What’s new this month?

Censys found open directories on five servers between September 15 and 17, showing a working DarkSword/Coruna setup. That includes delivery servers, stolen-data logs, and files used to build exploits. Researchers also saw a full control panel with a database tracking victims, wallet data, and commands.

Some of the details are pretty alarming:

  • 18 wallet modules. They target apps like MetaMask, Coinbase, Phantom, Trust Wallet, Exodus, imToken, Bitpie, Uniswap, and OKEx.
  • It hunts for seed phrases in your photos and notes. Researchers say it mines Photos and Notes for BIP39 recovery phrases. That’s the 12 or 24 words that can unlock a wallet.
  • It reacts when you open a wallet app. The malware watches for a targeted wallet app to launch, then injects the matching theft module into it.
  • Real victims were seen. The devices in the data reportedly ran iOS 16.1 and iOS 16.3.1.
  • It looks like a business. Researchers found Chinese-language admin panels and reseller controls. Censys linked the infrastructure to a Chinese-speaking exploitation-as-a-service operation. In other words, criminals can rent this.

There’s also a newer version called P7 DarkSword. It’s stealthier, steals keychain and crypto wallet data, and checks in with its control server for new commands every 15 seconds.

Who’s at risk?

Mostly people on old iOS versions. That’s the key point.

Macworld reports that every security hole DarkSword uses was fixed as of iOS 26.3, and the current version is iOS 27.0.1. Coruna’s older chains hit iOS 17.2.1 and below, which are long out of date.

If your iPhone is fully updated, these specific tools should not work on it. If it’s stuck on an old version, you’re the target. That includes older phones that can’t take the newest iOS, and people who just keep tapping “Remind me later.”

How to protect your crypto wallet

None of this is hard. Do it today.

  1. Update your iPhone. Go to Settings > General > Software Update. Install the newest version available for your phone. This is the biggest fix by far.
  2. Delete any seed phrase from Photos, Notes, or screenshots. I’d say this is the most important one after updating. If a screenshot of your recovery phrase exists on your phone, malware can find it. Write it on paper instead.
  3. Be careful with links. Coruna was spread through fake finance and crypto websites built to lure iPhone users. Don’t open crypto links from texts, ads, or random DMs. Type the address yourself or use a saved bookmark.
  4. Use a hardware wallet for bigger amounts. Your keys stay off the phone, so there’s much less for malware to steal.
  5. Think about Lockdown Mode if you’re a high-risk person or hold a lot. It limits some features, but it shrinks the attack surface.
  6. Don’t keep everything in one hot wallet. Keep a small amount on your phone for daily use. Store the rest somewhere safer.

If you think you were hit, move your funds to a fresh wallet made on a clean, updated device. Don’t reuse the old seed phrase. Once it’s been seen, it’s burned.

The bottom line

This story shows how fast spy-grade hacking tools can end up in criminal hands. The good news is that the fix is simple. Update your iPhone, get your seed phrase off your device, and skip shady crypto links.

Doing those three things puts you ahead of most targets.

Categorized in:

Tagged in:

,