SlowMist has yet to confirm crypto theft from iPhone Safari attack
The analyzed Safari sample targets iOS 18.4–18.6.2 using previously patched flaws, while its effectiveness on iOS 26.5 remains unverified.
Asanat Analysis — Why it matters
SlowMist's inability to confirm theft details signals a critical gap in iOS security incident attribution. The exploit targets already-patched vulnerabilities (iOS 18.4–18.6.2), suggesting either delayed patching by users or sophisticated chaining of known flaws. The uncertainty around iOS 26.5 effectiveness is particularly notable—if newer versions are vulnerable, it indicates Apple's patch cadence may not be closing Safari-to-wallet attack vectors fast enough.
This pattern mirrors historical mobile security incidents where wallet drains occurred through browser-based exploits months after patches existed. The hesitation to confirm theft amounts reflects either unresolved technical analysis or potential coordination delays with affected parties. For the DeFi ecosystem, this underscores that custody risk extends beyond smart contracts to the execution layer—users running outdated iOS versions remain exposed regardless of protocol security. Market infrastructure teams are likely revisiting mobile wallet guidance and considering hardware wallet promotion as baseline risk mitigation.