Exposed DarkSword Servers Linked to iPhone Crypto Wallet Theft
Censys found exposed DarkSword/Coruna servers used to steal cryptocurrency wallet recovery phrases from compromised iPhones.
Censys reported five exposed servers hosting a DarkSword/Coruna iOS exploitation-as-a-service platform, including exploit_server.py, the darksword.db database, wallet-injection modules, and reseller or agent controls, with no named actor attributed. A production-server capture contained 11 victim BIP39 recovery phrases, 179 device loot directories, and 75 control-plane or operator accounts; one report says telemetry showed iPhones on iOS 16.1 and 16.3.1 polling a watering-hole beacon every three seconds and that the infrastructure was active during September. Eighteen modules inject into wallet apps including MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, and imToken; the second report also names Bitpie and says the implant scans Photos and Apple Notes for phrases after a WebKit and JavaScriptCore exploit gains kernel access and reaches SpringBoard. Censys matched 22 in-the-wild samples to a separate command server. Sources agree CVE-2026-31001 was not a deployed iOS 26 attack, but one describes it as a referenced JavaScriptCore type-confusion flaw while the other calls it unfinished placeholder work; Apple says the established chains are patched.
- Censys found five exposed DarkSword/Coruna iOS exploitation-as-a-service servers, including exploit_server.py, darksword.db, wallet-injection modules, and reseller or agent controls; no actor was named.
- A production capture held 11 victim BIP39 recovery phrases, 179 device loot directories, and 75 control-plane or operator accounts.
- Telemetry cited iPhones on iOS 16.1 and 16.3.1 polling a watering-hole beacon every three seconds; infrastructure was described as active during September.
- Eighteen modules target MetaMask, Phantom, Trust Wallet, Coinbase, Exodus, and imToken; one report also names Bitpie and scanning of Photos and Apple Notes.
- One report describes a WebKit and JavaScriptCore chain that reaches SpringBoard after kernel access; Apple says the established chains are patched.
- CVE-2026-31001 is referenced, but both sources say no deployed iOS 26 chain was shown; they differ on whether it is type-confusion work or an unfinished placeholder.
- Censys matched 22 in-the-wild samples to a separate command server.
Coverage timelineoldest first · each row is one article
- · 13h agoExposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones
GBHackers· 65
Censys-exposed DarkSword/Coruna servers reveal an iOS exploitation-as-a-service platform stealing crypto wallet secrets, including 11 victim recovery phrases.
- · 9h agoDarkSword iOS Exploit Platform Uses Coruna Malware to Steal Crypto Wallet Recovery Phrases
Cyber Security News· 72
DarkSword's Coruna malware uses iOS browser exploits to steal cryptocurrency wallet recovery phrases from iPhones.
Vulnerabilities in this storyAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-31001 | NVD description · AI analysis pending | — | — | — | — | — |