GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

SlowMist: iOS Safari DarkSword Attack Can Steal Wallet Inputs, Zero-Click Trigger with Six-Vulnerability Chain

Odaily News, According to a disclosure by the SlowMist security team, they have detected an attack campaign disguised as a free VPS service, specifically targeting iPhone Safari browsers running iOS versions 18.4 to 18.6.2. The attackers exploited a chain of six vulnerabilities codenamed DarkSword to form a complete attack sequence, covering WebKit remote code execution, sandbox escape, and kernel read/write operations. This allows them to access app container files and keychain data without user awareness, and record keyboard inputs while wallets such as imToken, TokenPocket, or TronLink are in the foreground.The SlowMist team stated that all six aforementioned vulnerabilities have been patched by Apple, and the current attack constitutes reuse of an n-day vulnerability chain. Merely visiting a malicious page does not directly prove that mnemonic phrases or private keys have been stolen, and device forensics is still required for confirmation. iOS/iPadOS users are advised to upgrade their systems to version 18.7.3 or 26.3 and above as soon as possible.

SlowMist Discloses Phishing Campaign Involving Fake TronLink Chrome Extension That Steals Wallet Credentials Such as Mnemonics and Private Keys

According to SlowMist, its security monitoring system MistEye has detected a counterfeit TronLink Chrome MV3 extension targeting TRON wallet users with a two-layer phishing attack. The extension disguises itself as the official plugin using Unicode obfuscation and brand spoofing. Upon installation, it first loads a remote iframe-based pop-up page designed to trick users into entering their mnemonic phrases, private keys, keystore files, and passwords—then exfiltrates this sensitive data via same-origin APIs to a Telegram bot. The malicious infrastructure involved includes the domains tronfind-api[.]tronfindexplorer[.]com and trx-scan-explorer[.]org; the malicious extension ID is ekjidonhjmneoompmjbjofpjmhklpjdd. SlowMist advises users to immediately uninstall the extension. If sensitive information has already been submitted, users should promptly migrate their assets and discontinue use of the compromised wallet.