Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

SlowMist Warns Apple Zero-Day May Put Crypto Wallet Data at Risk

SlowMist says Apple’s latest security update is highly relevant to iOS attacks targeting sensitive crypto wallet data.

Written By Jalpa Bhavsar
Edited by Divya Mistry
Published 49 minutes ago
Make The Crypto Times preferred on GoogleGoogle
A smartphone displaying the Apple logo positioned in front of an illuminated SlowMist wall logo. JPG

Blockchain security firm SlowMist has warned crypto users to update their Apple devices after the company patched a zero-day vulnerability that may have been exploited in targeted attacks. 

In an X post, SlowMist said the vulnerability is particularly concerning for crypto users because of iOS exploitation activity it has observed targeting sensitive wallet data.

Apple addressed the vulnerability, tracked as CVE-2026-86950, in iOS 26.7.1 and iPadOS 26.7.1, released on September 28. The flaw affects the CoreGraphics component and could allow arbitrary code execution when a device processes a maliciously crafted file, according to Apple’s security advisory.

Apple said the issue involved an out-of-bounds write and was addressed through improved bounds checking. The company also said it was aware of a report indicating that the vulnerability may have been exploited in an “extremely sophisticated attack” against specific targeted individuals running versions of iOS before iOS 27.

AI Summary
Show
Apple patched zero‑day CVE‑2026‑86950, preventing arbitrary code execution that could expose crypto wallet data.
SlowMist warns that iOS exploits threaten high‑value crypto users, urging immediate updates across all Apple devices.
The flaw underscores broader industry risk as smartphones become primary access points for decentralized finance applications.

SlowMist’s CISO flags crypto wallet risk

SlowMist said Apple’s latest security update is “highly relevant” to iOS attack activity the blockchain security firm has previously tracked. The firm said the development is particularly concerning for crypto users because of iOS exploitation activity targeting sensitive wallet data.

SlowMist Chief Information Security Officer 23pds also linked Apple’s security update to a zero-day that he said was used in attacks involving crypto wallets in a separate X post.

That connection comes from SlowMist, not Apple’s advisory. Apple has confirmed possible exploitation of CVE-2026-86950 but has not said that the vulnerability was used specifically to steal cryptocurrency or wallet credentials.

SlowMist urged users to update their iPhones, iPads, Macs, and other Apple devices to the latest available security versions. It also advised users to avoid installing applications from unknown or untrusted sources and warned against opening suspicious links through Safari or in-app browsers. The firm further recommended treating unexpected files, links, and app-installation prompts with caution.

The warning follows earlier research from SlowMist into attacks affecting cryptocurrency users on iOS devices. On September 19, the firm said it had received reports of crypto assets being stolen from users who had previously installed FomoPeek versions 1.1–1.2.

A joint investigation by SlowMist and OKX identified malicious components in the affected versions, including an iOS kernel exploitation framework containing eight exploit methods. SlowMist said some users who had installed the affected versions subsequently reported losing crypto assets. 

However, SlowMist has not said that the FomoPeek incident and CVE-2026-86950 are the same vulnerability or part of the same attack campaign.

Apple confirms possible exploitation

Apple’s advisory lists iPhone 11 and later among the devices affected by CVE-2026-86950, along with several iPad Pro, iPad Air, iPad and iPad mini models. Apple credited Meta Product Security with reporting the vulnerability. The company said improved bounds checking was introduced to address the security issue.

Apple has not confirmed that CVE-2026-86950 was specifically used to steal cryptocurrency, private keys or seed phrases. Its advisory confirms the vulnerability and potential exploitation against targeted individuals, while the crypto-wallet connection comes from SlowMist’s observations of iOS attack activity.

The distinction is important because Apple has not disclosed the identities or number of people targeted in the reported attacks, identified the attackers or confirmed any cryptocurrency losses linked directly to CVE-2026-86950.

Security update urged for crypto users

The incident carries particular significance for crypto users because smartphones are widely used to access wallets, exchanges, and authentication applications. If attackers gain deep access to a device, sensitive information associated with those services could potentially be exposed.

SlowMist’s warning puts the focus on preventative measures while researchers continue to investigate the attack activity. Users are being urged to keep Apple devices updated and remain cautious about links, files and applications from unknown sources.

For now, Apple has confirmed the vulnerability and possible exploitation, while SlowMist has connected the update to broader iOS attack activity targeting sensitive crypto wallet data. Further details about the attacks and any confirmed crypto losses have not been disclosed.

Also Read: MEXC User Says He Lost $340,000 Through Hacker’s Unrevoked API Key

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Blockchain
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

The Dinari, Kakaopay Securities, and Ondo Finance logos displayed side by side on colorful blocks against a textured wall.
Kakao Pay Securities Explores Tokenized Korean Stocks With Dinari, Ondo
An illuminated blue MEXC logo with digital glitch effects on a dark background.
MEXC Confirms $340,000 Loss From API Key, Fully Compensates Affected User
A physical Hedera (HBAR) token coin resting on a rugged surface with a financial candlestick chart showing an upward trend in the background.
HBAR Price Soars 22% as Hedera App Lands on IBM Cloud: Can $0.12 Hold?
NVIDIA Launches Open Agent Safety Platform as AI Agents Enter Finance 
NVIDIA Launches Open Agent Safety Platform as AI Agents Enter Finance 
A metallic sign featuring the red geometric logo and black text of Blockchain.com set on a reflective surface.
Blockchain.com Sets Sights on $500M IPO This Year

Find Us on Socials

You may also like

Trump's 2 p.m. Oval Office Announcement What It Could Mean for Bitcoin

Trump’s 2 p.m. Oval Office Announcement: What It Could Mean for Bitcoin

A hooded figure working on a laptop in front of an illuminated MEXC logo on a dark wall.

MEXC User Says He Lost $340,000 Through Hacker’s Unrevoked API Key

India's ED Expands Crypto & Cyber Tracing Under Renewed NFSU Pact

India’s ED Expands Crypto & Cyber Tracing Under Renewed NFSU Pact

A glowing red "FAKE" block chained between blue "GIWA" blockchain blocks, topped with Ethereum tokens.

Fake GIWA Chain Drained 766 ETH After 1,335 Addresses Bridged Into It

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information