Blockchain security firm SlowMist has warned crypto users to update their Apple devices after the company patched a zero-day vulnerability that may have been exploited in targeted attacks.
In an X post, SlowMist said the vulnerability is particularly concerning for crypto users because of iOS exploitation activity it has observed targeting sensitive wallet data.
Apple addressed the vulnerability, tracked as CVE-2026-86950, in iOS 26.7.1 and iPadOS 26.7.1, released on September 28. The flaw affects the CoreGraphics component and could allow arbitrary code execution when a device processes a maliciously crafted file, according to Apple’s security advisory.
Apple said the issue involved an out-of-bounds write and was addressed through improved bounds checking. The company also said it was aware of a report indicating that the vulnerability may have been exploited in an “extremely sophisticated attack” against specific targeted individuals running versions of iOS before iOS 27.
SlowMist’s CISO flags crypto wallet risk
SlowMist said Apple’s latest security update is “highly relevant” to iOS attack activity the blockchain security firm has previously tracked. The firm said the development is particularly concerning for crypto users because of iOS exploitation activity targeting sensitive wallet data.
SlowMist Chief Information Security Officer 23pds also linked Apple’s security update to a zero-day that he said was used in attacks involving crypto wallets in a separate X post.
That connection comes from SlowMist, not Apple’s advisory. Apple has confirmed possible exploitation of CVE-2026-86950 but has not said that the vulnerability was used specifically to steal cryptocurrency or wallet credentials.
SlowMist urged users to update their iPhones, iPads, Macs, and other Apple devices to the latest available security versions. It also advised users to avoid installing applications from unknown or untrusted sources and warned against opening suspicious links through Safari or in-app browsers. The firm further recommended treating unexpected files, links, and app-installation prompts with caution.
The warning follows earlier research from SlowMist into attacks affecting cryptocurrency users on iOS devices. On September 19, the firm said it had received reports of crypto assets being stolen from users who had previously installed FomoPeek versions 1.1–1.2.
A joint investigation by SlowMist and OKX identified malicious components in the affected versions, including an iOS kernel exploitation framework containing eight exploit methods. SlowMist said some users who had installed the affected versions subsequently reported losing crypto assets.
However, SlowMist has not said that the FomoPeek incident and CVE-2026-86950 are the same vulnerability or part of the same attack campaign.
Apple confirms possible exploitation
Apple’s advisory lists iPhone 11 and later among the devices affected by CVE-2026-86950, along with several iPad Pro, iPad Air, iPad and iPad mini models. Apple credited Meta Product Security with reporting the vulnerability. The company said improved bounds checking was introduced to address the security issue.
Apple has not confirmed that CVE-2026-86950 was specifically used to steal cryptocurrency, private keys or seed phrases. Its advisory confirms the vulnerability and potential exploitation against targeted individuals, while the crypto-wallet connection comes from SlowMist’s observations of iOS attack activity.
The distinction is important because Apple has not disclosed the identities or number of people targeted in the reported attacks, identified the attackers or confirmed any cryptocurrency losses linked directly to CVE-2026-86950.
Security update urged for crypto users
The incident carries particular significance for crypto users because smartphones are widely used to access wallets, exchanges, and authentication applications. If attackers gain deep access to a device, sensitive information associated with those services could potentially be exposed.
SlowMist’s warning puts the focus on preventative measures while researchers continue to investigate the attack activity. Users are being urged to keep Apple devices updated and remain cautious about links, files and applications from unknown sources.
For now, Apple has confirmed the vulnerability and possible exploitation, while SlowMist has connected the update to broader iOS attack activity targeting sensitive crypto wallet data. Further details about the attacks and any confirmed crypto losses have not been disclosed.
Also Read: MEXC User Says He Lost $340,000 Through Hacker’s Unrevoked API Key
