A newly disclosed iPhone exploit is putting some crypto wallet users at risk, not because of a flaw in any blockchain, but because of a flaw on their device. Security firm SlowMist found that attackers can use a vulnerability in Safari to break into iPhones running iOS 13 through 26.5. The starting point is a malicious webpage; from there, the exploit can escalate its permissions, bypass multiple Apple protections, and reach sensitive data, including wallet private keys and seed phrases, stored locally on the phone. Investigators tied this attack path to compromised websites and to the FomoPeek iPhone app, which SlowMist and OKX’s security team said could access decrypted Keychain data.

This does not mean every iPhone wallet is automatically compromised, or that blockchains themselves are at risk. What it does mean is that when wallet secrets are created, stored, copied, or backed up on an iPhone, that phone’s device security becomes the critical line of defense, even if the underlying blockchain is as solid as ever. Saving a seed phrase in notes, screenshots, or app files leaves users exposed if their device is exploited. The browser, Safari in this case, is not just a gateway; it is a possible launchpad for attackers. That is why updates and careful handling of wallet credentials are just as important as blockchain security for crypto users.