On September 29, Apple released a critical update to patch a zero-day vulnerability that has been linked to the theft of crypto wallets.
SlowMist’s Chief Information Security Officer, 23pds, confirmed the flaw was exploited in targeted attacks on iOS versions prior to 27. SlowMist said Apple “is aware of a report indicating that this issue may have been exploited in highly sophisticated attacks targeting specific individuals, affecting iOS versions prior to iOS 17.”
SlowMist’s founder, Yu Xian, warned that certain black-market groups are actively exploiting vulnerabilities present in iOS versions prior to iOS 17 to steal crypto wallet assets from iPhone users. He urged users to promptly update their iPhones, iPads, and Macs to the latest system versions, to exercise caution when installing apps from unknown sources, and to avoid opening suspicious links via Safari or in-app browsers.
This development was highlighted as part of a recent crypto market update pointing to ongoing security threats.
Zero-day vulnerability details and impact
SlowMist publicly reported the issue on September 29. According to the organisation, the flaw has been observed in targeted attacks; 23pds stated these attacks affected iOS versions prior to 27, while SlowMist also indicated the issue may have affected iOS versions prior to iOS 17.
Security advice for users
SlowMist advised users to update all Apple devices to the latest system versions and to avoid risky behaviours such as installing unknown apps or clicking on suspicious links in Safari or in-app browsers to reduce the risk of wallet theft.

