The Phone Is the Vault: Trail of Bits and Mobile Crypto Risk
A zero-click iPhone exploit called DarkSword hunts crypto wallets no audit protects. Here is why Trail of Bits spun out iVerify, and how attackers now target your device, not the code.
In March 2026, security researchers pulled apart a piece of iPhone malware that read like a heist script. It arrived through hacked but otherwise ordinary websites, needed no tap, no download, and no mistake from the victim, and it chained six iOS flaws (three of them previously unknown) to seize control of the device. Then it went looking for one thing above all others: crypto. The implant scanned for Coinbase, Ledger, MetaMask, Phantom, and dozens of other wallet apps, scooped up their data files along with the phone’s keychain, messages, and location history, and slipped back out. Researchers called it DarkSword, and among the firms that took it apart was iVerify, a mobile-security company with an unusual pedigree: it was spun out of Trail of Bits, the firm most crypto builders name first when they think about a code audit.
That pairing says something the industry has been slow to accept. The most heavily audited corner of software on earth keeps losing most of its money somewhere an audit never looks: on the endpoint, the phone or laptop that actually holds the keys and signs the transactions. Trail of Bits built its reputation proving that smart-contract code can be made safer. Its decision, years before DarkSword existed, to incubate and then release a company dedicated to hunting spyware on phones is a tell about where the losses really come from. In 2026, your phone is the vault. This is how attackers are cracking it, why a smart-contract audit will not save you, and what the people who audit that code for a living now say you should do about the device in your pocket.
DarkSword: a zero-click iPhone chain built to empty crypto wallets
DarkSword was jointly disclosed in March 2026 by Google’s Threat Intelligence Group, iVerify, and the mobile-security firm Lookout, though it had been in use since at least November 2025. What made it notable was not a single clever trick but the completeness of the chain. According to The Hacker News, it strung together six iOS vulnerabilities, three of them zero-days at the time, across WebKit, Apple’s graphics layer, the dynamic linker, and the kernel. The delivery method was a classic watering hole: attackers planted a malicious iframe on legitimate but compromised websites, which quietly fingerprinted each visitor’s device and served a browser exploit that walked from Safari all the way down to kernel-level control. No phishing link to click, no attachment to open, no permission to grant. That is what “zero-click” means in practice, and it is the property that makes these kits so dangerous: doing everything right does not keep you safe.
Once it had privileged code execution, DarkSword behaved less like espionage tooling and more like a bank robbery. iVerify’s teardown found that the implant scans specifically for wallet applications, naming Coinbase, Ledger, MetaMask, and Phantom among dozens of targets, then uses heuristics to locate their data files. Alongside the wallet data it lifted keychain databases, Wi-Fi passwords, SMS and iMessage history, contacts, and WhatsApp and Telegram content. It affected iOS versions 18.4 through 18.7. Investigators tied it to a mix of suspected state-sponsored groups (one tracked as UNC6353, aimed at targets in Ukraine) and a commercial surveillance vendor, PARS Defense, with victims also identified in Saudi Arabia, Turkey, and Malaysia. Apple has since patched the flaws; iVerify urged users to update to iOS 18.7.6 or 26.3.1 and noted that Lockdown Mode and the iPhone 17’s hardware Memory Integrity Enforcement would have blocked the chain outright. As the company put it, “All iVerify apps are able to detect live infections of DarkSword.”
| DarkSword at a glance | Detail |
|---|---|
| Disclosed | March 2026, jointly by Google’s Threat Intelligence Group, iVerify, and Lookout; active since at least November 2025 |
| Delivery | Zero-click watering-hole via a malicious iframe on hacked legitimate websites; no user interaction |
| Flaws used | Six iOS vulnerabilities, three of them zero-days (WebKit, graphics layer, dynamic linker, kernel) |
| Affected iOS | 18.4 through 18.7 |
| Primary target | Crypto wallet apps (Coinbase, Ledger, MetaMask, Phantom and more), plus keychain, messages, and location |
| Attributed to | Suspected state groups and a commercial vendor (PARS Defense); victims in Ukraine, Saudi Arabia, Turkey, Malaysia |
| Fix | Patched by Apple; update to iOS 18.7.6 or 26.3.1; Lockdown Mode blocked it |
Why crypto’s most-cited code auditor is warning you about your phone
Trail of Bits is not, at first glance, a mobile-security company. Founded in New York in 2012 by Dan Guido and Alexander Sotirov, it has published hundreds of public security reviews and built tools much of the industry now relies on, including the Slither static analyzer and the Echidna and Medusa fuzzers. Its client list reads like a map of DeFi’s core infrastructure: Uniswap, Compound, Aave, MakerDAO, Chainlink, the Solana Foundation, Arbitrum, and ZKsync among them. When a protocol wants the badge that reassures a treasury committee, this is one of a small handful of names it reaches for. That reputation is exactly why its interest in phones is worth noticing. For how the same badge game plays out beyond Ethereum, see our look at who audits Solana and Move.
So why does a firm built on reading Solidity spend energy on iPhones? Because the code is increasingly not where the money leaks out. Guido has described the firm’s guiding instinct simply: “I don’t ever want to find the same bug twice.” That instinct produced static analyzers and fuzzers so that whole classes of contract bug could be caught automatically, forever. Applied one layer down, to the device that signs the transaction, the same instinct produced iVerify. An auditor who watches clients get drained despite clean reports eventually asks the obvious question: if the contract held, how did the attacker get in? More and more often in 2026, the honest answer is the phone, the laptop, or the human holding it. A firm that hates finding the same bug twice was never going to ignore the place the bugs kept reappearing.
iVerify, the mobile-security company Trail of Bits spun out
iVerify started inside Trail of Bits as a way to protect the firm’s own staff. Trail of Bits shipped the first iVerify iPhone toolkit in 2019, added an enterprise product in 2020 and an Android app in 2021, then, after a four-year incubation, set it loose as an independent company in August 2023 with a $4 million seed round led by Mischief Ventures. It has since raised further venture funding and built out an enterprise customer base. The company is run by chief executive Danny Rogers and chief operating officer Rocky Cole, a former National Security Agency analyst, alongside several Trail of Bits alumni. Guido framed the split as a proud handoff: “We’re excited to watch from the sidelines as iVerify leads the cause in safeguarding individual and organizational device security.”
What iVerify actually does is mobile threat hunting: a blend of a mobile endpoint-detection-and-response (EDR) app and human forensics that looks for the indicators of compromise left behind by sophisticated spyware on iOS and Android. Rogers described the core product to SecurityWeek as alerting users to “suspicious artifacts and anomalous behaviors known to be associated with advanced mercenary spyware attacks.” The intended customer, from the very start, was the high-value individual: executives, people traveling to sensitive regions, journalists, and anyone whose phone is worth a five- or six-figure exploit to compromise. That description fits a large slice of the crypto world precisely, which is why a company built to protect corporate VIPs from Pegasus keeps turning up in the middle of crypto-theft stories.
Mercenary spyware went downmarket, and crypto holders are the market
Commercial surveillance software, the category that includes NSO Group’s Pegasus, was long treated as a problem for dissidents and reporters. iVerify’s own threat hunting helped reframe it as a much broader business risk. In a December 2024 investigation reported by The Record, the company found seven Pegasus infections in an initial batch of roughly 2,500 self-scans, then eleven more among about 18,000 devices. Only about half of the infected users had ever received Apple’s Threat Notifications, meaning most had no idea. Victims worked in real estate, logistics, and finance, and included a European government official; some infections dated back to 2021 and had survived multiple operating-system updates. This was not a handful of famous activists. It was ordinary professionals with valuable access, discovered only because someone finally went looking with the right tools.
Rocky Cole, iVerify’s co-founder, did not soften the finding. “The world remains totally unprepared to deal with this from a security perspective,” he told The Record. “This stuff is way more prevalent than people think.” The crypto implication is direct. Mercenary spyware and DarkSword-style kits are built for exactly the profile a self-custody crypto holder presents: a liquid, irreversible, bearer asset controlled from a phone. A captured signature, a copied keychain, or a single glimpse of a seed phrase is not a data breach you can rotate your way out of; it is a wire transfer you cannot claw back. With Bitcoin trading around $76,700 and the total crypto market near $2.7 trillion in mid-September 2026, per CoinGecko, the reward for reaching the device has never been larger, and the tooling to reach it has never been more available for hire.
The seed phrase in your camera roll
Not every attacker needs a nation-state exploit chain. The cheaper version of the same idea has been sitting in the official app stores. Kaspersky documented SparkCat in 2025, a strain that used optical character recognition to read a phone’s photo library and pull out text. In 2026, researchers at Check Point documented an evolution called SparkKitty, which did the same job with a sharper focus: it hunted screenshots of crypto wallet recovery phrases, passwords, and QR codes, then shipped them to attacker servers. Crucially, it passed review on both Apple’s App Store and Google Play, hiding inside a crypto-themed iOS app and an Android app called SOEX that reached more than 10,000 downloads before removal.
The lesson is uncomfortable because it is so mundane. If you have ever screenshotted your seed phrase “just in case,” you turned your camera roll into a plaintext copy of your private key, sitting on a device that runs code you did not write and that syncs, by default, to a cloud you do not control. DarkSword weaponizes that reality at the high end, with kernel exploits and state-grade tooling. SparkKitty does it at the mass-market end, with a fake app and a permission dialog most people tap through without reading. Both bypass the smart contract entirely, and both prove the same point: the attacker does not need to break the chain if they can read your phone.
The 2026 ledger: attackers hit people and keys, not code
The numbers back up the shift. In its Hack3d report for the first half of 2026, CertiK counted more than $1.31 billion lost across 344 incidents. The single costliest category was not a Solidity bug at all; it was wallet and private-key compromise, which accounted for roughly $444 million across 33 incidents, an average of more than $13 million each. The two largest events of the half, the Kelp DAO RPC compromise (about $291 million) and the Drift Protocol breach (about $285 million), both in April 2026, together made up close to 44 percent of all losses, and both were failures of keys and infrastructure rather than of on-chain logic.
CertiK’s own recommendations tell the story: protect private keys, distribute signers across jurisdictions, and add controls for large transfers. Not one of those is a code fix. This is the statistical backbone of the argument Trail of Bits and iVerify have been making in different registers. Audits are necessary and they work; the industry has genuinely hardened its contracts, and the days when a rounding error routinely cost nine figures are receding. But the marginal dollar of loss has migrated to people, credentials, and the devices that hold them, and that migration is the whole reason a code-audit firm ended up in the phone-security business in the first place. Attackers, being rational, went where the defenses were thin.
What a smart-contract audit does, and does not, cover
An audit is a point-in-time review of a specific body of code. Done well, it is genuinely valuable: it can surface reentrancy, arithmetic and rounding errors, broken access control, and mishandled oracle data before they reach production. What it cannot do is vouch for anything outside that code. It says nothing about the phone that signs the transaction, the private keys sitting in a device keychain, the front-end that could be swapped through a DNS hijack, or the human who approves the wrong pop-up. It also cannot cover code that did not exist on the day it ran, the scope trap at the heart of several of 2026’s most expensive exploits. A report is a snapshot, not a warranty.
Two adjacent risk classes make the point. Bridges concentrate value behind trust assumptions that a contract review cannot fully validate, which is why the safest bridge is often no bridge at all. Price oracles can be manipulated in ways that leave the code technically correct while the protocol bleeds, as in the oracle attacks that reopened the rollback debate. Alexander Urbelis, chief information security officer at ENS Labs, put the general version of this to CoinDesk: “The bugs that drain treasuries often turn on intent and adversarial incentives.” Code review is one layer of defense, not the whole building. The table below sorts what a typical engagement can and cannot promise.
| What an audit reviews | What it cannot vouch for |
|---|---|
| Contract logic, reentrancy, access control | The phone or laptop that signs the transaction |
| Arithmetic and rounding invariants | Private keys stored in a device keychain or the cloud |
| Oracle and price-feed handling | Phishing, fake apps, and social engineering |
| Upgradeability and admin controls | Front-end, DNS, and domain hijacks |
| The exact code in scope on the day it ran | Code added or changed after the review |
| Declared dependency versions | Bridge and cross-chain trust assumptions |
The signing screen is the last line of defense
Even with flawless contracts and a spotless audit, a transaction still has to be approved on a device. That approval is where a compromised phone turns dangerous. “Blind signing,” the habit of approving a transaction you cannot fully read, becomes fatal when malware controls the screen: the software can present a harmless-looking summary while submitting a payload that grants a token approval, swaps a destination address, or drains an entire balance. Clipboard hijackers do a cruder version of the same thing, silently replacing a pasted wallet address with the attacker’s, and address-poisoning schemes seed your transaction history with lookalike addresses in the hope you copy the wrong one.
Hardware wallets help, and every serious holder should use one, because they keep the private key off the connected phone and force a separate, physical confirmation. But they are not a magic shield: a compromised host can still show you one thing while asking the device to sign another, so the details must be verified on the hardware screen itself. The industry’s move toward transaction simulation and “clear signing,” which turns an opaque blob of calldata into a human-readable statement of what will actually happen, is a direct response to this problem. The screens where people confirm, recover, and secure funds are, as we argued in our guide to wallet UX in 2026, the exact point where security and usability either hold together or fall apart. Most catastrophic losses happen in the two seconds it takes to approve without looking.
Can you actually defend an iPhone? Mobile EDR versus the walled garden
Modern phones are far more locked down than desktops, and that genuinely raises the cost of an attack: DarkSword needed six chained flaws precisely because iOS makes single-bug compromise hard. But the same walled garden that keeps casual malware out also keeps defenders out. Third-party security software cannot freely inspect the operating system, which makes forensic investigation difficult and lets sophisticated infections hide for years. That is why Apple’s own Threat Notifications missed roughly half of the Pegasus cases iVerify found: if even the platform owner cannot reliably see the compromise, an ordinary user has no chance of spotting it by watching for a slow battery or a warm case.
Apple’s answer has been to add strong opt-in defenses: Lockdown Mode, which strips away the attack surface DarkSword relied on, and hardware Memory Integrity Enforcement on the iPhone 17. iVerify’s answer is complementary: a mobile EDR layer that hunts for indicators of compromise and gives high-value users a way to actually check a device rather than assume it is clean. The tension between privacy and inspectability is real, and there is no tidy resolution; a phone open enough to audit thoroughly is also a phone easier to surveil. That difficulty is precisely why a specialist company exists to work on it full time, and why a code-audit firm judged the problem important enough to build one and then let it go independent.
A field guide: how crypto gets stolen through a phone
The device attack surface is wide, but it is not infinite. Most real-world thefts fall into a handful of patterns, almost none of which involve a smart-contract bug. The table below maps the common ones, a representative 2026 example, and the control that most reduces the risk.
| Attack | How it works | 2026 example | What reduces the risk |
|---|---|---|---|
| Zero-click exploit chain | A hacked website silently takes over the phone | DarkSword | Patch fast, Lockdown Mode, mobile EDR |
| Mercenary spyware | A commercial surveillance implant lives on the device | Pegasus infections found by iVerify | Lockdown Mode, threat hunting |
| App-store OCR stealer | A malicious app reads seed phrases from your photos | SparkCat and SparkKitty | Never screenshot a seed phrase; vet apps |
| Fake or trojanized wallet | A cloned wallet app captures your seed at setup | Recurring on both app stores | Install only from verified developers |
| Clipboard hijacker | Swaps a pasted address for the attacker’s | Common in mobile malware | Verify the full address; use a saved address book |
| SIM swap | Attacker ports your number to steal SMS codes | Ongoing against holders | Carrier PIN; avoid SMS 2FA; use a hardware key |
| Malicious approval | You sign a token approval that drains funds later | WalletConnect and dApp abuse | Clear signing; revoke approvals; simulate transactions |
| Phishing and fake support | You are tricked into revealing keys yourself | Perennial across channels | Never share a seed; no real support asks for one |
The through-line is that the contract is rarely the weak point. Whether the entry is a kernel exploit, a photo-scanning app, a swapped clipboard, or a ported phone number, the attacker’s goal is the same: reach the key or the approval, on the device, where no audit is watching and no on-chain safeguard applies.
Treasuries, DAOs, and funds: the device is now in scope
For anyone who signs on behalf of others, the endpoint is no longer an IT footnote; it is an audit item in its own right. Multisig signers, DAO treasury managers, and exchange or custody staff each hold a key that can move other people’s money, and each does it from a device. The Kelp DAO and Drift losses were not clever math; they were operational failures around keys and infrastructure. CertiK’s guidance after those incidents, to distribute signers across jurisdictions, add large-transfer controls, and protect keys, is essentially a device- and process-security program wearing a blockchain hat.
The practical playbook that has emerged looks a lot like enterprise mobile security: dedicated, hardened signing devices that are not someone’s daily-driver phone; mobile EDR and mobile device management across the signing team; a hardware wallet for every signer; transaction simulation before anything is approved; and treating a suspected device compromise as a board-level incident rather than a personal inconvenience. It is more expensive than a single audit and less satisfying than a green checkmark on a website, but it defends the layer where 2026’s biggest losses actually happened. A protocol that spends a fortune on code review and lets its signers approve transfers from an unmanaged phone has bought a strong front door and left a window open.
Who regulates the endpoint? Almost no one
There is no authority that certifies your phone is safe, just as there is none that mandates or accredits smart-contract audits. In the United States, the Securities and Exchange Commission requires public companies to disclose material cybersecurity incidents, but a self-custody holder or a decentralized protocol falls outside that regime entirely. Washington has taken steps against the commercial spyware industry, adding surveillance vendors to trade blocklists and restricting government use of their tools, yet none of that hardens a private individual’s device against a kit like DarkSword. Enforcement reaches the sellers, slowly, not the exploit already running on your handset.
The result is an accountability vacuum. If your keys are drained through a zero-click exploit, there is usually no regulator to make you whole and often no one to sue. The SEC’s energy in 2026 is aimed at the products and gatekeepers it can actually reach, from exchanges to the commodity-or-security gate that decides which tokens get an ETF, not at the security of the phone in a retail investor’s hand. That leaves self-defense as the only reliable policy, which is exactly the gap iVerify and firms like it are trying to fill commercially. In crypto, more than almost anywhere else, you are your own last line of support.
What Trail of Bits’ bet says about the next five years
Guido has warned that security is bifurcating. “There’s going to be security haves and have-nots,” he told Decential, “and it’s going to extend not just from individual projects, but also to blockchains.” The same split is now visible at the level of individuals and their devices. A well-resourced fund can run hardened signing hardware and mobile threat hunting; a retail holder with a screenshotted seed phrase on an unpatched phone cannot. Artificial intelligence widens the gap in both directions at once, letting attackers scale exploitation and reconnaissance while letting defenders automate detection and patching. Whoever adopts the new tooling faster pulls ahead.
Trail of Bits saw the endpoint problem early enough to build a company for it and spin that company out before the marquee crypto-draining iPhone exploit ever arrived. The takeaway for everyone else is less about any single product and more about where to spend the next security dollar. The contract layer is mature and well served by firms that are genuinely good at it. The device layer, the one that actually holds your keys and signs your transactions, is where the frontier, and the losses, have moved. Treating the phone as trusted infrastructure was always a convenient fiction; in 2026 it is an expensive one.
Protecting your crypto on mobile: a practical checklist
None of this requires paranoia, but it does require a few habits most holders skip. The essentials, in rough order of impact:
- Update your operating system immediately when patches ship; DarkSword is fixed, but only for people who actually install the update.
- Keep the smallest possible balance in a hot mobile wallet, and move savings to a hardware wallet or cold storage.
- Never screenshot, photograph, or store a seed phrase in your camera roll, notes app, cloud drive, or messages.
- Install wallet apps only from the verified developer, and treat any app that asks for photo-library access with suspicion.
- Turn on Lockdown Mode if you are an executive, fund manager, public figure, or otherwise a plausible high-value target.
- Use a dedicated device for signing large transactions, kept separate from your everyday phone.
- Verify every transaction’s details on the hardware wallet screen, and avoid blind signing wherever you can.
- Lock down your mobile carrier account with a PIN and move off SMS-based two-factor authentication toward an authenticator app or a hardware key.
- If you are a treasury signer or a serious individual holder, consider a mobile threat-hunting or mobile EDR tool that checks for indicators of compromise.
- Be ruthless with unsolicited support, giveaways, and urgent messages; no legitimate service ever needs your seed phrase.
Frequently Asked Questions
Can a smart-contract audit protect my crypto from phone malware?
No. An audit reviews on-chain code and says nothing about your device, your private keys, or the transactions you approve. Attacks like DarkSword and SparkKitty target the phone itself, not the contract, so a clean audit offers no protection against them.
What is DarkSword and am I still at risk?
DarkSword is a zero-click iOS exploit chain disclosed in March 2026 that quietly takes over iPhones and steals crypto wallet data. Apple has patched the underlying flaws, so the main risk now is running an outdated system; update to iOS 18.7.6 or 26.3.1 or later, and enable Lockdown Mode if you are a high-value target.
What is iVerify and how is it related to Trail of Bits?
iVerify is a mobile threat-hunting and EDR company that hunts spyware on iOS and Android. Trail of Bits, the well-known crypto code auditor, incubated it internally and spun it out as an independent company in 2023.
Does a hardware wallet stop mobile spyware?
It helps a great deal by keeping your private key off the connected phone, but it is not a complete shield. A compromised device can still trick you into approving a malicious transaction, so always verify the details on the hardware wallet’s own screen and avoid blind signing.
How do I know if my phone has spyware?
You often cannot tell on your own; only about half of Pegasus victims received Apple’s Threat Notifications. Keep your operating system updated, turn on Lockdown Mode if you are at high risk, and consider a mobile threat-hunting tool that checks for indicators of compromise.
By Anneke de Vries, security desk, HOGE Wire.