Buy now

If you keep a crypto wallet on iPhone, the week of 19 September 2026 gave you a reason to look at it again. SlowMist's chief information security officer, who posts as 23pds, warned that attackers have put a full-chain iOS exploit into working use, and that the chain is capable of pulling private keys and recovery words out of mobile wallets without the owner doing anything more than opening a link.

We build hardware wallets, so treat the closing sections as interested advice. The technical description below is drawn from the public reporting and is checkable, which matters more here than anything we might say about our own product.

What was disclosed

The warning covers devices running iOS 13 through iOS 26.5, which is close to every iPhone still in use. As reported by Phemex and others, the sequence begins when someone visits a malicious page in Safari, usually arriving through a social lure or a link planted on a site the target already trusts.

From there the steps are ordinary in shape and unpleasant in effect. A memory-corruption bug in WebKit and JavaScriptCore gives the page arbitrary read and write access at the JavaScript layer. The chain then defeats Pointer Authentication Codes to run native code, escapes the browser sandbox, and escalates to kernel privileges, which is the point at which it can read the device Keychain and the data belonging to wallet apps.

The detail that should hold your attention is the absence of a second step for the victim. No download, no install, no approval dialog. Visiting the page is the whole interaction.

Why a crypto wallet on iPhone inherits all of this

Every mobile wallet makes the same bargain, and it is usually a sensible one. The key has to be available to software on the handset so the app can sign transactions, which means the key is protected by the operating system rather than by anything the wallet itself controls. iOS is good at this, and the Keychain and Secure Enclave have held up well against ordinary attacks for years.

The bargain breaks when the operating system is the thing that fails. Once code is running with kernel privileges, the boundary the wallet was relying on no longer exists, and an app cannot defend a secret against the system it is running inside. That is true for every wallet on the device, whether the brand is a household name or not, and it has nothing to do with how carefully the wallet was written.

This is why the answer to "which mobile wallet is safest" has a ceiling. You are picking between applications that all sit behind the same door.

What the exploit cannot reach

Now the boundary worth knowing. A private key that was generated inside a certified secure element on a separate device, and that has never been exported, is not in the Keychain and is not in any app's storage. Kernel access on the phone does not produce it, because the phone never had it. The chip signs what it is asked to sign and returns a signature, and there is no interface that hands back the key.

On Ryder One the key is generated inside an EAL6+ certified Infineon SLC38 and stays there, with the firmware independently audited by Halborn and the report published in full. Connectivity is NFC only, so there is no USB data path and no Bluetooth or Wi-Fi radio for a compromised handset to reach through; the device is addressable while you hold it against the phone and unreachable the rest of the time. The transaction is rendered on the 1.6-inch AMOLED touchscreen on the device itself and the confirm button is wired directly to the secure element, so an infected phone showing you one destination cannot quietly get a different one signed.

We should be even-handed about the limit. If your phone is compromised while you use it alongside a hardware wallet, an attacker can still show you a convincing request and hope you approve it. What changes is that the true details appear on a screen the attacker does not control, which turns a silent theft into one you can refuse by reading.

If a recovery phrase ever touched that phone

Here is the part people skip, and it is where the lasting damage usually lives. A kernel-level compromise can read photo libraries, notes, files and synced folders, so a seed phrase stored in a screenshot or a notes entry is exposed even if the wallet app itself gave nothing away. Rotating the wallet later does not undo it, because those words remain valid for the accounts they created.

SlowMist's own guidance is to update iOS at once, avoid unsolicited links, and, for anyone who held a hot wallet on a vulnerable device, generate fresh keys on a clean handset and move the funds across. That advice is sound. Follow it before you read the rest of this section.

Where you put the new backup is the decision that outlasts the incident. Paper avoids every digital exposure and introduces fire, water and the recycling bin. A steel plate settles those and leaves your whole balance resting on one object staying unfound for decades, which improves on paper rather than solving the shape of the problem. TapSafe Recovery was designed to break the single point of failure apart: a Recovery Tag holds 50% of recovery, your paired phone holds 50% kept encrypted in your iCloud or Google Drive rather than on the handset itself, and optional Recovery Contacts hold 25% each while learning nothing about your wallet. It runs on our own implementation of Shamir's Secret Sharing, so no single item anyone reaches is sufficient on its own. The BIP-39 phrase stays available on the device as a last resort, and you are never tied to our hardware.

What to do today

Update the phone first, since the patched versions close the chain and everything else is secondary to that. Then search your own device for your recovery words the way an attacker would, checking the photo library, the notes app and any synced folder, and delete what you find. If a hot wallet on that handset held anything you would miss, move it to fresh keys made somewhere clean.

After that, the question is a structural one rather than an urgent one. Mobile wallets are good for the money you spend and poor for the money you keep, because their security is borrowed from an operating system that occasionally has a week like this one. Deciding where your long-term holdings sit is easier to do now than during the next disclosure.

Want your keys somewhere an iPhone exploit cannot reach? Get your Ryder One for 149 USD.


Meta description: A crypto wallet on iPhone relies on iOS holding. After SlowMist's September exploit warning, here is what the attack chain reaches and what stays out of range.

Target keyword: crypto wallet iphone

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More