Close Menu
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
What's Hot

U.S. judge freezes BlockFills assets in dispute over 70 bitcoin with creditor Dominion Capital

March 5, 2026

Kraken xStocks launches xChange for on-chain stock trading

March 5, 2026

Crypto Scams Can Trigger iOS Exploits

March 5, 2026
Facebook X (Twitter) Instagram
Thursday, March 5 2026
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
Facebook X (Twitter) Instagram
StreamLineCrypto.comStreamLineCrypto.com
  • Home
  • Crypto News
  • Bitcoin
  • Altcoins
  • NFT
  • Defi
  • Blockchain
  • Metaverse
  • Regulations
  • Trading
StreamLineCrypto.comStreamLineCrypto.com

Crypto Scams Can Trigger iOS Exploits

March 5, 2026Updated:March 5, 2026No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Crypto Scams Can Trigger iOS Exploits
Share
Facebook Twitter LinkedIn Pinterest Email
ad


Google’s Risk Intelligence Group (GTIG) is warning {that a} “new and highly effective” iOS exploit equipment, dubbed Coruna by its builders has been deployed on pretend finance and crypto web sites designed to lure iPhone customers into visiting pages that may silently ship exploits. For crypto holders, the danger is blunt: GTIG’s evaluation reveals the campaigns in the end centered on harvesting seed phrases and pockets knowledge from widespread cellular apps.

Coruna targets Apple units working iOS 13.0 by iOS 17.2.1, bundling 5 full exploit chains and 23 exploits. GTIG says it recovered the equipment after monitoring its evolution throughout 2025, from early use by a buyer of a industrial surveillance firm, to “watering gap” assaults on compromised Ukrainian web sites, and at last to broad-scale distribution by way of Chinese language-language rip-off websites tied to a financially motivated actor it tracks as UNC6691.

A Crypto Lure Designed For iPhones

Within the scam-wave section, GTIG says it noticed the JavaScript framework behind Coruna deployed throughout a “very massive set” of pretend Chinese language web sites largely themed round finance. One instance cited by GTIG is a pretend WEEX-branded crypto trade web page that attempted to push guests onto an iOS system—after which a hidden iFrame can be injected to ship the exploit equipment “no matter their geolocation.”

Associated Studying

The supply mechanics matter as a result of they blur the road between conventional phishing and outright system compromise: in GTIG’s telling, merely arriving on the booby-trapped web page from a weak iPhone was sufficient to start the chain. The framework fingerprints the system to determine mannequin and iOS model, then hundreds the suitable WebKit distant code execution exploit and a pointer authentication (PAC) bypass.

GTIG tied one WebKit RCE it recovered to CVE-2024-23222, noting it was addressed by Apple in iOS 17.3 on Jan. 22, 2024.

On the finish of the chain, GTIG says Coruna drops a stager it calls PlasmaLoader (tracked as PLASMAGRID) and describes it as centered much less on traditional surveillance options and extra on stealing monetary data. In response to GTIG, the payload can decode QR codes from photographs saved on the system and scan textual content blobs for BIP39 phrase sequences, together with key phrases reminiscent of “backup phrase” and “checking account”, together with in Apple Memos, which it may well then exfiltrate.

Associated Studying

The payload can also be modular. GTIG says it may well pull down and run further modules remotely, and that lots of the recognized modules are designed to hook features and exfiltrate delicate data from widespread crypto pockets apps—amongst them MetaMask, Belief Pockets, Uniswap’s pockets, Phantom, Exodus, and TON ecosystem wallets reminiscent of Tonkeeper.

The broader arc was additionally flagged by cellular safety agency iVerify, which printed its personal findings across the identical time as GTIG’s report. “And that’s precisely what occurred once more right here, however on cellular units. Cellphone OEMs do nearly as good a job as anybody can do…”

What Crypto Customers Can Do Now

Google says Coruna “shouldn’t be efficient in opposition to the newest model of iOS,” and urges customers to replace. If updating isn’t attainable, GTIG recommends enabling Apple’s Lockdown Mode. GTIG additionally says it added the recognized web sites and domains to Google Secure Shopping to assist cut back additional publicity.

For crypto-native customers, the speedy takeaway is sensible: cellular wallets sit on the intersection of high-value belongings and high-frequency net visitors, which makes “visit-to-compromise” campaigns uniquely harmful. GTIG’s reporting suggests the rip-off funnel wasn’t nearly getting victims to attach wallets, it was about getting them onto the appropriate system, on the appropriate iOS model, so exploitation might do the remaining.

At press time, the whole crypto market cap stood at $2.45 trillion.

Crypto Scams Can Trigger iOS Exploits
Whole crypto market cap faces the 0.786 Fib, 1-week chart | Supply: TOTAL on TradingView.com

Featured picture created with DALL.E, chart from TradingView.com



Source link

ad
Crypto Exploits IOS scams trigger
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Related Posts

U.S. judge freezes BlockFills assets in dispute over 70 bitcoin with creditor Dominion Capital

March 5, 2026

Kraken xStocks launches xChange for on-chain stock trading

March 5, 2026

Cardano Founder Shares What To Expect For XRP If The Clarity ACT Is Passed

March 5, 2026

NVIDIA CCCL 3.1 Adds Floating-Point Determinism Controls for GPU Computing

March 5, 2026
Add A Comment
Leave A Reply Cancel Reply

ad
What's New Here!
U.S. judge freezes BlockFills assets in dispute over 70 bitcoin with creditor Dominion Capital
March 5, 2026
Kraken xStocks launches xChange for on-chain stock trading
March 5, 2026
Crypto Scams Can Trigger iOS Exploits
March 5, 2026
Cardano Founder Shares What To Expect For XRP If The Clarity ACT Is Passed
March 5, 2026
NVIDIA CCCL 3.1 Adds Floating-Point Determinism Controls for GPU Computing
March 5, 2026
Facebook X (Twitter) Instagram Pinterest
  • Contact Us
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms of Use
  • DMCA
© 2026 StreamlineCrypto.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.