Connect with us

Tech

The DarkSword exploit on iOS 18 compromises cryptocurrency wallets across six platforms

Published

on

Google researchers have detected the DarkSword exploit on iOS 18 devices affecting versions 18.4 through 18.7, according to the Google Threat Intelligence report. This exploit chain utilizes six critical vulnerabilities to inject the Ghostblade malware, which extracts sensitive data from six exchange platforms and multiple digital wallets without leaving any apparent trace.

The intrusion chain is activated when users access compromised web portals that execute arbitrary code in the background. This silent process leverages flaws in the system’s rendering engine to install malicious components without requiring direct interaction from the owner of the affected device. The sophistication of DarkSword demonstrates a level of engineering previously reserved for government-level espionage operations.

Mobile espionage reaches critical levels of technical precision

Once inside the Apple environment, the Ghostblade component scans the system for centralized exchange applications such as Binance and Kraken. The objective is to capture login credentials and session tokens that allow total control over the user’s funds. This surgical approach minimizes system alerts, allowing the data extraction to occur within a matter of seconds.

The danger extends to self-custody solutions, including cold and hot wallets such as MetaMask, Ledger, and Phantom. By intercepting seed phrases and private keys during transaction processes, the malware nullifies the inherent security of physical storage for digital assets. The vulnerability puts the financial integrity of both retail and institutional investors at significant risk today.

Beyond financial data, the exploit extracts personal metadata including call logs, Wi-Fi passwords, and browsing cookies. This massive exfiltration capability allows for much more effective subsequent social engineering attacks against the victim. The collection of health and location data adds an extremely intrusive dimension of personal surveillance for any mobile user.

How does DarkSword alter the security paradigm for mobile devices?

From a technical perspective, Ghostblade introduces a tactical innovation based on the volatility of its files within the internal storage. After completing the data transfer to external command centers, the program automatically deletes its traces to avoid detection by mobile security tools. This ephemeral behavior makes it extremely difficult to create effective detection signatures at this time.

The geographic distribution of the campaign suggests advanced coordination, affecting critical infrastructure in nations such as Ukraine and Saudi Arabia. In these cases, the impersonation of legitimate government portals to spread the virus among the civilian population has been observed. This “watering hole” tactic maximizes the infection rate by abusing pre-existing institutional trust.

Historically, the blockchain sector has been the target of massive attacks such as the one recorded by Inferno Drainer, which stole nine million dollars. However, DarkSword represents a superior threat by acting directly on the operating system, differing from conventional phishing scams. The scale of this new risk demands a complete re-evaluation of security protocols.

To mitigate these risks, it is imperative that Apple device users install the latest security patches immediately. Reliance on SMS-based two-factor authentication should be reduced, opting instead for physical security keys or independent authentication apps. It is vital to prevent intrusions via software from unverified sources to maintain financial sovereignty.

The future of mobile security will depend on the manufacturers’ ability to close zero-day gaps before their exploitation. Meanwhile, constant monitoring of data flows and the use of isolated environments for cryptographic transactions are recommended measures. The industry must prepare for a new era of persistent threats that challenge the closed architecture of iOS continuously.

The post The DarkSword exploit on iOS 18 compromises cryptocurrency wallets across six platforms appeared first on The Cryptocurrency Post.

Tech

Aptos launches Confidential APT with encrypted balances on mainnet

Published

on

Aptos said Confidential APT is now live on mainnet, bringing opt-in encrypted balances to the network while keeping wallet addresses visible. The feature is positioned for compliant use cases including payroll, treasury and business-to-business settlement.https://twitter.com/Aptos/status/2084481961553445096

The Aptos account said transactions are verified with zero-knowledge proofs, allowing the network to confirm that transfers are valid without exposing the underlying amounts. The update is meant for users who want confidentiality for specific transfers rather than full anonymity across the network.

A separate governance page tied to the rollout shows the proposal as executed, matching Aptos’ public statement that the feature has been enabled on mainnet. The material linked from that page describes Confidential APT as part of Aptos’ on-chain privacy features.

How the feature is framed on Aptos

According to Aptos, Confidential APT is opt-in, so users can still use standard transparent transfers if they prefer. The company’s framing focuses on enterprise and institutional settings where transaction amounts may need to be hidden while counterparties remain identifiable.

The launch adds a privacy layer at the transaction level, but it does not by itself indicate broader usage or adoption. It does, however, give Aptos a live mainnet mechanism for hiding balances on selected transfers.

The post Aptos launches Confidential APT with encrypted balances on mainnet appeared first on The Cryptocurrency Post.

Continue Reading

Tech

NEAR says Machine Payments Protocol now uses NEAR Intents for agent settlements

Published

on

NEAR Protocol said the Machine Payments Protocol (MPP) from Stripe and Tempo now integrates with NEAR Intents, allowing agents on MPP to settle across more than 30 chains using NEAR infrastructure.

The update was shared by NEAR Protocol on X, where the team described the integration as live and pointed readers to public SDK and documentation for the payment method. The announcement frames NEAR Intents as part of the settlement layer for agent payments rather than as a standalone consumer product.

Settlement across multiple chains

According to the post, the integration gives any agent using MPP a way to settle payments across 30-plus chains. The announcement did not add further technical detail in the post itself, but it did direct users to the public documentation for the NEAR payment method.

MPP, or Machine Payments Protocol, is designed for programmatic payments between software agents and services. In this case, NEAR is presenting Intents as the mechanism that helps route those settlements across chains through its infrastructure.

The timing and scope of the change were stated by NEAR Protocol itself, which makes the integration the central confirmed development. The announcement did not include a broader rollout timeline, usage data or terms for availability beyond the public SDK and docs link.

What NEAR is highlighting

The key change is not a new token feature or a market-facing launch, but a payment-routing integration aimed at agent settlements. That places NEAR Intents inside an emerging category of machine-to-machine payment infrastructure, where the practical value depends on whether developers adopt it for real transactions.

For now, the confirmed claim is narrower: NEAR says MPP can now use its Intents system for cross-chain settlement, and the public documentation is available for developers who want to build around it.

The post NEAR says Machine Payments Protocol now uses NEAR Intents for agent settlements appeared first on The Cryptocurrency Post.

Continue Reading

Tech

NEAR AI says IronClaw 1.0 is now deployed as part of July shipments

Published

on

NEAR Protocol said its July shipments included NEAR staking for NEAR AI compute going live and the launch of IronClaw 1.0 on mainnet, marking a new step in the project’s AI and agent-related rollout. In a blog post announcing IronClaw 1.0, NEAR AI said the release is deployed across NEAR Foundation and NEAR AI.

The official recap also grouped the updates with broader AI and agent infrastructure changes, suggesting the deployments were part of a wider set of July deliveries rather than a standalone launch. That framing matters for readers tracking the project’s product pace: the post presents staking and IronClaw as live components, not as plans or test-stage features.

What NEAR said changed

According to the recap shared by NEAR Protocol, NEAR staking for NEAR AI compute is now live. The same update says IronClaw 1.0 has launched on mainnet, adding an additional deployment milestone to the project’s AI stack.

A separate post from a member of the project community also pointed to staking mechanics for NEAR AI compute and IronClaw hosting, but the clearest public confirmation in the material comes from NEAR’s own recap and the IronClaw 1.0 announcement.

The available information does not spell out all operational details of the deployments in one place, but it does make one thing clear: NEAR is presenting both the compute staking component and IronClaw 1.0 as active releases rather than future roadmap items.

The post NEAR AI says IronClaw 1.0 is now deployed as part of July shipments appeared first on The Cryptocurrency Post.

Continue Reading

Trending