Close Menu
CryptoAINews
  • Cryptocurrency
  • Blockchain
  • Bitcoin News
  • Altcoins
  • Crypto Market Trends
  • Crypto Mining
  • Ethereum
  • AI News
  • Sponsored
  • Advertise
Trending
  • How Googlers built the 2026 I/O save the date puzzle
  • BARD crypto surges 39%, yet $1.85 mln potential sell-off raises risk
  • AI ‘Vibe Coding’ Could Propel Ethereum Ahead
  • Crypto Scams Can Trigger iOS Exploits
  • What Did Anthropic Educate Pentagon On & Why Does It Matter?
  • How 1,000+ customer calls shaped a breakout enterprise AI startup
  • NotebookLM adds Cinematic Video Overviews
  • Jensen Huang says Nvidia is pulling back from OpenAI and Anthropic, but his explanation raises more questions than it answers
  • AI News
  • Cryptocurrency
  • Blockchain
  • Bitcoin News
  • Altcoins
  • Crypto Market Trends
  • Crypto Mining
  • Ethereum
  • Sponsored
  • Advertise
CryptoAINews
  • Cryptocurrency
  • Blockchain
  • Bitcoin News
  • Altcoins
  • Crypto Market Trends
  • Crypto Mining
  • Ethereum
  • AI News
  • Sponsored
  • Advertise
CryptoAINews
Home » Blockchain » Crypto Scams Can Trigger iOS Exploits
ChatGPT Image Mar 5 2026 10 30 56 AM
Blockchain

Crypto Scams Can Trigger iOS Exploits

CryptoAINewsBy CryptoAINewsMarch 5, 2026No Comments4 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email


Google’s Risk Intelligence Group (GTIG) is warning {that a} “new and highly effective” iOS exploit equipment, dubbed Coruna by its builders has been deployed on pretend finance and crypto web sites designed to lure iPhone customers into visiting pages that may silently ship exploits. For crypto holders, the chance is blunt: GTIG’s evaluation shows the campaigns finally centered on harvesting seed phrases and pockets information from standard cell apps.

Coruna targets Apple gadgets working iOS 13.0 by means of iOS 17.2.1, bundling 5 full exploit chains and 23 exploits. GTIG says it recovered the equipment after monitoring its evolution throughout 2025, from early use by a buyer of a business surveillance firm, to “watering gap” assaults on compromised Ukrainian web sites, and at last to broad-scale distribution through Chinese language-language scam sites tied to a financially motivated actor it tracks as UNC6691.

A Crypto Lure Designed For iPhones

Within the scam-wave part, GTIG says it noticed the JavaScript framework behind Coruna deployed throughout a “very massive set” of pretend Chinese language web sites largely themed round finance. One instance cited by GTIG is a pretend WEEX-branded crypto change web page that attempted to push guests onto an iOS system—after which a hidden iFrame could be injected to ship the exploit equipment “no matter their geolocation.”

Associated Studying

The supply mechanics matter as a result of they blur the road between conventional phishing and outright system compromise: in GTIG’s telling, merely arriving on the booby-trapped web page from a susceptible iPhone was sufficient to start the chain. The framework fingerprints the system to establish mannequin and iOS model, then hundreds the suitable WebKit distant code execution exploit and a pointer authentication (PAC) bypass.

GTIG tied one WebKit RCE it recovered to CVE-2024-23222, noting it was addressed by Apple in iOS 17.3 on Jan. 22, 2024.

On the finish of the chain, GTIG says Coruna drops a stager it calls PlasmaLoader (tracked as PLASMAGRID) and describes it as centered much less on traditional surveillance options and extra on stealing monetary info. Based on GTIG, the payload can decode QR codes from photographs saved on the system and scan textual content blobs for BIP39 phrase sequences, together with key phrases similar to “backup phrase” and “checking account”, together with in Apple Memos, which it could possibly then exfiltrate.

Associated Studying

The payload can be modular. GTIG says it could possibly pull down and run extra modules remotely, and that most of the recognized modules are designed to hook capabilities and exfiltrate delicate info from frequent crypto pockets apps—amongst them MetaMask, Belief Pockets, Uniswap’s pockets, Phantom, Exodus, and TON ecosystem wallets similar to Tonkeeper.

The broader arc was additionally flagged by cell safety agency iVerify, which printed its personal findings across the similar time as GTIG’s report. “And that’s precisely what occurred once more right here, however on cell gadgets. Telephone OEMs do pretty much as good a job as anybody can do…”

What Crypto Customers Can Do Now

Google says Coruna “shouldn’t be efficient in opposition to the newest model of iOS,” and urges customers to replace. If updating isn’t doable, GTIG recommends enabling Apple’s Lockdown Mode. GTIG additionally says it added the recognized web sites and domains to Google Protected Searching to assist scale back additional publicity.

For crypto-native customers, the instant takeaway is sensible: cell wallets sit on the intersection of high-value belongings and high-frequency net visitors, which makes “visit-to-compromise” campaigns uniquely harmful. GTIG’s reporting suggests the rip-off funnel wasn’t nearly getting victims to attach wallets, it was about getting them onto the fitting system, on the fitting iOS model, so exploitation may do the remainder.

At press time, the full crypto market cap stood at $2.45 trillion.

Whole crypto market cap faces the 0.786 Fib, 1-week chart | Supply: TOTAL on TradingView.com

Featured picture created with DALL.E, chart from TradingView.com



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
CryptoAINews
  • Website

Related Posts

Analyst Says It’s Time For Bitcoin, But What’s Important About $58,000?

March 4, 2026

Bitcoin Slides Again as Iran War Jitters Hit BTC, Risk Assets

March 3, 2026

XRP Price About To Enter ‘Face-Melting Phase’, And The Target Is $27

March 2, 2026

Say What You Want — XRP’s Chart Is Screaming $50 — Analyst

March 1, 2026
Add A Comment
Leave A Reply Cancel Reply

About us

CryptoAINews is an independent digital publication focused on cryptocurrency, blockchain, and artificial intelligence news.

The platform is owned and operated by Robert Grabarevic, providing timely news coverage, market updates, and educational content for a global audience interested in emerging technologies and digital finance.

CryptoAINews is committed to transparent reporting, responsible publishing, and delivering informative content based on publicly available data, verified sources, and industry developments.

All content published on this website is for informational purposes only and does not constitute financial or investment advice.

Top Insights

How Googlers built the 2026 I/O save the date puzzle

March 5, 2026

BARD crypto surges 39%, yet $1.85 mln potential sell-off raises risk

March 5, 2026

AI ‘Vibe Coding’ Could Propel Ethereum Ahead

March 5, 2026
Categories
  • Advertise
  • AI News
  • Altcoins
  • Bitcoin News
  • Blockchain
  • Crypto Market Trends
  • Crypto Mining
  • Cryptocurrency
  • Ethereum
  • Sponsored
  • Imprint-Legal-Notice
  • Author / Publisher Bio
  • Privacy Policy
© 2025 CryptoAINews – Owned & Operated by Robert Grabarevic

Type above and press Enter to search. Press Esc to cancel.