Malicious Web Themes Target iPhone Users to Harvest Crypto Wallet Seeds
Security researchers have uncovered a new campaign that embeds hidden code in website themes to siphon cryptocurrency wallet seed phrases from iPhone visitors. The malicious themes are being deployed on Vietnamese movie and comic streaming sites, turning ordinary page loads into a covert conduit for spyware and crypto theft.
The attack operates by inserting a script into the visual theme files that users download when accessing the compromised sites. Once the theme is applied, the script exploits a browser vulnerability to gain access to the device’s clipboard and other data stores, capturing the 12‑ or 24‑word recovery phrases many crypto wallets rely on. Because the code runs in the background, victims see no warning or prompt, and the theft can occur before the user even realizes their wallet has been compromised.
Apple’s iOS platform is often praised for its closed ecosystem and rigorous App Store review process, which limits the spread of malicious software. However, web‑based attacks sidestep these safeguards by delivering payloads directly through the browser, a vector that does not require a downloadable app. The use of popular streaming sites amplifies the threat, as they attract large numbers of mobile users seeking entertainment, many of whom may be unaware of the security risks associated with third‑party themes.
Cryptocurrency wallets store private keys and seed phrases that grant full control over digital assets. Losing a seed phrase effectively hands over the wallet’s contents to the attacker, and unlike traditional bank accounts, there is typically no recourse for recovery. The lure of such high‑value data has made crypto users a prime target for cybercriminals, and the current technique represents a novel method of extracting that information without needing to compromise the wallet app itself.
Experts advise iPhone users to exercise caution when browsing unfamiliar sites, especially those offering downloadable themes or customizations. Disabling clipboard access for browsers, keeping the operating system updated, and using reputable security tools can reduce exposure. Additionally, many wallet providers now recommend storing seed phrases offline in physical form rather than copying them on devices that regularly interact with the internet.
The discovery highlights a growing trend of attackers leveraging web‑based infection chains to reach mobile devices, a space that has traditionally been considered more secure. As the cryptocurrency market continues to expand, security professionals expect similar tactics to evolve, targeting other regions and platforms. Ongoing monitoring and rapid disclosure of such vulnerabilities remain essential to protect users from covert, financially devastating attacks.
Comments (0)
Be the first to comment.
Join the discussion