The post Google Warns of “Coruna” iPhone Exploit That Could Drain Crypto Wallets appeared first on Coinpedia Fintech News
A newly discovered iPhone vulnerability is raising alarms across the crypto community. Security researchers say a sophisticated exploit kit called Coruna is targeting older iPhones and could potentially steal sensitive crypto wallet data, including recovery phrases.
The warning comes from the Google Threat Intelligence Group, which revealed that the exploit aggressively scans devices running outdated versions of Apple’s mobile software.
Coruna is not a simple malware attack. Researchers say it combines five full exploit chains and at least 23 vulnerabilities to break into devices running versions between iOS 13 and iOS 17.2.1.
The attack usually begins when a user visits a compromised or malicious website. Hidden JavaScript on the site silently scans the visitor’s device to identify the model, operating system version, and security settings.
Once a vulnerable device is detected, Coruna launches a multi-stage exploit chain that bypasses Apple’s built-in security protections. The malware then escalates system privileges, allowing attackers to install spyware and extract sensitive information from the device.
According to researchers, the malware is designed to hunt for encrypted wallet files, login credentials, and mnemonic recovery phrases used to restore crypto wallets.
If attackers gain access to those recovery phrases, they can instantly restore the wallet on another device and transfer the funds. This means victims could lose their entire holdings of assets like Bitcoin and Ethereum without realizing it until the transactions are complete.
Investigators say Coruna spreads through “watering hole” attacks, where hackers compromise websites frequently visited by crypto users, including fake trading platforms and phishing sites.
Security firm iVerify found that parts of Coruna’s code resemble tools believed to have originated from U.S. government cyber programs.
However, researchers believe the toolkit may have leaked and is now being used by cybercriminal groups and intelligence actors from countries like Russia and China.
This could mark the first large-scale mobile exploit campaign using tools derived from nation-state cyber capabilities.
The good news is that the attack has clear limitations. Coruna fails to operate on devices running the latest iOS versions. It also stops if Apple’s Lockdown Mode is enabled and does not work in private browsing mode.
Security experts say users should take a few critical precautions:
For crypto investors, experts say updating your device may now be more important than timing the market, as one successful exploit could wipe out an entire wallet in seconds.
Stay ahead with breaking news, expert analysis, and real-time updates on the latest trends in Bitcoin, altcoins, DeFi, NFTs, and more.
Coruna is an advanced exploit kit targeting outdated iPhones. It can bypass iOS security and steal crypto wallet data, including recovery phrases, which attackers can use to drain funds.
Yes. If attackers obtain your wallet’s recovery phrase or login data, they can restore the wallet on another device and transfer Bitcoin, Ethereum, or other assets instantly.
Keep iOS updated, avoid suspicious crypto websites, enable Lockdown Mode if needed, and store recovery phrases offline rather than in notes, screenshots, or cloud storage.
Crypto wallets hold direct access to digital assets. If attackers steal recovery phrases or credentials, they can transfer funds instantly with little chance of recovery.


