Google reveals iPhone cryptocurrency attack toolkit "Coruna," capable of stealing seed phrases and wallet information

March 5 News: Google Threat Intelligence Group (GTIG) recently released a security report stating that researchers have discovered a new iPhone exploit toolkit called “Coruna,” used to steal cryptocurrency wallet mnemonics and financial information. The toolkit targets devices running iOS 13.0 to 17.2.1 and launches targeted attacks through multiple exploit chains, drawing significant attention in the mobile security field.

The report shows that “Coruna” contains five complete iOS exploit chains, involving a total of 23 security vulnerabilities, some of which have never been publicly disclosed before. Google researchers said they first identified related attack activity in February 2025 and found that the tool was initially suspected to be used by Russian espionage groups for cyberattacks against Ukrainian users. It was later used to impersonate financial and crypto-related websites to trick users into revealing information.

The attack mainly relies on malicious web pages delivering exploit code. When iPhone users visit specific sites, JavaScript frameworks on the pages perform device fingerprinting, verify the system version, and then load the corresponding exploit chain. Researchers found the same framework on multiple compromised Ukrainian websites and noted that the attack code was only sent to iPhones in certain regions.

In December 2025, the team further detected the same framework on numerous fake Chinese-language websites related to financial services, including counterfeit crypto platform pages. Once victims access these sites on iOS devices, the tools scan for sensitive information such as mnemonic phrases, backup words, or bank account details, and attempt to read data from common crypto wallet apps to gain control of digital assets.

Google states that this exploit toolkit currently cannot run on the latest iOS versions, and recommends iPhone users upgrade their systems promptly. If upgrading is not possible, users can enable Apple’s “Lockdown Mode” to defend against complex network attacks.

Meanwhile, discussions about the origin of “Coruna” have also sparked controversy. Rocky Cole, co-founder of mobile security firm iVerify, told media that the tool is highly complex, with development costs possibly reaching millions of dollars, and shares some modules similar to those used in U.S. government cyber tools. However, Kaspersky security experts said there is currently not enough evidence to directly link its code to any known tools.

Security experts warn that cryptocurrency users should be vigilant against phishing pages and update their devices promptly when using mobile wallets or visiting related websites to reduce the risk of mnemonic leaks and digital asset theft.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Attacker Mints 1B DOT, Dumps for $237K ETH

A security incident involving the ERC-20 version of Polkadot on Ethereum raised concerns, emphasizing the risks of wrapped and cross-chain assets. An attacker exploited a flaw to mint and dump 1 billion DOT tokens, causing a market collapse and highlighting vulnerabilities in smart contract management.

Coinfomania2h ago

Music Star G. Love Loses 5.9 Bitcoin in Shocking App Store Scam

_Musician G. Love loses 5.9 BTC in fake Ledger app scam, raising serious concerns about crypto security and user awareness worldwide._ A major crypto scam has affected Garrett Dutton, widely known as G. Love. The American singer lost 5.9 Bitcoin valued at almost 420,000. The loss occurred when he t

LiveBTCNews2h ago

Aave Faces a Major Trust Crisis: Service Providers Exit En Masse, with “Technology, Governance, and Risk Control” Fully Failing

Author: Jae, PANews Compared with the external pressure of a bear market, Aave has instead seen a “black swan” emerge internally first. Aave, which has long occupied the throne of lending agreements, is now facing the most severe ecosystem shake-up since its founding. There has been no hacker attack, no code vulnerabilities—only power gone out of control and conflicting interests. From BGD Labs, a technical cornerstone, decisively leaving, to a public break between governance pioneer ACI (Aave Chan Initiative), and then to Chaos Labs, the risk-management steward, announcing that it is parting ways— a major “service provider retreat” is unfolding. The depth of this game goes far beyond a mere cooperation dispute; it has triggered

区块客3h ago

Polkadot Undergoes Bridge Exploit, Attacker Mints 1B $DOT on Ethereum

Polkadot faced a major security breach where an attacker minted 1B $DOT coins on Ethereum via a 3rd-party bridge, draining over $240,000 in $ETH. This incident highlights ongoing vulnerabilities in cross-chain infrastructure and its impact on market stability.

BlockChainReporter4h ago

Circle CEO: Due to the “moral dilemma,” the Drift hacker incident, which was not frozen, resulted in the theft of USDC

Circle CEO Jeremy Allaire addressed criticism at a news conference regarding the previously unfrozen stolen USDC, emphasizing that the company will only freeze wallets under law enforcement instructions. In addition, he said Circle is in communication with U.S. lawmakers, hoping to establish a “safe harbor” mechanism for stablecoin issuers.

GateNews5h ago

A woman in Hong Kong in her 50s was scammed through online romance, losing more than 2 million yuan; the scammer claimed to be a cryptocurrency investment expert.

Hong Kong police have disclosed a cryptocurrency investment scam in which a woman was tricked on Instagram, losing more than 2 million yuan. The fraudster posed as an investment expert, luring her into making transfers and exchanging cash multiple times. Police remind people to be more vigilant when making online friends and to watch out for transfer scams.

GateNews6h ago
Comment
0/400
No comments