iPhone Spyware Is Now Hunting Crypto Wallets Every 15 Seconds
iVerify's P7 DarkSword report describes a new iPhone spyware variant that takes remote commands and pulls imToken wallet data off compromised devices on a roughly 15-second loop. Here's why that loop matters more than the malware itself.
Your seed phrase lives on your phone. Think about that for a second. For most of us, the handset is the wallet, the 2FA, the exchange login, and the identity all at once. And now there's malware built specifically to strip it out.
Security researchers at iVerify flagged a new iPhone spyware variant in their P7 DarkSword report. Once a device is compromised, the tool accepts remote commands from an operator and goes hunting for imToken-related data. Not a smash and grab. A sustained pull. The extraction routine reportedly runs on a 15-second cycle, vacuuming wallet credentials and other sensitive data off the handset while the owner has no idea.
Fifteen seconds. Anon, let me explain what that actually means. By the time you've unlocked your phone, glanced at a notification, and locked it again, the thing has already checked in several times. That's not a one-time theft. That's a live feed.
imToken as the named target isn't random either. It's one of the most widely used non-custodial wallets on the planet, with millions of installs across Asia and beyond. Non-custodial is the entire pitch. Your keys, your coins. But the moment spyware can read what the app can read, that promise gets a lot thinner. The chain doesn't lie. Your phone might.
And here's the part that should bug you. This isn't exotic nation-state gear with a two-million-dollar budget. Mobile spyware went commercial years ago. It gets sold, licensed, and pointed at regular people who happen to hold size. Retail traders. Airdrop farmers. Anyone whose bags are worth the effort.
So how do you even know if your device is dirty? Honestly, you mostly can't. iOS doesn't ship a tool that tells you. You'd need a scanner like the one iVerify sells, or enterprise-grade device checks, and even then you're playing catch-up against something that runs every 15 seconds.
My take: this is bigger than people realize, and not because the malware is clever. It's because we've quietly made the phone the weakest link in self-custody and then acted surprised when attackers noticed. Long-term holdings belong on a hardware wallet. Hot wallets should stay small and treated as disposable. Don't jailbreak. Don't sideload. Patch iOS the day updates drop, because Apple moves fast once it knows what it's hunting.
Two things to watch. Whether iVerify publishes the full exploit chain, and whether Apple confirms a fix. Until one of those lands, assume your phone is less private than you think.
Related Articles
Colibrì Runs a 1.5TB AI Model on 25GB of RAM: The Local AI Breakthrough That Changes Everything
July 11, 2026

AI in Healthcare 2026: FDA-Cleared Clinical Tools, Hospital Deployments, and the Diagnostics Revolution
July 9, 2026

AI Data Center Energy Crisis 2026: How the Power Grid Bottleneck Is Reshaping AI Scaling
July 8, 2026
