Cryptocurrency theft in 2026 is increasingly beginning through compromised websites, software packages, and mobile applications.
Instead of attacking a blockchain directly, criminals are looking for ways to steal private information that gives users access to their funds. Security researchers identified 13 malicious packages spread across five developer namespaces.
The compromised website themes contained JavaScript designed to identify iPhone visitors and deliver an exploit chain against devices running vulnerable versions of iOS.
The campaign used WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529, which Apple had already addressed in newer software updates.
Once exploited, the attack could move beyond the browser and provide deeper access to the device, creating opportunities for spyware and cryptocurrency-wallet theft.
Developers Are Becoming a Gateway to Crypto Theft
Software developers are also facing growing supply chain attacks. In July, attackers compromised version 1.20.21 of Injective Labs’ @injectivelabs/sdk-ts npm package, a software development kit used by wallets, trading tools, and decentralized finance (DeFi) applications.
The malicious version attempted to steal wallet private keys and mnemonic recovery phrases. Because the legitimate package receives roughly 50,000 weekly downloads, a compromised release can potentially expose a large number of developers and applications.
Another malicious npm release, jscrambler@8.14.0, installed a Rust-based information stealer targeting Windows, Linux, and macOS.
Researchers found that it searched for wallet information and seed phrases associated with MetaMask, Phantom, and Exodus, while also targeting browser passwords, cloud credentials, and password-manager data.
Fake Wallet Apps Put iPhone Users Directly at Risk
Attackers are also going after cryptocurrency users through fake wallet applications. Kaspersky reported finding more than two dozen phishing applications in Apple’s App Store that imitated popular crypto wallets.
Some of these applications redirected users toward sideloaded wallet clones, where victims could be asked to enter their recovery phrases. The information could then be transmitted to attackers.
Another threat, SparkKitty, searches phone photo libraries for screenshots that may contain recovery phrases. This makes seemingly harmless storage habits a serious security risk for crypto users.
Recovery Phrases Are Still the Main Target
A recovery phrase can restore access to a cryptocurrency wallet without the original device or hardware wallet. If criminals obtain it, they may be able to take control of the wallet and move its funds.
For this reason, users should never store recovery phrases in screenshots, cloud photo libraries, ordinary notes, or other easily accessible locations.
Developers should carefully review and pin software dependencies, while website operators should remove untrusted themes, rotate exposed credentials, and monitor suspicious network activity. Most importantly, iPhone users should install security updates promptly.
The attacks demonstrate a simple lesson: protecting cryptocurrency requires more than securing the blockchain. Users must also protect the devices, applications, websites, and software supply chains that can expose the secrets controlling their funds.




