Every 15 Seconds: New iPhone Spyware Is Draining Crypto Wallets and Most Users Have No Idea

A newly documented iPhone spyware tool can silently hunt for crypto wallet data and extract it on a 15-second loop, and most holders using mobile wallets don't even know the threat exists.

iVerify's P7 DarkSword report is the source, and it's not subtle. Researchers identified remote commands capable of targeting imToken-related data on compromised iPhones, pulling sensitive wallet information repeatedly in near real-time. That's not a glitch or a proof-of-concept. That's an active, operational exfiltration pipeline running in your pocket.

How This Attack Actually Works

The spyware operates post-compromise, meaning it needs initial access to your device before the wallet-hunting begins. Once inside, it doesn't wait around. It issues remote commands on a repeating cycle, collecting crypto wallet data every 15 seconds and sending it back to whoever is pulling the strings.

imToken is the named target in the iVerify report, but the implications reach further. If one wallet app is being actively hunted, it signals that mobile wallets broadly are now high-value targets worth building persistent, automated attack infrastructure around. This isn't opportunistic. It's deliberate.

Why This Matters More Than the Last Hack You Ignored

Most crypto security headlines are about protocol exploits, bridge hacks, or phishing links. This is different. This is device-level surveillance infrastructure built specifically to extract wallet data, running silently, automatically, and continuously.

Your hardware wallet sitting at home does nothing if the seed phrase you typed into your phone six months ago was already captured. Your two-factor authentication means nothing if the app generating the codes is on a compromised device. The attack surface here is your phone itself, and most people treat their phone as the safest part of their crypto setup.

What Crypto Holders Should Do Right Now

First, stop storing seed phrases, private keys, or wallet recovery data anywhere on your iPhone. Screenshots, notes apps, and even encrypted folders are all accessible on a compromised device.

Second, run iVerify or a comparable mobile threat detection tool if you hold meaningful crypto. The app exists specifically to surface this kind of compromise, and DarkSword was caught because of it.

Third, if you use imToken or any mobile-first wallet as your primary storage, reconsider your setup. Hardware wallets with air-gapped signing are not optional for serious holders anymore, they're the minimum viable security posture.

The 15-second extraction cycle is the detail that should keep you up at night. Attackers aren't skimming. They're sweeping, continuously, waiting for the moment your balance makes the data worth using.

Watch this threat category closely. It is not going away.