On 16 April 2024, crypto wallet provider Trust Wallet issued a public alert on X warning of a “high‑risk zero‑day exploit targeting iMessage,” claiming it had “credible intel” from the dark web that the exploit could infiltrate iPhones without any user interaction and that high‑value targets were most at risk. The company said the code was being advertised on a dark‑web marketplace as an iMessage remote code execution “zero‑click” exploit working on the latest iOS version, allegedly priced at around $2 million in bitcoin, and advised iOS users—especially those holding significant crypto or other sensitive assets—to disable iMessage until Apple could patch the issue. Trust Wallet framed the risk as significant but also noted that each use of such an exploit would increase the chance of detection, suggesting it would likely be reserved for targeted, high‑value operations rather than mass attacks. Subsequent reporting raised doubts about the threat’s authenticity and criticized the warning as potentially overblown. TechCrunch and other outlets found that Trust Wallet’s “intel” consisted of a single dark‑web advertisement by a group calling itself CodeBreach Lab, offering the alleged iMessage exploit for sale but providing no verifiable technical proof, no working contact mechanism, and requiring buyers to send $2 million to an anonymous wallet upfront. Security reporters and researchers noted that dark‑web exploit listings are frequently scams and that, as of those reports, there was no independent confirmation that the vulnerability or exploit actually existed or had been used in real‑world attacks. The episode highlighted the tension between rapidly warning users about possible zero‑day threats to high‑value iPhone and crypto holders and the risk of spreading fear and uncertainty based on unverified dark‑web claims.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on $LINK

Comments