Come post your brilliant ideas in the comments, you arrogant plonkers.
Apple patched another ~30 security holes in iOS 26.6.1 with a particularly nasty one: "Processing an image may lead to arbitrary code execution" (CVE-2026-65346)
You're going to get GODSTOMPED by the many men who are NOT good. Tons of iOS exploits were abused for YEARS before the "good guys" ever caught wind. Some of the flaws they were exploiting had been sitting there for DECADES.
Your "security" is contingent upon the GOODWILL of other men.
That is a horrible game plan. And when you lose all your money for being cute with your OPSEC, don't cry too loud.
Skill Issue.
The vulnerable code behind iOS CVE-2026-20700 predates the 2007 iPhone itself, having been inherited from macOS, with roots reaching back to NeXTSTEP. It was not patched until 2026. Yes, really.
It was actively exploited "in the wild" by multiple threat actors, and chained together with other security holes.
@tayvano_
"DARKSWORD"
And before DARKSWORD, iOS was getting cucked by "CORUNA", an iOS exploit that achieves FULL DEVICE COMPROMISE.
I'll repost some others (non-exhaustive) since you people glossed over them:
KISMET - NSO Group
FORCEDENTRY - NSO Group
FINDMYPWN - NSO Group
PWNYOURHOME - NSO Group
ENDOFDAYS - QuaDream
BLASTPASS - NSO Group
OPERATION TRIANGULATION - Unknown
GRAPHITE - Paragon Solutions
What else is there to say?
∙
North Korea IS capable of zero-days, and chaining zero-days, but they don't need any of that to annihilate the crypto industry. They're operating at a fraction of their true power, like DragonBall Z.
They send you guys poisoned PDFs, phishing links, Zoom links, and your dead bodies float down the river.
It's a Graveyard of Rekt™
What battle? What defence? It's a slaughter and butcher.
When "normies" clown crypto, it's accurate. It's a joke industry. There's Bitcoin, there's Ether, and there's the USD. That's it.
Everything else must invent a reason to exist, in an attempt to acquire: more Bitcoin, Ether, and USD. People have been trying to "make moves" for 17 years, only to get bodied by tokenized fiat currency.
KEK
North Korea is a third world threat actor, not even close to being the top elite. But they don't need to elite to manhandle the crypto industry.
And despite the Rekt City™ that takes place daily, the crypto industry displays the greatest hubris by far.
Projects communicate through postmortems as if some profound lesson was absorbed, only to get killshotted the very next day, by some other exploit they never saw coming.
You have mountains of evidence, security researchers stating the contrary, but y'all triple down that an iPhone is more secure than a Hardware Wallet.
Millions of lines of code on a multimedia entertainment device
vs
A compact codebase on dedicated hardware that has one job
Not even Apple engineers would agree with you.
DONKEY.
∙
@vidya_no68665 thinks he's clever with:
>"You're suppose to set the Iphone aside and only interact with it when needed not fucking daily drive it, I thought this was fucking obvious."
You are grossly overestimating the security of stock iOS with absolutely nothing on it. The attack surface is MASSIVE.
On iOS, your PRIVATE KEY is exposed in RAM, you retard. The Secure Enclave cannot do secp256k1 so your wallet has no choice but to decrypt and sign in memory. You are naked, AND in the AFU State which is the most vulnerable state for an iPhone.
Compare that to a proper hardware wallet where the private key remains inside the Secure Element. (Do not mention Coldcard, I have a specialty dunk thread for those noob investors already, who are full of arrogance).
@__noided
Further, run Wireshark on a separate device and see how busy your "clean iphone" is with hundreds of connections happening in the background. It's not "quiet". Your iPhone is never idle, and it's constantly parsing untrusted data: iMessage, WebKit, ImageIO, fonts... which IS the attack surface.
@n13 -- Airplane Mode is a software toggle, not a hardware kill switch. Wi-Fi/Bluetooth/Cellular/NFC/UWB run their own firmware and remain connected to the main processor. Some use DMA to access restricted regions of host memory. Now, Apple does constrain this access but they don't eliminate it.
Find My literally still works against a powered off iPhone using reserve power. It broadcasts a Bluetooth Low Energy beacon that other Apple devices can pick up and relay through the Find My network. Your iPhone is still transmitting even when "off".
If people want to get cute with muh "QR Codes", come on now. The iPhone can still parse attacker-controlled input, AND memory corruption bugs in image-processing code have led to RCE already. CVE-2026-65346 is a recent example, patched this week. You can presume there are others that the "good guys" haven't found yet. Why would they be notified?
∙
History Lesson:
Exploit after exploit, Apple was brought to their knees.
In desperation, you know what Apple did in response?
They sued the NSO Group.
lol lmao even
"PLS STOP HACKING US, PLSSSS"
And then? Apple walked away from their own lawsuit because discovery would have forced them to disclose sensitive intel that other bad actors would have weaponized against them.
NSO Group aside, there's an entire black market and grey market for iOS zero days. And these upstanding scholars are not buying exploits to report them to Apple. They are going to use them to destroy you, for as long as possible until they're patched, if ever. If they're lucky, they can use it for YEARS.
"In the wild" simply means "the good guys finally noticed bro".
Great plan, everyone. Good work.
Guess who discovers tons of iOS zero-days?
Google
Citizen Lab
Amnesty
Kaspersky
Numerous independent researchers
Anonymous reports
Often, it's not even Apple themselves.
Your goodwill is stacked on top of goodwill from people who have zero obligation to Apple.
Y'all have no clue if it was exploited or not because not everyone is reporting they got Rekt™. And, you have no idea if you were exploited when it concerns zero-days. It can execute and persist, without you noticing.
@SatoshiSideho -- Apple has been getting Rekt™ for years
@bch_gangster -- Zach does great work and I'm not knocking that. But he's a self-taught on-chain investigator, not a cryptographer, and he's never claimed otherwise. He has social reach, and you're citing him on something outside his expertise. People can be wrong, you know?
∙
The amusing thing is I dunk on hardware wallets all the time, targeting their actual weaknesses unrelated to noob skill issues. Go read them.
I've been citing iPhones & Pixels well before Zach's post, and well before any KOL reacted to "timeline news".
Y'all have this notion that I don't have a plethora of tools at my disposal and have reached a sound conclusion based on hard evidence, and BATTLE EXPERIENCE.
I don't need a job, your job, or any referral links. I can speak with the most freedom, uninhibited by bias.
Meanwhile, dudes clinging onto their sole iPhone are looking for confirmation bias.