The hacking kit itself exploits vulnerabilities in Apple's WebKit and JavaScriptCore components, which allows hackers to target vulnerable iPhone devices to access sensitive data.
After hacking into the device, the Coruna malware can then focus on crypto wallets to try and steal information that can give hackers access to your funds.
The affected crypto wallet apps include Coinbase, MetaMask, Trust Wallet, Phantom, Exodus, Uniswap, Bitpie, imToken, and OKEx.
The threat isn't limited to wallet apps. According to Censys, the malware can also scan through your photos and notes on infected devices to look for BIP39 recovery phrases.
These phrases are highly valuable to cybercriminals, as they can be used to recover crypto wallets, giving the criminals potential access to your crypto holdings even if they don't have access to your device.
How to protect your crypto
Thankfully, Apple has already fixed the vulnerabilities exploited by DarkSword.
All known security vulnerabilities used by the hacking kit have already been patched in iOS 26.3, as per Macworld.
There is a possibility that older iPhone devices running iOS 26.2 and below (including older versions of iOS 18) could still be vulnerable to the attack, if they haven't been updated with the required security fixes.
Therefore, crypto holders are being advised to ensure that their devices are up to date to minimise the risk of being targeted by these attacks.