Trust Wallet Warns Users of iMessage Zero-Day Exploit Targeting iOS Devices

Trust Wallet has issued an urgent security alert warning users of a high-risk zero-day vulnerability affecting Apple's iMessage platform on iOS, according to a notice released on December 24, 2025. The flaw reportedly enables attackers to gain unauthorized access to devices without any user interaction, a so-called "zero-click" exploit.
According to the wallet provider, the vulnerability could allow malicious actors to bypass standard device-level protections and access sensitive information if a digital wallet application is active in the background. Cybersecurity researchers cited by Trust Wallet indicated that the exploit may target data stored within a device's secure enclave, potentially exposing private keys or seed phrases under certain conditions.
As an immediate precaution, Trust Wallet advised users to disable iMessage in their system settings until Apple deploys an official patch. The company described the step as a temporary mitigation measure aimed at reducing exposure to the vulnerability.
The incident has raised broader concerns within the cryptocurrency community, as zero-click exploits can circumvent traditional safeguards such as two-factor authentication and biometric locks by exploiting weaknesses in the operating system itself. Trust Wallet recommended that users holding significant digital assets consider moving funds to hardware wallets or using "watch-only" addresses for routine monitoring. Users were also encouraged to review and revoke unnecessary decentralized application (dApp) permissions.
"This type of attack highlights the increasing focus on mobile infrastructure rather than direct attacks on blockchain protocols," the company noted, pointing to a wider trend of sophisticated cyber threats targeting smartphones and messaging platforms.
In response, Trust Wallet said it is accelerating the rollout of an emergency update that will strengthen local data encryption and implement stricter session timeout policies. The firm is also working with industry security groups to share threat intelligence and improve standards for non-custodial wallets operating on shared mobile systems.
While no confirmed large-scale losses have been directly linked to the iMessage exploit so far, the warning underscores the risks associated with managing digital assets on everyday communication devices. The episode has prompted renewed discussion about mobile security as an integral component of digital asset protection going into 2026.
Subscribe Now

