<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>SafeW Risk Dossier · Blog</title><link>https://blog.nosafew.com/</link><description>Recent blog posts on SafeW Risk Dossier · Blog</description><generator>Hugo (https://gohugo.io)</generator><language>en</language><managingEditor/><webMaster/><lastBuildDate>Sat, 08 Aug 2026 16:45:40 +0800</lastBuildDate><atom:link href="https://blog.nosafew.com/en/tags/xinbi-guarantee/index.xml" rel="self" type="application/rss+xml"/><item><title>It Wasn't the Link That Stole Your USDT — It Was the App You Installed: Debunking the “iOS Vulnerability” Shill Posts</title><link>https://blog.nosafew.com/en/posts/safew-blame-the-link/</link><pubDate>Sat, 08 Aug 2026 16:45:40 +0800</pubDate><author/><description>
Over the past couple of days, the same post has been making the rounds in Chinese-language crypto and underground-payment group chats: on August 7, 2026, someone had 1.5 million USDT (worth over ten million RMB, by the post&amp;amp;rsquo;s own account) swept out of two wallets within ten seconds of each other. The post then offers its “deep analysis”: an Apple system vulnerability — iOS 13 through 26 have all been cracked, merely browsing a website can silently steal your wallet keys, therefore “do not click on any website” and “be careful with any URL.”
If this post has crossed your feed, keep the conclusion of this article in mind: it wasn&amp;amp;rsquo;t a link you clicked that stole your USDT — it was an app you installed with your own hands. And posts like this one, which blame everything on links and on Apple, are the smokescreen laid down for the real culprit. Below, in plain language, is who the thieves are and how the deflection script works.</description><content:encoded>&lt;p&gt;Over the past couple of days, the same post has been making the rounds in Chinese-language crypto and underground-payment group chats: on August 7, 2026, someone had 1.5 million USDT (worth over ten million RMB, by the post&amp;rsquo;s own account) swept out of two wallets within ten seconds of each other. The post then offers its “deep analysis”: an Apple system vulnerability — iOS 13 through 26 have all been cracked, merely browsing a website can silently steal your wallet keys, therefore “do not click on any website” and “be careful with any URL.”&lt;/p&gt;
&lt;p&gt;If this post has crossed your feed, keep the conclusion of this article in mind: &lt;strong&gt;it wasn&amp;rsquo;t a link you clicked that stole your USDT — it was an app you installed with your own hands.&lt;/strong&gt; And posts like this one, which blame everything on links and on Apple, are the smokescreen laid down for the real culprit. Below, in plain language, is who the thieves are and how the deflection script works.&lt;/p&gt;
&lt;h2 id="1-first-meet-the-thieves-this-family-of-apps-is-in-the-usdt-stealing-business" &gt;
&lt;div&gt;
&lt;a href="#1-first-meet-the-thieves-this-family-of-apps-is-in-the-usdt-stealing-business"&gt;
#
&lt;/a&gt;
1. First, meet the thieves: this family of apps is in the USDT-stealing business
&lt;/div&gt;
&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://blog.nosafew.com/images/posts/safew-blame-the-link/tweet-xinbi.png"
alt="Tweet: SafeW / SafeX pushed by Xinbi Guarantee, and related delivery apps, carry SparkCat"&gt;&lt;figcaption&gt;
&lt;p&gt;The tweet: SafeW / SafeX, heavily pushed by Xinbi Guarantee, along with the closely connected delivery apps “Kuaizi Life” and “Wukong Waimai,” all carry SparkCat — malware built to steal wallet seed phrases.&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Xinbi Guarantee, a gray-market escrow bazaar on Telegram, runs a USDT-stealing business of its own. The two “insider” messengers it pushes hard — &lt;strong&gt;SafeW&lt;/strong&gt; and &lt;strong&gt;SafeX&lt;/strong&gt; — plus several Southeast Asian food-delivery apps tied to it in a thousand ways — “Kuaizi Life” (筷子生活) in the Philippines, “Wukong Waimai” (悟空外卖) in Thailand, “Baituo Baituo” (拜托拜托) in Dubai — have all been found carrying the same malicious code: &lt;strong&gt;SparkCat, built specifically to steal crypto wallet seed phrases.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This is not some group-chat rumor. Kaspersky, one of the world&amp;rsquo;s best-known security firms, has confirmed it two years running:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;February 2025&lt;/strong&gt;: Kaspersky published its SparkCat report — a batch of apps in the official App Store and Google Play had this stealer code embedded, and SafeW&amp;rsquo;s package names were on the affected list. Per coverage at the time, the list included 43 apps from the App Store and 10 from Google Play; besides Wukong Waimai, it also featured ATV Asia TV, VPN accelerators, and several blockchain-related apps.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;April 2026&lt;/strong&gt;: a new SparkCat variant surfaced — with “SafeW - Cloud Office Assistant” on iOS and SafeX on Android back on the list. New name, same theft.&lt;/li&gt;
&lt;/ul&gt;
&lt;figure&gt;&lt;img src="https://blog.nosafew.com/images/posts/safew-blame-the-link/phhua-wukong.png"
alt="Phhua forum post, February 2025: apps made by gray-industry operators"&gt;&lt;figcaption&gt;
&lt;p&gt;A February 2025 post on Phhua, a Chinese-language forum in the Philippines: Kaspersky named Wukong Waimai among apps carrying SparkCat, which scans users&amp;rsquo; photo albums and can steal crypto and banking credentials.&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Plenty of Wukong Waimai users in Thailand said they had suffered unexplained thefts before, and only understood where the problem was after reading the coverage. The app even launched a WeChat mini-program.&lt;/p&gt;
&lt;p&gt;The tweet puts it bluntly: &lt;strong&gt;this is crooks preying on crooks.&lt;/strong&gt; People in these circles hold the most USDT, are the least likely to go to the police when robbed, and are the most eager to install whatever app “the circle” recommends — which makes them the fattest prey. Kaspersky has called it out two years in a row, people keep installing, and that is exactly the meal these thieves live off.&lt;/p&gt;
&lt;h2 id="2-how-sparkcat-steals--no-link-clicking-required-at-any-point" &gt;
&lt;div&gt;
&lt;a href="#2-how-sparkcat-steals--no-link-clicking-required-at-any-point"&gt;
#
&lt;/a&gt;
2. How SparkCat steals — no link-clicking required at any point
&lt;/div&gt;
&lt;/h2&gt;
&lt;p&gt;One piece of background first: &lt;strong&gt;your seed phrase is the master key to your wallet&lt;/strong&gt; — the dozen-or-two English words you were told to write down when you created it. Whoever holds it can empty your wallet completely, without touching your phone, without your password, without any confirmation from you. Many people, for convenience, keep a screenshot of their seed phrase in their photo album. That screenshot is exactly what the thief is hunting for.&lt;/p&gt;
&lt;p&gt;SparkCat&amp;rsquo;s method, in plain language, is five steps:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;You install an app that looks perfectly harmless — food delivery, chat, escrow deals.&lt;/li&gt;
&lt;li&gt;It asks for &lt;strong&gt;photo album access&lt;/strong&gt; with a legitimate-sounding excuse: sending pictures, uploading screenshots, submitting receipts. You tap “Allow” without a second thought.&lt;/li&gt;
&lt;li&gt;In the background it runs OCR (the technology that “reads text out of images”) over your album, picture by picture, looking specifically for seed phrases, private keys, and bank card details.&lt;/li&gt;
&lt;li&gt;Whatever it recognizes gets quietly uploaded to its server. At this point your wallet already belongs to someone else — you just don&amp;rsquo;t know it yet.&lt;/li&gt;
&lt;li&gt;The thief is in no hurry. One day they “harvest” in bulk, and a whole batch of wallets gets drained within seconds of each other.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Note: from start to finish, &lt;strong&gt;you never clicked a single link&lt;/strong&gt;. You clicked nothing, and the money is gone anyway — because you installed the thief onto your phone yourself, and handed it your photo album with your own hands.&lt;/p&gt;
&lt;h2 id="3-now-the-ios-vulnerability-post-itself-a-textbook-deflection-template" &gt;
&lt;div&gt;
&lt;a href="#3-now-the-ios-vulnerability-post-itself-a-textbook-deflection-template"&gt;
#
&lt;/a&gt;
3. Now the “iOS vulnerability” post itself: a textbook deflection template
&lt;/div&gt;
&lt;/h2&gt;
&lt;figure&gt;&lt;img src="https://blog.nosafew.com/images/posts/safew-blame-the-link/shill-post-ios.png"
alt="The “iOS vulnerability incident” post circulating in group chats"&gt;&lt;figcaption&gt;
&lt;p&gt;The “iOS vulnerability” post flooding group chats: it warns you off every website and every URL — and never names a single app.&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Back to the post from the opening. It tells a story: two phones (one on iOS 18, one on 26.4), holding two different wallets, drained simultaneously within ten seconds; its “deep analysis” then concludes that phone A had its keys silently stolen while browsing a website — therefore, everyone, “do not click on any website.”&lt;/p&gt;
&lt;p&gt;Not one part of it survives scrutiny:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. “Browsing a webpage can silently steal your keys”?&lt;/strong&gt; A vulnerability of that class is a top-tier weapon on the black market, worth tens of millions of dollars. Anyone actually holding it would go after exchanges and institutions, not spend their days picking off retail players in payment circles. And if it were real, Apple would ship an emergency patch overnight, security firms worldwide would be sounding alarms, and it would be all over the news. Yet this post can produce no CVE number and no report from any security vendor — its entire body of “evidence” is the very screenshot being forwarded from group to group.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2. “Versions 13–17 were cracked, and now 18–26 are cracked too”?&lt;/strong&gt; Translated: every iOS version ever made is compromised and nobody can defend themselves. That isn&amp;rsquo;t analysis, it&amp;rsquo;s intimidation — scare you into feeling it&amp;rsquo;s hopeless, and you&amp;rsquo;ll stop investigating. It even trips over itself: it says version 26 is cracked, then tells you to “upgrade to the latest system without a moment&amp;rsquo;s delay.” If everything is cracked, what exactly are you upgrading to escape?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. The post&amp;rsquo;s own story contradicts its “link” theory.&lt;/strong&gt; If phone A was infected by clicking a link, how did phone B — a different phone, a different wallet — get drained in the same ten seconds? The only thing the two phones share is their owner: the same batch of “insider apps” installed, the same habit of keeping seed-phrase screenshots in the album. Two wallets emptied ten seconds apart means &lt;strong&gt;the keys to both were already in the thief&amp;rsquo;s hands&lt;/strong&gt; — that day was simply cash-out day. This is not the scene of a fresh link infection; it is the scene of a batch harvest. And that is precisely SparkCat&amp;rsquo;s rhythm: scan albums, collect keys, accumulate a batch, then pick a day and strike all at once.&lt;/p&gt;
&lt;p&gt;There&amp;rsquo;s even a line in the post that gives the game away without meaning to: “different wallets doesn&amp;rsquo;t mean you&amp;rsquo;re safe.” Correct — but not because some Apple vulnerability has magical reach. It&amp;rsquo;s because &lt;strong&gt;both wallets&amp;rsquo; seed phrases sat in the same phone&amp;rsquo;s photo album and were scanned out together by the same app.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;4. Six pieces of “security advice,” five of them pointing outward.&lt;/strong&gt; Links, URLs, system versions, Apple IDs, IDs bought online — all of it aims your vigilance at the world outside your phone. The one item that comes close — “some small apps run their business at a loss, but they steal your USDT” — points in the right direction, yet refuses to name a single name. Why not? &lt;strong&gt;Because naming names would mean naming themselves.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;5. Why is “blame the link” the perfect scapegoat?&lt;/strong&gt; Because you open dozens, sometimes hundreds of webpages a day. “Did I click something I shouldn&amp;rsquo;t have?” is a question you can never finish checking and never rule out. So the panic gets somewhere to go: you spend your days paranoid about links and websites, while the actual thief on your phone never spends a single day under suspicion. An explanation that can never be verified explains nothing — but it muddies the water perfectly.&lt;/p&gt;
&lt;p&gt;So our call is direct: &lt;strong&gt;posts like this are shill posts.&lt;/strong&gt; Every time someone gets drained, the group chats instantly fill with “it was the links” and “it was Apple.” Once or twice is coincidence; every single time is a script. Even if some individual forwarding it means well, the net effect of this talking-point is exactly one thing: you end up suspecting the entire world — except SafeW and SafeX.&lt;/p&gt;
&lt;p&gt;To be complete: unfamiliar links do carry real risk — phishing sites that trick you into typing in your seed phrase are an everyday thing, and you should stay careful. But in this string of thefts that Kaspersky actually documented, the channel of attack was the apps themselves. Lock down links all you want; with these apps on your phone, you get robbed anyway.&lt;/p&gt;
&lt;h2 id="4-next-time-one-of-these-posts-crosses-your-feed-run-it-through-three-questions" &gt;
&lt;div&gt;
&lt;a href="#4-next-time-one-of-these-posts-crosses-your-feed-run-it-through-three-questions"&gt;
#
&lt;/a&gt;
4. Next time one of these posts crosses your feed, run it through three questions
&lt;/div&gt;
&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Does it name any specific app?&lt;/strong&gt; If it rails against “links,” “vulnerabilities,” and “small apps” but won&amp;rsquo;t produce a single name, it&amp;rsquo;s probably steering the narrative.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Does its “vulnerability” have a CVE number, or a report from any security firm?&lt;/strong&gt; Real vulnerabilities come with identifiers and vendor advisories. A “vulnerability” you can&amp;rsquo;t find anywhere is a prop for scaring people.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Does it ever tell you to check what you&amp;rsquo;ve installed and what permissions you&amp;rsquo;ve granted?&lt;/strong&gt; Anyone who actually knows security asks, as their very first question, “what&amp;rsquo;s installed on your phone?”&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Fails all three? Treat it as a shill post: don&amp;rsquo;t believe it, don&amp;rsquo;t forward it, don&amp;rsquo;t follow it.&lt;/p&gt;
&lt;h2 id="5-already-installed-these-apps--or-already-been-robbed-do-these-four-things-now" &gt;
&lt;div&gt;
&lt;a href="#5-already-installed-these-apps--or-already-been-robbed-do-these-four-things-now"&gt;
#
&lt;/a&gt;
5. Already installed these apps — or already been robbed? Do these four things now
&lt;/div&gt;
&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Secure the money first.&lt;/strong&gt; On a clean device, create a brand-new wallet (brand-new seed phrase) and move everything over. Treat every old wallet as compromised; never put funds back into it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Clean the album.&lt;/strong&gt; Delete every screenshot of seed phrases, private keys, and passwords. From now on, seed phrases go on paper only — no photos, no screenshots, no cloud drives.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Clean the apps.&lt;/strong&gt; Check the phone for SafeW, SafeX, Kuaizi Life, Wukong Waimai, Baituo Baituo, and anything else installed because “the group” or “the escrow market” recommended it — revoke their photo and other permissions first, then uninstall.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Move to a hardware wallet (recommended).&lt;/strong&gt; The one thing that shill post gets right is “use a hardware wallet.” But only after the first three steps — otherwise you screenshot the new wallet&amp;rsquo;s seed phrase, and you&amp;rsquo;re right back where you started.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Stop staying up all night replaying “which link did I click.” Do these four things first.&lt;/p&gt;
&lt;h2 id="one-last-line" &gt;
&lt;div&gt;
&lt;a href="#one-last-line"&gt;
#
&lt;/a&gt;
One last line
&lt;/div&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;The links are taking the blame; the apps are taking your money.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Next time you see a panic post shouting “never click on any website,” look down at your phone and check what&amp;rsquo;s installed on it first. Full evidence, timeline, and recovery guide: &lt;a href="https://nosafew.com/"&gt;nosafew.com&lt;/a&gt;.&lt;/p&gt;</content:encoded><category>SafeW</category><category>SafeX</category><category>SparkCat</category><category>crypto theft</category><category>Xinbi Guarantee</category><category>shill posts</category><category>scam</category><category>Debunked</category><guid isPermaLink="true">https://blog.nosafew.com/en/posts/safew-blame-the-link/</guid></item></channel></rss>