Binance Warns iPhone Users of FomoPeek Malware
- Binance warned iPhone and iPad users to check if they installed FomoPeek after malicious code in versions 1.1 and 1.2 could expose crypto wallet credentials.
- Security researchers SlowMist and OKX found frameworks inside the app capable of exploiting iOS vulnerabilities, escaping sandbox restrictions and decrypting Keychain information.
- Binance advised affected self-custody users to create a new wallet on a separate trusted device and transfer their assets to new addresses.
Binance has warned iPhone and iPad users to check whether they installed FomoPeek after security researchers found malicious code in versions 1.1 and 1.2 that could expose crypto wallet credentials and other sensitive device data.
The warning follows an investigation by SlowMist and OKX security teams into reports of stolen crypto. Researchers linked affected users to the app and found code capable of exploiting iOS vulnerabilities, escaping normal app restrictions and accessing data stored by other applications.
FomoPeek Exploit Could Expose Private Keys and Seed Phrases
FomoPeek was marketed as a tool for tracking large crypto wallets across networks including Solana, Ethereum and TRON.
SlowMist found two suspicious frameworks inside versions 1.1 and 1.2 that were unrelated to the app’s advertised functions. One contained an iOS kernel exploit framework with eight attack methods that could select an exploit based on the device model and operating system version.
The framework declared support for targets running iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1. A successful attack could escape the iOS sandbox, decrypt Keychain information and access files belonging to other apps.
That could expose private keys, recovery seed phrases, login credentials, chat histories and locally stored files. The malicious code could also communicate with remote infrastructure and receive instructions from its operators.
Versions 1.1 and 1.2 Reached Apple’s App Store
SlowMist’s review of historical releases found that FomoPeek version 1.0 did not contain the two malicious frameworks.
Version 1.1, build 105, introduced them on Sept. 9. Version 1.2, build 110, retained the code after its Sept. 12 release. Both affected versions were distributed through Apple’s official App Store rather than only through third-party installation channels.
Version 1.3, build 111, removed both frameworks on Sept. 17. Removing the affected app does not make wallet credentials that may already have been exposed safe.
Binance Tells Affected Users to Move Assets to New Wallets
Binance advised users who installed FomoPeek to delete the app, avoid reinstalling it and update iOS to the latest available version.
Self-custody users should create a new wallet on a separate trusted device that never had FomoPeek installed and transfer their assets to new addresses. Users who notice unauthorized transactions should preserve the affected device and relevant evidence.
The warning concerns malware running on the device itself rather than a compromise of Binance Wallet or another specific crypto wallet application.