A hand holding a smartphone displaying Apple Inc. (AAPL) stock with buy and sell options, with a stock chart visible on a monitor in the background.
TECHNOLOGY

FomoPeek iOS App Linked to $580K Theft

Image Credit: Shutterstock

A malicious iOS app distributed through Apple’s App Store has been linked to nearly $580,000 in crypto theft after researchers found code capable of escaping Apple’s security sandbox and accessing sensitive wallet data.

SlowMist traced about 579,984 USDT in cumulative receipts to a primary attacker address associated with the incident. The security firm began investigating with OKX after users reported stolen assets and some affected users were found to have installed compromised versions of FomoPeek.

Versions 1.1 and 1.2 Carried Hidden iOS Exploit Modules

FomoPeek was presented as a read-only tool for monitoring large crypto transactions across networks including Ethereum, Solana and TRON.

Researchers found two malicious modules inside versions 1.1 and 1.2 that were unrelated to that function. The modules could communicate with remote infrastructure, attempt kernel exploits, escape the iOS sandbox and access information held by other applications.

SlowMist identified eight exploit methods capable of selecting an attack based on the device model and operating-system version. The framework declared support for iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1.

Successful exploitation could expose Keychain records, wallet files, private keys, seed phrases and information stored in note-taking applications. During isolated testing, SlowMist retrieved a collection list covering 19 wallet and note apps.

SlowMist Traces 579,984 USDT to Primary Attacker Address

SlowMist’s on-chain investigation identified a primary attacker address that became active on Sept. 15 and had received 579,984.34 USDT by the time its report was published.

The funds involved Ethereum, BNB Chain and Arbitrum before being consolidated and transferred through additional addresses and services. SlowMist traced portions toward FixedFloat and KuCoin, while subsequent reporting also identified flows involving cce.cash.

The 579,984 USDT figure represents funds traced to the primary address associated with the incident. It should not be treated as a final loss estimate across every FomoPeek user while the investigation remains ongoing.

Malicious Code Disappeared From September 17 Update 

SlowMist found no malicious modules in FomoPeek version 1.0. Version 1.1 introduced them on Sept. 9, while version 1.2 retained the code after its Sept. 12 release.

Both affected versions were distributed through Apple’s official App Store. Version 1.3, released Sept. 17, no longer contained the two malicious frameworks.

Users who installed versions 1.1 or 1.2 should treat wallet credentials accessible from those devices as potentially compromised. Binance and SlowMist have advised impacted self-custody users to generate new wallet credentials on a separate trusted device and transfer assets to new addresses rather than relying only on deleting the app.

More For You

Explore More News