FOMO App Found With Crypto-Draining Malware on Apple Store
What happened
Security researchers found that a crypto-draining malware was hiding inside the official FOMO app on Apple's App Store. The malware could steal users' seed phrases and private keys, giving attackers access to their crypto wallets.
The security firm SlowMist discovered the problem and warned iPhone users to update their devices.
Key numbers
- The vulnerable versions of the FOMO app were active between September 9 and September 17.
- SlowMist says users should treat their seed phrases, private keys, and sensitive credentials as compromised.
How the exploit works
SlowMist's Chief Information Security Officer, Shān Zhang, warned that iPhone versions running iOS 13 through iOS 26.5 are vulnerable to malicious Safari links. These links exploit a memory-corruption flaw in WebKit and JavaScriptCore.
Through this flaw, attackers gain read and write access to the JavaScript layer. From there, they can bypass pointer authentication codes, escape the WebContent sandbox, and escalate kernel privileges to gain root access. This allows them to make unauthorized changes and exfiltrate crypto keys and wallet data.
The malware found in the official FOMO app contained modules with similar capabilities to these DarkSword exploits.
What SlowMist says
SlowMist warns that simply updating or deleting the FOMO app may not be enough to protect users. The firm says users should treat their relevant seed phrases, private keys, and sensitive credentials as compromised.
The malware in the FOMO app was reportedly spread thanks to promotion by crypto key opinion leaders on social media.
What is confirmed
SlowMist identified crypto-draining malware in official versions of the FOMO app on the App Store. The vulnerable versions were active between September 9 and September 17. The malware was capable of stealing seed phrases and private keys using methods similar to the DarkSword exploits targeting iOS WebKit and JavaScriptCore.
What is still unclear
The exact number of users affected by the malicious FOMO app has not been disclosed. It is also unclear how many people downloaded the app during the vulnerable period.
Why it matters
This discovery shows that even official apps on major platforms like Apple's App Store can contain hidden malware. Crypto users who downloaded the FOMO app during the affected period may have had their wallet credentials exposed, putting their digital assets at risk.
What happens next
SlowMist has urged iPhone users to update to the latest iOS version to protect against the Safari-based exploit. Users who downloaded the FOMO app during the affected period are advised to treat their wallet credentials as compromised.