FomoPeek iPhone App Linked to Nearly $580,000 in Stolen USDT
Malicious app on the App Store linked to $580,000 in losses
A version of the FomoPeek app distributed through Apple's App Store has been linked to nearly $580,000 in stolen USDT, a stablecoin. The app was marketed as a tool for tracking large cryptocurrency transactions, but contained hidden malware that compromised users' devices.
Key numbers
- Approximately 579,900 USDT was stolen through the exploit.
- Versions 1.1 (Sept. 9) and 1.2 (Sept. 12) contained the malicious modules.
- The harmful components were removed in version 1.3, released Sept. 17.
What FomoPeek was
FomoPeek was presented as a read-only tool that allowed users to track large crypto transactions across Ethereum, Solana, and Tron. Some victims had previously installed versions 1.1 or 1.2 of the app. Blockchain security firm SlowMist began investigating the app after receiving reports of stolen assets tied to exposed private keys.
How the exploit bypassed iPhone security
Working with researchers at OKX, SlowMist found two hidden modules embedded in versions 1.1 and 1.2 that had no connection to the app's advertised monitoring functions. One module communicated with external command-and-control servers, while the other contained a kernel exploitation framework with eight attack methods that could adjust to the victim's iPhone model and operating-system version.
A successful exploit could escape Apple's application sandbox and access Keychain information and files belonging to other apps on the device. That created a route to locally stored private keys, seed phrases, and login credentials without requiring users to connect a wallet or enter those details into FomoPeek. Researchers also found that the framework could receive remote instructions, including settings that governed whether exploitation was enabled and how often it would run.
SlowMist founder Yu Xian said the risk extended to passwords stored in Apple's Keychain and encrypted files held by other applications. He explained that after a successful attack, the app could break through the iOS sandbox, read and decrypt the system keychain, and access data files from other apps on the device.
Nearly $580,000 traced on-chain
Blockchain analysis firm Salus identified the attacker address 0x6d37f2C5e8F8546b648D317295565dA95975f4BB and estimated the proceeds at about 579,900 USDT.
- 401,028 USDT was traced through three intermediary addresses to FixedFloat.
- 20,000 USDT moved through deposit addresses before being consolidated into a KuCoin hot wallet.
- 111,458 USDT was routed through an address Salus associated with an escrow platform.
- Another 10,000 USDT passed through the CCE mixing service before reaching addresses linked to an escrow service.
Salus also indicated that the group behind the FomoPeek incident had been involved in a separate private-key theft in June. Investigators are still determining whether the same technique was used in that attack.
Crypto platforms warn users
Several crypto platforms, including Binance, OKX, Gate, Bitget Wallet, and Rabby, have issued warnings to users. Binance stated that the third-party app contains malicious code that can exploit iOS system vulnerabilities to gain the highest level of device privileges, potentially accessing sensitive data stored on the device, including private keys, seed phrases, and login credentials.
The firms broadly urged users to remove FomoPeek, update iOS, and move assets to newly created wallets on devices where the compromised app was never installed. These fresh credentials are necessary because deleting the app or patching the operating system cannot invalidate a private key that may already have been copied.
Why this matters for crypto security
The incident highlights a vulnerability in the model of using a dedicated iPhone for crypto storage. On-chain investigator ZachXBT had argued two months earlier that a separate iPhone dedicated to crypto could be preferable to existing hardware wallets. His recommendation relied on keeping the device isolated from everyday browsing and messaging. FomoPeek exposes a different weakness in that model. The app was built for crypto users and distributed through Apple's official marketplace, yet contained tooling capable of breaching the barriers separating applications on the device. This does not establish that dedicated crypto iPhones are inherently less secure than hardware wallets, but it shows that isolation offers limited protection if software installed on the device can compromise the operating system itself.
What happens next
Salus continues to follow addresses linked to the remaining proceeds. Binance and other platforms are monitoring for deposits that could give investigators another opportunity to track or restrict the movement of the stolen USDT.