SlowMist: Malicious iOS App FomoPeek Linked to $580K Crypto Theft
Malicious iOS App Steals Crypto via Kernel Exploits
A malicious iOS app called FomoPeek has been linked to approximately $580,000 in stolen cryptocurrency. Blockchain security firm SlowMist reported that versions of the app distributed through Apple’s App Store contained hidden code designed to steal sensitive data from users.
The app used security flaws in Apple’s iOS system to escape its normal restrictions. This allowed it to access the "Keychain," a secure storage area on iPhones that holds sensitive information like passwords and wallet data. The attack did not require users to visit a malicious website or open a specific webpage; the harmful code activated as soon as the app was launched.
Key Findings from the Investigation
- Theft Amount: A primary hacker address received about 579,984 USDT (a type of stablecoin pegged to the US dollar). This is valued at nearly $580,000.
- Timeline: The malicious versions of FomoPeek were released on September 9 and September 12. A cleaned-up version 1.3 was released on September 17, which removed the harmful components.
- Targeted Apps: SlowMist identified 19 specific wallet and note apps as targets, including MetaMask, Trust Wallet, SafePal, OKX Wallet, and Apple Notes.
- Technical Reach: The exploit framework supported iOS versions from 12.0 up to 18.7.2, as well as versions 26.0 to 26.1.
- Fund Movement: The stolen funds were moved across multiple blockchains and sent to services like FixedFloat, KuCoin, and cce.cash.
How the Attack Worked
SlowMist, conducting its investigation with the OKX security team, found that the app included two malicious modules. These modules exploited iOS vulnerabilities to gain elevated privileges. Once inside the system, they could read data from other apps.
SlowMist confirmed in a controlled test that the framework could collect data from the Apple Notes container. However, the firm clarified that this testing did not prove that private keys or seed phrases were extracted from every named wallet. A remote server was used to control the exploitation and collect the data.
Advice for Users
SlowMist strongly advises anyone who installed FomoPeek versions 1.1 or 1.2 to treat their wallet credentials as compromised. Because the attacker may have already copied sensitive data off the device, simple steps like uninstalling the app or enabling Lockdown Mode will not recover the stolen information.
The security firm recommends that affected users create a new wallet on a different, clean device and move their remaining assets to it immediately.
Official Responses
Cointelegraph contacted Apple and OKX for comment regarding the incident but did not receive a response before publication.
Why This Matters
This incident highlights a significant risk in the mobile app ecosystem. Even apps available on official stores like the Apple App Store can contain hidden malware. For crypto users, this means that installing an unverified or suspicious app can lead to direct access to their digital wallets, bypassing traditional security measures.
What Happens Next
SlowMist researchers are continuing to trace the stolen funds as they move through various addresses and services.