SlowMist: Malicious iOS App FomoPeek Linked to $580K Crypto Theft

Sep 23, 2026 16:29 Written by Newisty Editorial Team security ios hack slowmist wallet
SlowMist: Malicious iOS App FomoPeek Linked to $580K Crypto Theft

Malicious iOS App Steals Crypto via Kernel Exploits

A malicious iOS app called FomoPeek has been linked to approximately $580,000 in stolen cryptocurrency. Blockchain security firm SlowMist reported that versions of the app distributed through Apple’s App Store contained hidden code designed to steal sensitive data from users.

The app used security flaws in Apple’s iOS system to escape its normal restrictions. This allowed it to access the "Keychain," a secure storage area on iPhones that holds sensitive information like passwords and wallet data. The attack did not require users to visit a malicious website or open a specific webpage; the harmful code activated as soon as the app was launched.

Key Findings from the Investigation

  • Theft Amount: A primary hacker address received about 579,984 USDT (a type of stablecoin pegged to the US dollar). This is valued at nearly $580,000.
  • Timeline: The malicious versions of FomoPeek were released on September 9 and September 12. A cleaned-up version 1.3 was released on September 17, which removed the harmful components.
  • Targeted Apps: SlowMist identified 19 specific wallet and note apps as targets, including MetaMask, Trust Wallet, SafePal, OKX Wallet, and Apple Notes.
  • Technical Reach: The exploit framework supported iOS versions from 12.0 up to 18.7.2, as well as versions 26.0 to 26.1.
  • Fund Movement: The stolen funds were moved across multiple blockchains and sent to services like FixedFloat, KuCoin, and cce.cash.

How the Attack Worked

SlowMist, conducting its investigation with the OKX security team, found that the app included two malicious modules. These modules exploited iOS vulnerabilities to gain elevated privileges. Once inside the system, they could read data from other apps.

SlowMist confirmed in a controlled test that the framework could collect data from the Apple Notes container. However, the firm clarified that this testing did not prove that private keys or seed phrases were extracted from every named wallet. A remote server was used to control the exploitation and collect the data.

Advice for Users

SlowMist strongly advises anyone who installed FomoPeek versions 1.1 or 1.2 to treat their wallet credentials as compromised. Because the attacker may have already copied sensitive data off the device, simple steps like uninstalling the app or enabling Lockdown Mode will not recover the stolen information.

The security firm recommends that affected users create a new wallet on a different, clean device and move their remaining assets to it immediately.

Official Responses

Cointelegraph contacted Apple and OKX for comment regarding the incident but did not receive a response before publication.

Why This Matters

This incident highlights a significant risk in the mobile app ecosystem. Even apps available on official stores like the Apple App Store can contain hidden malware. For crypto users, this means that installing an unverified or suspicious app can lead to direct access to their digital wallets, bypassing traditional security measures.

What Happens Next

SlowMist researchers are continuing to trace the stolen funds as they move through various addresses and services.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!