Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Malicious iOS app FomoPeek linked to $580,000 crypto theft
00

Malicious iOS app FomoPeek linked to $580,000 crypto theft

Sep 23, 2026

The malicious iOS app FomoPeek, distributed via Apple's App Store, has been linked to the theft of nearly $580,000 in cryptocurrency. An investigation by SlowMist and OKX revealed that FomoPeek versions 1.1 and 1.2 contained kernel exploits targeting 19 wallet and note apps, including MetaMask and Apple Notes. SlowMist traced 579,984 USDT to a hacker address active on September 15, 2026, and urged affected users to move assets to new wallets.

FomoPeek Release Timeline

  • ▪Blockchain security firm SlowMist reported that malicious versions of the FomoPeek app were released on September 9 and September 12, 2026.
  • ▪Version 1.3 of the FomoPeek app, released on September 17, 2026, removed the malicious components found in FomoPeek versions 1.1 and 1.2

Technical Details of the Exploit Framework

  • ▪The FomoPeek app contained two malicious modules with multiple kernel exploits capable of escaping Apple's sandbox and gaining elevated privileges.
  • ▪The exploit framework within the FomoPeek app included eight attack methods and declared support for iOS versions 12.0 to 18.7.2 and 26.0 to 26.1.
  • ▪The FomoPeek exploit framework loaded upon app launch without requiring users to open a webpage, controlled by a remote server.

Targeted Applications and Data Collection

  • ▪A remote server configuration for the FomoPeek app targeted 19 wallet and note applications, including MetaMask, Trust Wallet, SafePal, OKX Wallet, and Apple Notes.
  • ▪Blockchain security firm SlowMist confirmed in a controlled environment that the FomoPeek exploit framework could collect application data, including the Apple Notes container.

Stolen Cryptocurrency and Fund Movements

  • ▪SlowMist identified a primary hacker address active on September 15, 2026, that received approximately 579,984 USDT (nearly $580,000) from exploits of FomoPeek, distributed through Apple's App Store.
  • ▪Portions of the stolen cryptocurrency from the FomoPeek exploits were transferred to services including FixedFloat, KuCoin, and cce.cash.

Security Recommendations and Warnings

  • ▪SlowMist cautioned that enabling Lockdown Mode or uninstalling FomoPeek after an exploit cannot retrieve sensitive data already copied by an attacker who exploited FomoPeek
  • ▪SlowMist recommended that users who installed FomoPeek versions 1.1 or 1.2 transfer their assets to a new wallet created on an unaffected device.

Debatable claims

  • ▪Apple's App Store vetting process is inadequate to stop sophisticated malware
  • ▪Apple should compensate victims of malicious App Store apps

1 source

Cointelegraph
Malicious iOS App FomoPeek Linked to $580K Crypto Theft
View source article

Story comments

Loading comments…

Related Projects

SlowMistApple

Topics

Crypto securityCrypto privacy & surveillanceCryptocurrency theft