Skip to content

Coins

Cryptocurrency App Secretly Steals Assets — Delete Immediately

Key Highlights Blockchain security firm SlowMist, in collaboration with the OKX security team, discovered malicious code in FomoPeek versions 1.1 and 1.2 designed to steal private keys, seed phrases, and...

Key Highlights

  • Blockchain security firm SlowMist, in collaboration with the OKX security team, discovered malicious code in FomoPeek versions 1.1 and 1.2 designed to steal private keys, seed phrases, and Keychain data from iOS devices.
  • The malware includes an exploit framework targeting iOS kernel vulnerabilities across versions 12.0 through 18.7 and 26.0–26.1, capable of bypassing sandbox protections and automatically selecting from eight attack methods based on device model.
  • SlowMist urges all affected users to immediately migrate assets to a new wallet generated on a clean device, update iOS to the latest version, and permanently cease using FomoPeek.

SlowMist Uncovers Supply-Chain Attack in FomoPeek iOS App

Blockchain security company SlowMist has issued a critical alert revealing that versions 1.1 and 1.2 of the FomoPeek application contain malicious code engineered to exfiltrate users’ private keys, seed phrases, login credentials, and other sensitive data stored in the iOS Keychain. The discovery followed reports from multiple FomoPeek users who experienced unexplained asset theft, prompting a joint forensic investigation by SlowMist and the OKX security team.

Exploit Framework Targets Broad iOS Version Range

According to SlowMist’s technical analysis, the compromised application bundles an exploit framework wholly unrelated to FomoPeek’s stated functionality. This framework specifically targets kernel vulnerabilities in Apple’s iOS operating system, supporting eight distinct attack vectors. The malware automatically fingerprints the victim’s device model and iOS version to select the appropriate exploit, enabling it to bypass the iOS sandbox and decrypt Keychain contents.

The affected iOS versions span a remarkably wide range: iOS 12.0 through 18.7, as well as the newly released iOS 26.0 and 26.1. This coverage suggests the attackers maintained and updated their exploit chain over an extended period, potentially impacting millions of devices that have not applied the very latest security patches.

Active Command-and-Control Infrastructure

SlowMist researchers further determined that FomoPeek communicates with hidden command-and-control (C2) servers not associated with any legitimate public service. Analysis of intercepted unencrypted network traffic indicates the attack functions remain active and execute automatically at regular intervals, meaning the threat is ongoing and not merely a dormant payload.

Why This Matters

This incident represents a sophisticated supply-chain compromise targeting cryptocurrency users through a seemingly legitimate application. The breadth of iOS versions exploited underscores the persistent value of kernel-level vulnerabilities to threat actors and the difficulty of defending against zero-day or n-day exploits once they are weaponized in widely distributed software. For the crypto ecosystem, the case highlights the critical importance of verifying application integrity, using hardware wallets for significant holdings, and maintaining rigorous device hygiene. The collaboration between SlowMist and OKX also demonstrates the growing role of exchange security teams in threat intelligence sharing and incident response.

Frequently Asked Questions

Which FomoPeek versions are confirmed compromised?

Only versions 1.1 and 1.2 have been identified as containing the malicious exploit framework and data-exfiltration code.

What should I do if I installed FomoPeek 1.1 or 1.2?

Immediately check your wallet for unauthorized transactions. Using a trusted device on which FomoPeek was never installed, generate a new private key and mnemonic phrase, then transfer all assets to the new wallet. Update your iPhone or iPad to the latest iOS version, delete FomoPeek, and do not reinstall it.

Does updating iOS alone fix the problem?

Updating iOS patches the kernel vulnerabilities used by the exploit, preventing future Keychain decryption. However, if your private keys or seed phrases were already stolen, the attacker retains control of the associated wallets. You must rotate credentials on a clean device as described above.

Evan Mercer

Penulis

Evan Mercer covers coins, digital assets and the market stories shaping everyday conversations about money. His work focuses on accessible explanations, useful context and the signals behind sudden moves.