< Back to all clusters
[TECHNOLOGY] · United States, Hong Kong SAR China · 9 sources

started · updated

FomoPeek malware on iOS linked to $580,000 crypto theft

Blockchain security firm SlowMist has identified a malicious iOS application named FomoPeek, which was distributed through the Apple App Store. Marketed as a tool for tracking cryptocurrency whale wallets on Ethereum, Solana, and Tron, versions 1.1 and 1.2 of the app contained hidden modules designed to exploit the iOS kernel.

These malicious components allowed the app to bypass Apple’s sandbox security mechanism, granting attackers access to sensitive data stored in the iOS Keychain. This exposure included private keys, seed phrases, and login credentials. SlowMist has linked the malware to the theft of approximately 580,000 USDT.

The exploit framework was reported to target a wide range of operating systems, specifically iOS versions 12.0 through 18.7.2 and 26.0 through 26.1. Additionally, researchers warned that the DarkSword exploit chain may have been adapted to target devices running iOS 26.5, though this has not been independently confirmed by Apple or Google.

Security experts emphasize that simply deleting the FomoPeek app is insufficient if private keys or recovery phrases have already been compromised. Affected users are advised to move their funds to new wallets created on clean devices.

Entities

Apple · Darksword · FomoPeek · Google · Google Threat Intelligence Group · OKX · SlowMist

Claims

What the coverage asserts, and how many sources carry each claim.