started · updated
FomoPeek malware on iOS linked to $580,000 crypto theft
Blockchain security firm SlowMist has identified a malicious iOS application named FomoPeek, which was distributed through the Apple App Store. Marketed as a tool for tracking cryptocurrency whale wallets on Ethereum, Solana, and Tron, versions 1.1 and 1.2 of the app contained hidden modules designed to exploit the iOS kernel.
These malicious components allowed the app to bypass Apple’s sandbox security mechanism, granting attackers access to sensitive data stored in the iOS Keychain. This exposure included private keys, seed phrases, and login credentials. SlowMist has linked the malware to the theft of approximately 580,000 USDT.
The exploit framework was reported to target a wide range of operating systems, specifically iOS versions 12.0 through 18.7.2 and 26.0 through 26.1. Additionally, researchers warned that the DarkSword exploit chain may have been adapted to target devices running iOS 26.5, though this has not been independently confirmed by Apple or Google.
Security experts emphasize that simply deleting the FomoPeek app is insufficient if private keys or recovery phrases have already been compromised. Affected users are advised to move their funds to new wallets created on clean devices.
Entities
Apple · Darksword · FomoPeek · Google · Google Threat Intelligence Group · OKX · SlowMist
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] The FomoPeek app is linked to the theft of approximately 580,000 USDT. www.criptotendencias.com · www.cryptobreaking.com · cryptoslate.com
- [● 5 SOURCES] The malware was capable of bypassing the iOS sandbox to access Keychain data and other app files. www.criptotendencias.com · www.cryptobreaking.com · www.ad-hoc-news.de · themarketperiodical.com · cryptoslate.com
- [● 4 SOURCES] FomoPeek was marketed as a tool for tracking cryptocurrency whale wallets on Ethereum, Solana, and Tron. www.tronweekly.com · themarketperiodical.com · coinedition.com · cryptoslate.com
- [● 7 SOURCES] SlowMist identified malicious code in FomoPeek versions 1.1 and 1.2. www.tronweekly.com · www.criptotendencias.com · www.cryptobreaking.com · themarketperiodical.com · www.ad-hoc-news.de · +2 more
- [○ 1 SOURCE] Deleting the FomoPeek app does not protect users if their private keys or recovery phrases have already been stolen. coinedition.com
- [○ 1 SOURCE] Attackers may have adapted the DarkSword exploit chain to target devices running iOS 26.5. crypto.news
- [● 5 SOURCES] The malware's exploit framework targeted iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1. www.tronweekly.com · www.cryptobreaking.com · www.ad-hoc-news.de · themarketperiodical.com · coinedition.com
- [● 4 SOURCES] Malicious components were removed in FomoPeek version 1.3, released on September 17. www.tronweekly.com · www.cryptobreaking.com · themarketperiodical.com · coinedition.com