Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 11 sources · 3 days · First seen · Last updated
FomoPeek iOS malware cryptocurrency theft
Overview
Security firms, including Binance, SlowMist, and OKX, identified a malicious iOS application named ‘FomoPeek’ that was distributed through the Apple App Store. Marketed as a tool for tracking cryptocurrency whale wallets, versions 1.1 and 1.2 of the app contained hidden modules designed to exploit the iOS kernel and bypass the operating system’s application sandbox.
This exploit allowed the malware to access protected areas of a device, such as the iOS Keychain, to steal private keys, seed phrases, login credentials, and personal files. The framework was capable of targeting a wide range of software, from iOS 12.0 up to version 26.5.
Following the discovery, SlowMist linked the malware to the theft of approximately 580,000 USDT. Experts have advised affected users to remove the application, update their operating systems, and move funds to new wallets created on clean devices, as simply deleting the app may not protect assets if credentials have already been compromised.
Entities
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 7 SOURCES] SlowMist identified malicious code in FomoPeek versions 1.1 and 1.2. www.tronweekly.com · www.criptotendencias.com · www.cryptobreaking.com · themarketperiodical.com · www.ad-hoc-news.de · +2 more
- [● 5 SOURCES] The malware's exploit framework targeted iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1. www.tronweekly.com · www.cryptobreaking.com · www.ad-hoc-news.de · themarketperiodical.com · coinedition.com
- [● 5 SOURCES] The malware was capable of bypassing the iOS sandbox to access Keychain data and other app files. www.criptotendencias.com · www.cryptobreaking.com · www.ad-hoc-news.de · themarketperiodical.com · cryptoslate.com
- [● 4 SOURCES] FomoPeek was marketed as a tool for tracking cryptocurrency whale wallets on Ethereum, Solana, and Tron. www.tronweekly.com · themarketperiodical.com · coinedition.com · cryptoslate.com
- [● 4 SOURCES] Malicious components were removed in FomoPeek version 1.3, released on September 17. www.tronweekly.com · www.cryptobreaking.com · themarketperiodical.com · coinedition.com
- [● 3 SOURCES] The FomoPeek app is linked to the theft of approximately 580,000 USDT. www.criptotendencias.com · www.cryptobreaking.com · cryptoslate.com
- [○ 1 SOURCE] Deleting the FomoPeek app does not protect users if their private keys or recovery phrases have already been stolen. coinedition.com
- [○ 1 SOURCE] Attackers may have adapted the DarkSword exploit chain to target devices running iOS 26.5. crypto.news
Timeline
-
[TECHNOLOGY] 9 sourcesFomoPeek malware on iOS linked to $580,000 crypto theft
Malicious iOS app FomoPeek, distributed via the App Store, bypassed Apple’s sandbox to steal approximately $580,000 in USDT by exposing crypto private keys and seed phrases.
-
[TECHNOLOGY] 3 sourcesFomoPeek malware targets iOS users to steal crypto keys
Binance and SlowMist warn that FomoPeek app versions 1.1–1.2 contain malware capable of exploiting iOS to steal crypto private keys, seed phrases, and sensitive personal data.
Sources
ad-hoc-news.de · coinedition.com · criptotendencias.com · crypto.news · cryptobreaking.com · cryptoslate.com · en.bitcoinsistemi.com · livebitcoinnews.com · news.bitcoin.com · themarketperiodical.com · tronweekly.com