# FomoPeek iOS malware cryptocurrency theft

> Live situation record from CLSTR: https://clstr.news/situations/fomopeek-ios-malware-cryptocurrency-theft
> Updated: 2026-09-21T20:47:23.000Z. Sources: 11. Developments: 2.

Security firms, including Binance, SlowMist, and OKX, identified a malicious iOS application named ‘FomoPeek’ that was distributed through the Apple App Store. Marketed as a tool for tracking cryptocurrency whale wallets, versions 1.1 and 1.2 of the app contained hidden modules designed to exploit the iOS kernel and bypass the operating system’s application sandbox.

This exploit allowed the malware to access protected areas of a device, such as the iOS Keychain, to steal private keys, seed phrases, login credentials, and personal files. The framework was capable of targeting a wide range of software, from iOS 12.0 up to version 26.5.

Following the discovery, SlowMist linked the malware to the theft of approximately 580,000 USDT. Experts have advised affected users to remove the application, update their operating systems, and move funds to new wallets created on clean devices, as simply deleting the app may not protect assets if credentials have already been compromised.

## Claims

- SlowMist identified malicious code in FomoPeek versions 1.1 and 1.2. (corroborated by 7 sources)
- The malware's exploit framework targeted iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1. (corroborated by 5 sources)
- The malware was capable of bypassing the iOS sandbox to access Keychain data and other app files. (corroborated by 5 sources)
- FomoPeek was marketed as a tool for tracking cryptocurrency whale wallets on Ethereum, Solana, and Tron. (corroborated by 4 sources)
- Malicious components were removed in FomoPeek version 1.3, released on September 17. (corroborated by 4 sources)
- The FomoPeek app is linked to the theft of approximately 580,000 USDT. (corroborated by 3 sources)
- Deleting the FomoPeek app does not protect users if their private keys or recovery phrases have already been stolen. (single source)
- Attackers may have adapted the DarkSword exploit chain to target devices running iOS 26.5. (single source)

## Timeline

### 2026-09-21: FomoPeek malware on iOS linked to $580,000 crypto theft

Malicious iOS app FomoPeek, distributed via the App Store, bypassed Apple’s sandbox to steal approximately $580,000 in USDT by exposing crypto private keys and seed phrases.

9 sources. https://clstr.news/cluster/darksword-exploit-targets-iphone-users-to-compromise-crypto-wallets

### 2026-09-19: FomoPeek malware targets iOS users to steal crypto keys

Binance and SlowMist warn that FomoPeek app versions 1.1–1.2 contain malware capable of exploiting iOS to steal crypto private keys, seed phrases, and sensitive personal data.

3 sources. https://clstr.news/cluster/fomopeek-malware-targets-ios-users-to-steal-crypto-keys

---
Cite as: FomoPeek iOS malware cryptocurrency theft. CLSTR, https://clstr.news/situations/fomopeek-ios-malware-cryptocurrency-theft
