LOOK CRYPTO · DATA PIPELINE

Data collection status

Checking collection status…

← All news
CRYPTO NEWS

Malicious iOS App FomoPeek Linked to $580K Crypto Theft, According to SlowMist

Cointelegraph · Ezra Reguerra

Blockchain security firm SlowMist uncovered that the malicious iOS app FomoPeek, distributed via Apple’s App Store, is linked to cryptocurrency theft totaling nearly $580,000. The malware contained multiple kernel exploits capable of escaping Apple’s sandbox restrictions and accessing sensitive wallet data of users.

Discovery and Malicious App Capabilities

An investigation by blockchain security company SlowMist revealed that the malicious iOS app FomoPeek contained two exploit modules that leveraged iOS vulnerabilities. These modules enabled elevated privileges, allowing the app to escape Apple’s sandbox and access Keychain data and files from other apps that stored valuable crypto-related information.

The malicious versions were released on September 9 and 12, while version 1.3, launched on September 17, removed the malware components.

Incident Investigation and Attack Methods

SlowMist’s probe, carried out in collaboration with OKX security team, began after users reported theft of assets and traced the issue back to affected FomoPeek versions installed on their devices.

The exploit framework consisted of eight attack methods and claimed compatibility with iOS versions from 12.0 to 18.7.2 as well as from 26.0 to 26.1.

Theft Analysis and Fund Movement

On-chain analysis by SlowMist identified a primary hacker wallet that received approximately 579,984 USDT related to this incident.

This address became active on September 15; stolen funds passed through multiple blockchain networks before consolidation and dispersal across various addresses and services.

Some of the funds moved to services including FixedFloat, KuCoin, and cce.cash, while other portions were sent to additional wallets that SlowMist continues to monitor.

Comments and Responses

Cointelegraph reached out to Apple, SlowMist, and OKX for comments but did not get a response prior to publication.

Why it matters

This news highlights the significant security risks posed by malicious apps distributed through official stores like the Apple App Store, indicating that even major technology platforms can sometimes fail to promptly detect complex kernel-level exploits. The theft of nearly $580,000 in cryptocurrency illustrates the substantial financial impact on affected users. Given the nature of the exploits and scale of the theft, the incident underscores the critical need for rigorous app security analysis and collaborative efforts among researchers and platforms to safeguard users’ digital assets.

Prepared from the source material with AI-assisted editing and checked against the supplied facts.

Open original source ↗