NewsCryptoFomoPeek iOS App Malware Exposed Crypto Keys as Users Report Wallet Drains

FomoPeek iOS App Malware Exposed Crypto Keys as Users Report Wallet Drains

Author: Crypto Adventure·

Key Takeaways

  • SlowMist issued an asset-theft warning on September 19 after jointly investigating stolen-crypto cases with OKX's security team, linking FomoPeek versions 1.1 and 1.2 to the reported losses.
  • Researchers identified two malicious modules in FomoPeek, one containing an iOS kernel exploitation framework with eight attack methods that adapted to different device models and operating-system versions.
  • The exploit could escape the app sandbox, decrypt Keychain data and read other applications' files, potentially exposing private keys, recovery phrases, login credentials and chat records.
  • Captured network traffic showed the malicious functionality connecting to servers outside the app's normal infrastructure and executing automatically at recurring intervals rather than lying dormant.
  • Binance Wallet advised affected users to remove the app, update to the latest iOS version and generate fresh wallet credentials on a clean device, since deleting the app alone cannot secure keys that were already extracted.
FomoPeek iOS App Malware Exposed Crypto Keys as Users Report Wallet Drains

FomoPeek, an iPhone application marketed as a tool for tracking whale wallets across Solana, Ethereum and TRON, contained malicious code capable of circumventing iOS security restrictions and extracting cryptocurrency wallet credentials from affected devices.

Whale-tracking tools appeal to traders who follow large-holder movements on-chain, an audience that routinely stores or accesses crypto wallets directly on their phones — the same credentials the malware was designed to extract.

SlowMist issued an asset-theft warning on September 19 after investigating multiple cases of stolen crypto jointly with OKX's security team. The affected users had installed or used FomoPeek versions 1.1 or 1.2 before their assets were taken.

The disclosure arrived during a that saw several unrelated crypto security incidents. Blink temporarily suspended services after an attacker drained custodial accounts, while Fetch.ai and NuNet were hit by a separate $2 million exploit.

Malware Contained Eight iOS Attack Methods

Researchers identified two malicious modules inside FomoPeek that bore no relation to the app's advertised wallet-tracking functions. One of them housed an iOS kernel exploitation framework with eight attack methods capable of adapting to different device models and operating-system versions.

The affected range identified by researchers spans iOS 12.0 through 18.7 and iOS 26.0 through 26.1.

Once the exploit succeeded, the malicious code could escape the normal application sandbox, access and decrypt Keychain information and read data belonging to other applications. Potentially exposed information included private keys, recovery phrases, login credentials, chat records and other files stored on the device. The finding cuts against the assumption that each iOS app's data stays isolated, since wallet credentials held in the Keychain sit within reach once kernel access is achieved.

SlowMist also detected connections to servers outside FomoPeek's normal infrastructure. Captured network traffic indicated that the malicious functionality was active and configured to execute automatically at recurring intervals rather than lying dormant.

Exposed Wallet Credentials Must Be Replaced

Binance Wallet warned affected users to remove FomoPeek, update their devices to the latest available iOS version and avoid reinstalling the application.

Users who stored or accessed crypto wallets on an affected device were advised to generate fresh wallet credentials on a clean device that had never run FomoPeek, then transfer any remaining funds to the new addresses.

Deleting the application alone cannot secure a private key or recovery phrase that has already been extracted. Anyone holding those credentials can recreate the wallet elsewhere and authorize transactions without ever regaining access to the compromised iPhone.

Users who identify unauthorized transactions were also advised to preserve the affected device and transaction records for investigation rather than immediately wiping the evidence.

SlowMist has not disclosed the aggregate value stolen through FomoPeek or the total number of compromised devices. Its September 19 investigation linked versions 1.1 and 1.2 to reported asset theft and confirmed that both releases contained functionality capable of reaching sensitive data outside the app's normal sandbox. Updated findings from the investigation, if released, would clarify how many users ran the flagged versions and the resulting scale of losses.