FomoPeek iOS Malware Targets Crypto Users, Prompting Warnings From SlowMist and Binance
Key Takeaways
- •SlowMist warned on September 19 that versions 1.1 and 1.2 of the iOS app FomoPeek contained malicious code, with affected users reporting stolen assets and exposed private keys.
- •The app concealed an iOS kernel exploitation framework with eight exploit methods covering iOS versions 12.0–18.7 and 26.0–26.1, allowing it to escape the sandbox and access keychain data and files from other applications.
- •Version 1.3 of FomoPeek, updated on September 17, no longer included the exploitation frameworks, two days ahead of SlowMist's public alert.
- •Binance urged users who installed the app to uninstall it, update iOS, and move self-custody wallet assets to a new wallet on a device that never had FomoPeek installed, while reporting no confirmed impact on its users.
- •Gate.io and OKX, both of which assisted SlowMist's investigation, also issued warnings as the incident underscores the growing use of mobile apps, including fakes on legitimate app stores, to target crypto users.

Blockchain security firm SlowMist has identified malicious software embedded in the iOS app FomoPeek, targeting cryptocurrency users. In an alert posted on X on September 19, the firm warned iPhone users about the malware, noting that several users had reported having assets stolen.
According to SlowMist, its investigation found that the affected users had their private keys exposed. The firm also identified that some of the victims had installed version 1.1 or 1.2 of FomoPeek, an application that presents itself as a read-only tool for monitoring whale wallets across the Ethereum, Solana, and Tron networks.
FomoPeek Malware Capable of Bypassing the iOS Sandbox
SlowMist's analysis showed that the iOS version of the app contained two modules unrelated to its stated business function. One of these modules houses an iOS kernel exploitation framework with eight distinct methods for exploiting the operating system. The framework impacted iOS versions 12.0–18.7 and 26.0–26.1, selecting exploit methods based on the iPhone model and iOS version in use.
Kernel-level exploits are regarded as among the most severe classes of device compromise because the kernel underpins the isolation boundaries that separate one app's data from another's. When exploitation succeeds, the app escapes the iOS sandbox, enabling it to decrypt sensitive keychain data and access files belonging to other apps. As a result, nearly all sensitive information on a compromised device is at of exposure, including login credentials, seed phrases, chat history, and private keys — meaning wallet material stored in separate applications was within reach even though FomoPeek itself was positioned as a monitoring tool rather than a wallet.
The malware can also collect data, connect to hidden servers, and receive remote commands from bad actors. However, the malicious code appears to have since been removed: version 1.3 of the app, updated on September 17, no longer includes the exploitation frameworks. The removal thus predated SlowMist's September 19 public alert by two days.
Binance Urges Users to Move Assets, Uninstall FomoPeek, and Update iOS
Several cryptocurrency exchanges have alerted their users about the incident. Binance asked users of iPhones and iPads running iOS 26.x or earlier who had installed the app to uninstall it and never redownload it. In a post on X, the exchange also advised updating iOS to the latest version, while acknowledging that it had not received any reports of a Binance user being affected.
For users of Binance's self-custody wallet, the exchange recommended moving assets to a new wallet on a device that has never had FomoPeek installed — guidance that reflects the sandbox escape's ability to reach files belonging to other applications on the same device.
Other exchanges, including Gate.io and OKX, both of which assisted SlowMist with its investigation, have also issued warnings to their users.
Mobile Devices Remain a Growing Attack Surface
The incident underscores how threat actors continue to target crypto users through mobile devices. Over the past few years, bad actors have increasingly relied on a variety of methods to exploit smartphones and gain access to crypto wallets. Notably, malicious apps have sometimes surfaced on legitimate distribution channels such as the Play Store and App Store. Several fake crypto applications have appeared on the App Store, including one impersonating the Wasabi wallet that caused a user to lose 6 BTC in August.
For users weighing their own exposure, the concrete checkpoints offered by the advisories are the installed FomoPeek version, the device's iOS version, and further updates from the firms and exchanges involved in the investigation.
This article is for informational purposes only. Users who may have installed affected software should follow guidance from official security providers and wallet platforms.
Source: The Market Periodical