Binance has warned iPhone and iPad users to check whether they ever installed FomoPeek after security researchers linked versions 1.1 and 1.2 of the app to malicious code capable of exposing private keys, seed phrases and data stored across affected devices.
The warning, issued through Binance Wallet’s official channels on September 19 and republished by crypto.news on Sunday, follows an investigation by blockchain security firm SlowMist, which worked with the OKX security team to dissect the application. Binance advised anyone who installed the affected versions to remove the app, avoid reinstalling it and update iOS to the latest available release.
“Security Advisory | iPhone Users: Check Whether You’ve Ever Installed the FomoPeek App. Binance is aware of a security incident recently disclosed by the community. According to security firms including SlowMist, the third-party app FomoPeek (versions 1.1-1.2) contains malicious code,” Binance Wallet posted on September 19.
The malware targets the device, not one app
What separates FomoPeek from the usual wave of fake wallet clones is scope. The malicious code targets the device itself rather than a specific crypto application, Binance said. A successful attack could therefore expose information held by other apps, including login credentials, chat records and files, alongside cryptocurrency wallet data.
SlowMist’s analysis found two modules inside versions 1.1 and 1.2 that had nothing to do with the app’s advertised functions. One contained an iOS kernel exploitation framework equipped with eight exploit methods, letting it select an attack based on the device model and operating system version. The framework’s declared coverage ran from iOS 12.0 through 18.7.2 and from iOS 26.0 through 26.1, with older versions facing a higher level of risk.
Once an exploit succeeded, the code could escape the iOS sandbox, decrypt Keychain data and read files belonging to other applications. That access path exposes private keys, wallet recovery phrases, passwords and sensitive information stored as images on the phone, the researchers said. SlowMist began its investigation after receiving multiple reports of stolen assets involving private key exposure, and the firm’s findings were then mirrored in Binance’s advisory.
A familiar playbook with a new entry point
The crypto industry has seen this shape of attack before, usually with a weaker mechanism. An earlier malware family called SparkCat used optical character recognition to scan photos for recovery phrases, and some of the applications carrying it reached official app stores. Kaspersky traced that campaign back to March 2024, making it one of the longer-running mobile threats aimed specifically at crypto holders.
In March, Google’s Threat Intelligence Group identified an iPhone exploit kit known as Coruna containing five complete exploit chains and 23 vulnerabilities, targeting devices on iOS 13 through 17.2.1 and searching compromised phones for wallet recovery phrases and financial information. Google researchers noted that the toolkit had moved through different groups over time, including financially motivated cybercriminals, which suggests the underlying tooling circulates rather than staying with whoever built it.
In February 2025, SlowMist reported that a fake application called BOM had compromised more than 13,000 wallets across Android and iOS, with losses estimated above $1.82 million. That application requested access to files, photos and media before scanning device storage for private keys and mnemonic phrases and transmitting the information to a remote server. On-chain analysis linked the main attacker address to stolen assets moving across BNB Chain, Ethereum, Polygon, Arbitrum and Base, with USDT, Ethereum, Wrapped Bitcoin and Dogecoin among the affected currencies.
Impersonation scams have run in parallel. A fake Wasabi Wallet app appeared on Apple’s App Store in August and was linked to the theft of roughly 6 BTC from one victim, the 27th reported crypto wallet clone found on the store during 2026 at the time. A fake Ledger application remains the largest reported case among the clones, with roughly $9.3 million stolen, and a fake Ledger Live app was tied to the loss of 5.9 BTC, worth about $420,000, from the American musician Garrett Dutton, known professionally as G. Love. Dutton downloaded the software posing as the Ledger Live manager onto a new MacBook Neo and entered his recovery phrase into the fraudulent application, after which blockchain records showed the stolen Bitcoin moving to several deposit addresses associated with the KuCoin exchange.
The difference with FomoPeek is that it does not need to trick anyone into surrendering a recovery phrase. It takes system-level access first and collects everything afterward, which is why Binance’s advice goes beyond simply deleting the app. Wallet impersonation depends on human error at a specific moment. A kernel exploit framework works regardless of how careful the user is with their seed phrase.
What affected users should do
Self-custody users who installed FomoPeek were told to use a separate device that has never had the app installed, create a new wallet there and transfer all assets to the new address. SlowMist recommended checking accounts for unauthorized activity and generating a new private key and seed phrase on a trusted device before moving funds out of any wallet potentially exposed through versions 1.1 or 1.2.
Binance added that users should keep device software current and avoid applications from untrusted sources, and asked anyone who detects unusual asset activity to preserve the affected device and relevant evidence before contacting customer support. Preservation matters because the exploit framework’s behavior varies by iOS version, and a wiped device destroys the evidence researchers would need to trace which exploit path was used against a given phone.
The incident is a reminder that the weakest link in self-custody is rarely the wallet software itself. It is the operating system beneath it, and the applications a user installs around it. A kernel exploit framework with eight selectable attack methods, shipped inside an ordinary-looking app, defeats nearly every operational security habit short of never installing the thing at all. The practical takeaway is narrow but firm: if FomoPeek was ever on the device, the wallet keys on it should be treated as compromised, and the funds should move to a wallet generated somewhere the app never ran.
