Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$85,496▼ 0.28%ETH$2,716▼ 0.97%SOL$116.72▼ 0.24%TOTAL CRYPTO$2.92T▼ 3.21%S&P 5007,764.64▲ 1.18%NASDAQ27,244.28▲ 4.06%DOW51,863.69▼ 2.65%GOLD4,342.40▼ 7.57%WTI90.89▲ 6.92%BRENT96.35▲ 4.54%EUR/USD1.1409▼ 2.39%USD/JPY157.88▼ 0.63%DXY100.95▲ 1.97%
Crypto

FomoPeek iOS App Stole $580K in Crypto, SlowMist Finds

Malicious versions of a whale-watching app escaped the iOS sandbox and grabbed wallet data. SlowMist traced about $580,000 in USDT to one address.

Pexels – Morthy Jameson

A whale-watching app distributed through Apple App Store contained kernel exploits that escaped the iOS sandbox and stole private key material, and blockchain security firm SlowMist has linked it to roughly $580,000 in stolen crypto. The firm published its investigation on Wednesday with the OKX security team after receiving theft reports from users who had installed the app.

The app, called FomoPeek, marketed itself as a tool for monitoring whale wallet movements. Versions 1.1 and 1.2, released on the App Store on September 9 and September 12, carried two malicious modules that exploited iOS vulnerabilities to gain elevated privileges. Once elevated, the code could read Keychain data and files belonging to other installed apps, including wallet files and seed phrases.

How the theft worked

SlowMist said the malicious app declared support for iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1, giving it a wide pool of potential targets. The kernel exploits let the app break out of the sandbox that normally confines each app to its own data. From there it could harvest anything a user had stored on the device, from exchange session tokens to plaintext recovery phrases.

On-chain analysis identified a primary hacker address that received about 579,984 USDT. The address became active on September 15 and moved stolen funds across multiple networks through services including FixedFloat, KuCoin and cce.cash. SlowMist did not name the total number of victims but said users who installed either malicious version should treat all keys accessible from their iPhone as compromised.

A clean version 1.3 appeared on the App Store on September 17 with the malicious components removed. That gap between the last malicious build and the clean release is the window in which most of the traced thefts occurred. It is also the window in which most victims would have had no reason to suspect anything, since the app functioned as advertised on the surface.

Recommendations for affected users

Security researchers recommend generating new seed phrases on a clean device and immediately transferring funds to secure wallets. Simply deleting the app is not enough, because anything the app already read remains in the hands of the attacker. Users should also revoke exchange API keys and sessions created from the affected device, and treat any accounts that were logged in on the phone as at risk.

Researchers also suggest checking whether any hardware wallet pairing apps were used on the same device. Seed phrases typed into on-screen keyboards on a compromised phone should be considered burned, even if the wallet itself lives on a separate hardware device, because the phrase was visible to the compromised system at the moment of entry.

The case is unusual because the malicious code passed App Store review twice. Apple screens submissions with a mix of automated and manual review, and kernel-level exploit chains are rare in apps that make it through. The incident shows that review is not a security guarantee, particularly for apps targeting the crypto community, where a single seed phrase can be worth more than typical app fraud takes in over years.

Part of a broader pattern

Crypto theft through mobile apps has been climbing all year. SlowMist and other firms have documented fake wallet apps, clipboard hijackers and malicious browser extensions throughout 2026. What sets FomoPeek apart is the use of genuine iOS kernel exploits rather than social engineering, which puts it closer to state-grade tooling than ordinary scamware. Researchers note that full exploit chains of this kind typically sell for millions on the gray market, which raises the question of who built the tooling and who paid for it.

The timing also lands amid a broader security story in bitcoin infrastructure. The Liquid Network sidechain was drained of 4,000 BTC, about $320 million, by self-described white-hat hackers earlier this month, and a Coldcard hardware wallet hack led white-hat responders to evacuate 52 bitcoin ahead of the attackers last week. Security researchers describe 2026 as an unusually active year for attacks on both software and hardware wallets, with several incidents involving insider knowledge or supply-chain compromise rather than brute-force attacks on cryptography.

For exchanges, the incident is a reminder that session security matters. Some of the stolen funds moved quickly because the app harvested active exchange sessions, letting attackers trade or withdraw before users noticed anything wrong. Exchanges including OKX have been cooperating with SlowMist on tracing, and some have frozen suspect deposits. Recovery odds are slim once funds pass through instant swap services, but frozen exchange deposits occasionally return to victims through legal process.

Apple did not immediately respond to requests for comment on how the malicious versions passed review. The App Store listing for FomoPeek was still live at the time of writing, serving the clean version 1.3. Whether Apple takes further action, such as notifying users who installed the affected builds, remains to be seen. Past incidents of this kind have usually ended with silent removal rather than public notification, which leaves the burden of response on security firms and the users themselves.

The broader lesson for crypto users is unchanged: seed phrases belong on paper or dedicated offline storage, never on a phone, and any device that has run untrusted software should be treated as burned until its keys are rotated. That advice is older than the smartphone era, but incidents like this one keep proving it current.

SourcesCointelegraph, citing the SlowMist investigation; Gate News, citing Bitcoin News and OKX security team input; Crypto Briefing.
Share: X