SlowMist Flags Crypto Wallet Security Risks From FomoPeek And DarkSword 

Ledger
Coinmama


SlowMist has raised fresh crypto wallet security concerns after identifying malicious code in FomoPeek and warning about the DarkSword exploit. The threats use different methods, but both threaten sensitive iPhone data, including private keys and wallet recovery phrases.

The security firm’s September 19 FomoPeek alert followed reports of stolen cryptocurrency. A joint investigation with OKX identified malicious components in versions 1.1 and 1.2 of the application, which was distributed through Apple’s App Store.

Separately, SlowMist Chief Information Security Officer 23pds warned that attackers may have adapted DarkSword to target iOS 26. 5. Apple and Google have not independently confirmed that exposure.

FomoPeek Malware Exposes Crypto Wallet Security Risks

Technical analysis by SlowMist found two malicious modules called apptrace and libapptracecore. The modules were included in the application called FomoPeek, which was marketed as a cryptocurrency wallet tracking tool.

Phemex

Eight different exploitation methods have been detected in the malware. In the code, it was mentioned that the exploit is compatible with iOS 12.0 to 18.7.2 and iOS 26.0 to 26.1 versions; however, FomoPeek needs at least iOS 16.

Exploitation succeeded in bypassing the Apple application sandbox and stealing information from the Keychain. The private keys, recovery phrases, logins, passwords, and data from other apps were available for extraction.

Also Read: Fetch.ai Exploit: Hacker Drains $2M Across Two AI Crypto Projects

Researchers also uncovered hidden command-and-control (C&C) infrastructure. In an isolated test environment, they identified a collection list targeting 19 wallet and note-taking apps. Testing also confirmed that the malware could collect and upload data from Apple Notes. 

Those discoveries revealed significant threats to crypto wallet security beyond the application. FomoPeek version history was used by SlowMist to trace the malicious modules. There were no such modules in version 1.0 of the application. However, starting from version 1.1, released on September 9, the code of the modules was present.

DarkSword Raises Further iPhone Security Concerns

The standalone DarkSword alert pertains to browser exploits and not malicious software. Google’s Threat Intelligence Group pinpointed this framework in March after monitoring its activities since November 2025.

DarkSword made use of six vulnerabilities to attack iPhones running iOS 18.4 through 18.7. Malicious code was deployed via infected websites to exploit any vulnerable system once the webpage was accessed.

Source: Malwarebytes

Google pointed out three malware families linked to the attacks: GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. They were capable of stealing messages, accounts, web browser history, and crypto wallets.

The campaigns that were identified involved users from Saudi Arabia, Turkey, Malaysia, and Ukraine. The discovery posed a risk for crypto wallet security in vulnerable gadgets; however, there is no evidence of the more recent iOS 26.5 version.

Apple fixed the six vulnerabilities listed in the initial investigation by Google in iOS 26.3. There is no publicly verified information regarding SlowMist’s new warning as to how attackers could overcome the patches.

Fake Wallet Apps Add to Crypto Wallet Security Concerns

Another case that occurred in April demonstrated the danger of another sort related to the company’s market. According to the report by the blockchain researcher ZahXBT, a counterfeit version of Ledger Live led to the theft of about $9.5 million worth of cryptocurrency.

The said malicious macOS application is reported to have targeted more than 50 people. In contrast to DarkSword, it utilized the victim’s entry of the recovery phrase into the malicious software.

What Affected Users Need to Do

SlowMist warned FomoPeek users that they should stop using the app and check their wallets for any unapproved transactions. If their credentials are exposed, users should create new wallets on new devices and move their remaining funds to them.

In relation to securing one’s crypto wallet, deleting malicious software will not revoke the stolen private key since hackers still have access to the wallet where they obtained the credentials.

Google has also advised users to install the most recent iOS version. However, users who cannot upgrade can use Apple’s Lockdown Mode as an additional layer of security.

These are different measures to secure crypto wallets from different threats.

Also Read: Solana Price Eyes $176 Rally as Breakout and Network Activity Strengthen



Source link

Ledger

Be the first to comment

Leave a Reply

Your email address will not be published.


*