FomoPeek iOS App Malware Exposes Crypto Keys as Users Report Wallet Drains

Changelly



FomoPeek, an iPhone app marketed for tracking whale wallets across Solana, Ethereum and TRON, contained malicious code capable of escaping iOS security restrictions and extracting cryptocurrency wallet credentials from affected devices.

SlowMist issued an asset-theft warning on September 19 after investigating multiple cases of stolen crypto with OKX’s security team. The affected users had installed or used FomoPeek versions 1.1 or 1.2 before their assets were taken.

The disclosure comes amid several unrelated crypto security incidents this weekend. Blink temporarily suspended services after an attacker drained custodial accounts, while Fetch.ai and NuNet were hit by a separate $2 million exploit.

Malware Contains Eight iOS Attack Methods

Researchers identified two malicious modules inside FomoPeek that were unrelated to its advertised wallet-tracking functions. One contained an iOS kernel exploitation framework with eight attack methods capable of adapting to different device models and operating-system versions.

The affected range identified by researchers spans iOS 12.0 through 18.7 and iOS 26.0 through 26.1.

Once successful, the malicious code could escape the normal application sandbox, access and decrypt Keychain information and read data belonging to other applications. Potentially exposed information included private keys, recovery phrases, login credentials, chat records and other files stored on the device.

SlowMist also detected connections to servers outside FomoPeek’s normal infrastructure. Captured network traffic indicated that the malicious functionality was active and configured to execute automatically at recurring intervals rather than existing as dormant code.

Exposed Wallet Credentials Must Be Replaced

Binance Wallet warned affected users to remove FomoPeek, update their devices to the latest available iOS version and avoid reinstalling the application.

Users who stored or accessed crypto wallets on an affected device were advised to generate fresh wallet credentials on a clean device that had never run FomoPeek, then transfer remaining funds to the new addresses.

Deleting the application alone cannot secure a private key or recovery phrase that has already been extracted. Anyone holding those credentials can recreate the wallet elsewhere and authorize transactions without regaining access to the compromised iPhone.

Users who identify unauthorized transactions were also advised to preserve the affected device and transaction records for investigation rather than immediately wiping evidence.

SlowMist has not disclosed the aggregate value stolen through FomoPeek or the total number of compromised devices. Its September 19 investigation linked versions 1.1 and 1.2 to reported asset theft and confirmed that the releases contained functionality capable of reaching sensitive data outside the app’s normal sandbox.



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*