Techub News reported that a joint investigation by SlowMist TI and the OKX security team found malicious code embedded in FomoPeek app versions 1.1 to 1.2, and linked the app to multiple incidents involving leaked private keys and stolen assets.
Hidden module included an iOS kernel exploitation framework
The investigation found that, beyond its normal functions, FomoPeek contained a hidden module unrelated to its business use. That module included an iOS kernel exploitation framework capable of automatically selecting attack methods for different device models and system versions.
Affected iOS versions and data at risk
The affected range covers iOS 12.0 to 18.7 and iOS 26.0 to 26.1. Once an attack succeeds, the malicious app may break through iOS sandbox restrictions, obtain and decrypt Keychain data, and read files from other applications. That could allow it to steal private keys, seed phrases, account login credentials, chat records, local files, and other sensitive information.
Attack functions were active and executed regularly
The investigation also found that FomoPeek connected to hidden servers unrelated to its public-facing service and received remote instructions. Captured plaintext traffic showed that its attack functions were currently enabled and executed automatically on a regular basis. Devices running older iOS versions faced relatively higher risk.
Recommended steps for affected users
Users who have installed or used FomoPeek versions 1.1 to 1.2 were advised to immediately create a new wallet on a trusted device that has never had the app installed, generate a new private key and seed phrase, and move assets as soon as possible. They were also advised to check for unusual account activity, update to the latest available iOS version, and stop using the app or reinstall it.
If suspicious transfers are found, users should contact the relevant platform's official customer service as soon as possible and preserve the device involved along with any evidence.

