SlowMist and OKX security team say FomoPeek iOS app carried malicious code

SlowMist and OKX security team say FomoPeek iOS app carried malicious code

N
News Editor
2026-09-20 12:12:26
SlowMist TI and the OKX security team said a joint investigation found malicious code embedded in FomoPeek versions 1.1 to 1.2, linking the app to multiple cases involving leaked private keys and stolen assets. According to the findings, the app included a hidden module unrelated to its stated business functions, including an iOS kernel exploitation framework that could automatically choose attack methods based on device model and system version. The reported impact range covers iOS 12.0 to 18.7 and iOS 26.0 to 26.1. If the attack succeeds, the malicious app may break out of the iOS sandbox, obtain and decrypt Keychain data, read files from other apps, and steal sensitive information such as private keys, seed phrases, account credentials, chat records, and local files. Investigators also said FomoPeek connected to hidden servers unrelated to its public service and received remote commands. Captured plaintext traffic showed the attack functions were active and ran automatically on a regular basis, with older iOS versions facing relatively higher risk.

Techub News reported that a joint investigation by SlowMist TI and the OKX security team found malicious code embedded in FomoPeek app versions 1.1 to 1.2, and linked the app to multiple incidents involving leaked private keys and stolen assets.

Hidden module included an iOS kernel exploitation framework

The investigation found that, beyond its normal functions, FomoPeek contained a hidden module unrelated to its business use. That module included an iOS kernel exploitation framework capable of automatically selecting attack methods for different device models and system versions.

Affected iOS versions and data at risk

The affected range covers iOS 12.0 to 18.7 and iOS 26.0 to 26.1. Once an attack succeeds, the malicious app may break through iOS sandbox restrictions, obtain and decrypt Keychain data, and read files from other applications. That could allow it to steal private keys, seed phrases, account login credentials, chat records, local files, and other sensitive information.

Attack functions were active and executed regularly

The investigation also found that FomoPeek connected to hidden servers unrelated to its public-facing service and received remote instructions. Captured plaintext traffic showed that its attack functions were currently enabled and executed automatically on a regular basis. Devices running older iOS versions faced relatively higher risk.

Recommended steps for affected users

Users who have installed or used FomoPeek versions 1.1 to 1.2 were advised to immediately create a new wallet on a trusted device that has never had the app installed, generate a new private key and seed phrase, and move assets as soon as possible. They were also advised to check for unusual account activity, update to the latest available iOS version, and stop using the app or reinstall it.

If suspicious transfers are found, users should contact the relevant platform's official customer service as soon as possible and preserve the device involved along with any evidence.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1000

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.