Odaily reported that blockchain security firm SlowMist issued an alert on FomoPeek App versions 1.1–1.2, warning of an asset theft risk after receiving multiple user reports of stolen funds. After verification, SlowMist said all related cases involved private key exposure, and some of the affected users had downloaded and used FomoPeek versions 1.1–1.2.
Following a joint analysis by SlowMist and the OKX security team, the firms said there is clear evidence that the app had been implanted with malicious code. In addition to its normal business functions, the application reportedly bundled two modules unrelated to its stated business. One of those modules contained a professional iOS kernel attack framework integrating eight exploit methods, with the ability to automatically choose an attack path based on device model and system version. The affected iOS versions were listed as iOS 12.0–18.7 and 26.0–26.1.
SlowMist said that if the attack succeeds, the app can bypass iOS sandbox isolation, then read and decrypt the system Keychain and access data files from other apps on the device. Private keys, seed phrases, login credentials, chat records and files stored on the device could all face exposure as a result.
The alert also said the app connects to hidden servers unrelated to its public-facing business and receives remote instructions. Plaintext communications captured by the team showed the attack function is currently enabled and runs automatically on a regular basis. SlowMist added that the lower the iOS version running on a device, the higher the potential risk.
For users who have downloaded or used the app, SlowMist advised them to immediately check the security of their accounts, assets and private keys; create a new account and generate a brand-new key on a safe device that has never had the app installed; move assets to the new account as soon as possible; update to the latest iOS version; and stop using or reinstalling the app.
If any abnormal asset activity is found, users should contact the official customer service channels of the relevant platform at once and preserve the device and related evidence for further review, according to the warning.

