SlowMist warns FomoPeek App versions 1.1 to 1.2 pose asset theft risk

SlowMist warns FomoPeek App versions 1.1 to 1.2 pose asset theft risk

N
News Editor
2026-09-19 06:55:49
SlowMist has issued a security alert on FomoPeek App versions 1.1 to 1.2 after receiving multiple reports of stolen user assets. The firm said verified cases involved private key leaks, and some affected users had downloaded and used those versions of the app. After a joint review with the OKX security team, SlowMist said it found clear evidence that the application had been implanted with malicious code. According to the alert, the app bundled two modules unrelated to its stated business functions. One of them contained a professional iOS kernel attack framework with eight exploit options that could automatically choose an attack path based on device model and system version. The affected iOS versions were listed as iOS 12.0 to 18.7 and 26.0 to 26.1. If the attack succeeds, the app can break through iOS sandbox isolation, read and decrypt the system Keychain, and access data files from other apps on the device. SlowMist said private keys, seed phrases, login credentials, chat records and files stored on the device could all be exposed. It also said the app connected to hidden servers unrelated to its public business and received remote instructions, with intercepted plaintext communications showing the attack function was active and executed regularly. Users who installed or used the app were urged to check account and key security, create new accounts and keys on a safe device, move assets, update iOS, stop using the app, and keep evidence if abnormal asset activity is found.

Odaily reported that blockchain security firm SlowMist issued an alert on FomoPeek App versions 1.1–1.2, warning of an asset theft risk after receiving multiple user reports of stolen funds. After verification, SlowMist said all related cases involved private key exposure, and some of the affected users had downloaded and used FomoPeek versions 1.1–1.2.

Following a joint analysis by SlowMist and the OKX security team, the firms said there is clear evidence that the app had been implanted with malicious code. In addition to its normal business functions, the application reportedly bundled two modules unrelated to its stated business. One of those modules contained a professional iOS kernel attack framework integrating eight exploit methods, with the ability to automatically choose an attack path based on device model and system version. The affected iOS versions were listed as iOS 12.0–18.7 and 26.0–26.1.

SlowMist said that if the attack succeeds, the app can bypass iOS sandbox isolation, then read and decrypt the system Keychain and access data files from other apps on the device. Private keys, seed phrases, login credentials, chat records and files stored on the device could all face exposure as a result.

The alert also said the app connects to hidden servers unrelated to its public-facing business and receives remote instructions. Plaintext communications captured by the team showed the attack function is currently enabled and runs automatically on a regular basis. SlowMist added that the lower the iOS version running on a device, the higher the potential risk.

For users who have downloaded or used the app, SlowMist advised them to immediately check the security of their accounts, assets and private keys; create a new account and generate a brand-new key on a safe device that has never had the app installed; move assets to the new account as soon as possible; update to the latest iOS version; and stop using or reinstalling the app.

If any abnormal asset activity is found, users should contact the official customer service channels of the relevant platform at once and preserve the device and related evidence for further review, according to the warning.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.