SlowMist and OKX say App Store-listed FomoPeek versions 1.1 and 1.2 carried an iOS exploit framework

SlowMist and OKX say App Store-listed FomoPeek versions 1.1 and 1.2 carried an iOS exploit framework

N
News Editor
2026-09-22 03:10:39
SlowMist and the OKX security team said their joint analysis found that FomoPeek, an on-chain whale-tracking app distributed through Apple’s App Store, included a full iOS kernel attack framework in versions 1.1 and 1.2. According to the report, users did not provide mnemonic phrases and did not sign any transactions, yet their assets could still be stolen. SlowMist’s MistTrack data showed a main hacker address active since Sept. 15 that had received 579,984.34 USDT as of publication, with funds still flowing in. The researchers said the malicious components were shipped inside the official App Store builds rather than spread through re-signing or sideloading, and that the framework could communicate with attacker-controlled servers, exploit kernel flaws, escape the sandbox, decrypt Keychain data and collect information across apps. The report also said the command-and-control server targeted 19 wallet and note-taking apps, including Gate Web3, SafePal, OKX Wallet, MetaMask, Trust Wallet, imToken, TokenPocket, TronLink and Apple Notes. SlowMist advised users who installed versions 1.1 or 1.2 to treat old mnemonic phrases and private keys as compromised and move assets to a newly created wallet on a clean device.

SlowMist and the OKX security team said a joint investigation found that FomoPeek, an on-chain whale-monitoring app listed on Apple’s App Store, shipped a full iOS kernel attack framework in versions 1.1 and 1.2. The report said users could lose assets even if they never handed over a mnemonic phrase and never signed a transaction.

Data from SlowMist MistTrack showed that a main hacker address had been active since Sept. 15 and had received a total of 579,984.34 USDT by the time of publication, with inflows still continuing.

How the app was promoted and when the code changed

FomoPeek was presented publicly as a read-only on-chain alert tool. Its promotional material said it did not connect to wallets and did not require mnemonic phrases. The app was promoted through crypto KOLs and community channels. Users were asked to download it from the App Store with an invitation code, register, set a "security code," add wallet monitoring, and operate it on a physical iPhone for five to seven minutes. After review, they could receive 5 to 7 USDT.

The promotional copy also stressed that each iPhone had only one chance, multiple accounts on the same device would not count, and cloud phones were not supported. SlowMist said each run of the exploit chain took more than two minutes, which matched the requirement for real-device use and several minutes of activity. It added that this was only supporting evidence and was not enough on its own to prove malicious intent.

The version timeline in the report said FomoPeek 1.0, released on Aug. 29, appeared clean. Version 1.1, released on Sept. 9, was the first to include the malicious module. Version 1.2, released on Sept. 12, kept the same code. The framework was fully removed only in version 1.3 on Sept. 17, and the app package size dropped from 10.47 MB to 1.81 MB.

Modules inside the app and what they could do

SlowMist and the OKX security team said FomoPeek contained two modules unrelated to its stated core function. One, apptrace, handled communication with attacker-controlled servers. The other, libapptracecore, combined exploit execution and data collection.

According to the report, the framework included eight exploit strategies and would choose one automatically based on the device model and iOS version. The code claimed coverage from iOS 12.0 to 18.7.2, as well as iOS 26.0 to 26.1. The researchers said the malicious modules were not distributed through third-party re-signing or sideloading. They were included in the official App Store versions, and the malicious framework used the same Apple signing identity as the main app.

Targets included 19 wallet and note apps

A collection list returned by the command-and-control server targeted 19 wallet and note-taking apps. The report specifically named Gate Web3, SafePal, OKX Wallet, MetaMask, Trust Wallet, imToken, TokenPocket, TronLink and Apple Notes.

If exploitation succeeded, private keys, mnemonic phrases, login credentials, chat records and files could all be exposed, the report said.

Deleting the app or upgrading does not mean the device is safe

SlowMist warned that uninstalling the app or upgrading to version 1.3 did not mean the device had returned to a safe state. If the framework had already succeeded, the data could already have left the device.

The report also pointed to another public case, ComeCome, a food-delivery app aimed at Chinese users in places including Dubai. SlowMist said version 2.9.3 of that app was found to contain a component called DKStatistics, which also had the ability to escape the iOS sandbox and access data from wallet apps, WhatsApp and Apple Notes.

SlowMist described the methods seen in FomoPeek and ComeCome as "app poisoning" or "trusted-channel poisoning," rather than a typical watering-hole attack. The logic, it said, was the same: infiltrate an entry point that the target group has trusted for a long time, then wait for users to walk in on their own.

What SlowMist told affected users to do

For users who had installed FomoPeek version 1.1 or 1.2, SlowMist advised stopping use immediately and not reinstalling the app. It said users should create a brand-new wallet and generate a new mnemonic phrase on a clean device that had never installed FomoPeek, then move assets there. Old mnemonic phrases and private keys should be treated as compromised and should no longer be used. The report also told users to review abnormal transfers and approval records across chains and revoke approvals that were no longer needed.

SlowMist ended the report with a warning not to assume an app is safe just because it comes from the App Store, or that a website is safe just because it is a familiar daily channel. When attackers target crypto users, it said, any long-trusted entry point can become a trap.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.