‹ BackNewsOn-chain Security

On-chain Security

Bitget says security incident involved about $351.6 million, with losses covered by user protection fund
Bitget launches recovery bounty program with 5% rewards for frozen or recovered funds
SlowMist says DoinGud contract flaw let attacker replay transactions and net about 35,380 USDC
SlowMist flags GaslessReservoirEnabler flaw after about $23,000 in WETH and ZED is drained
SlowMist
2026-09-21 01:58:08

SlowMist says App Store-listed FomoPeek carried modules that could steal wallet data across apps

SlowMist said in a Sept. 20 report that FomoPeek, an on-chain monitoring app distributed through Apple’s App Store, included two malicious modules in versions 1.1 and 1.2 that could remotely fetch instructions, attempt kernel exploits, escape sandbox restrictions, decrypt Keychain data and collect information from other apps. The security firm said the case began after multiple users reported stolen assets and private key exposure, with some of the affected users having used those two versions before the thefts. According to the report, FomoPeek presented itself as a standard crypto tracking product. It had an App Store listing, a website, and an official X account, and marketed itself as a read-only whale tracker for Solana, Ethereum and TRON wallets that did not require seed phrases or wallet connections. SlowMist said its isolated testing retrieved a collection list covering 19 wallet and note-taking apps and captured an uploaded archive containing Apple Notes data. The report also traced one main attacker address analyzed by MistTrack. SlowMist said the address had been active since Sept. 15 and had received a cumulative 579,984.34 USDT by the time the report was published. Funds touched Ethereum, BNB Chain and Arbitrum, with part of the flow moving through FixedFloat and KuCoin. SlowMist advised users who had run FomoPeek 1.1 or 1.2 to treat related seed phrases, private keys and credentials as compromised and migrate assets on a separate trusted device.

3151
SlowMist says App Store-listed FomoPeek carried modules that could steal wallet data across apps
PeckShield says attacker exploited SingularityNET bridge contract flaw to mint AGIX and WMTx
BlockSec Phalcon says Ethereum attack spree hit multiple projects for over $2.1 million
Fake Uniswap ENS names used in arbitrage bot scam that stole over $500,000