‹ BackiOS 26

iOS 26

SlowMist
2026-09-22 03:10:39

SlowMist and OKX say App Store-listed FomoPeek versions 1.1 and 1.2 carried an iOS exploit framework

SlowMist and the OKX security team said their joint analysis found that FomoPeek, an on-chain whale-tracking app distributed through Apple’s App Store, included a full iOS kernel attack framework in versions 1.1 and 1.2. According to the report, users did not provide mnemonic phrases and did not sign any transactions, yet their assets could still be stolen. SlowMist’s MistTrack data showed a main hacker address active since Sept. 15 that had received 579,984.34 USDT as of publication, with funds still flowing in. The researchers said the malicious components were shipped inside the official App Store builds rather than spread through re-signing or sideloading, and that the framework could communicate with attacker-controlled servers, exploit kernel flaws, escape the sandbox, decrypt Keychain data and collect information across apps. The report also said the command-and-control server targeted 19 wallet and note-taking apps, including Gate Web3, SafePal, OKX Wallet, MetaMask, Trust Wallet, imToken, TokenPocket, TronLink and Apple Notes. SlowMist advised users who installed versions 1.1 or 1.2 to treat old mnemonic phrases and private keys as compromised and move assets to a newly created wallet on a clean device.

110
SlowMist and OKX say App Store-listed FomoPeek versions 1.1 and 1.2 carried an iOS exploit framework
SlowMist
2026-09-21 19:20:46

SlowMist warns Darksword exploit may now target iOS 26.5 and steal wallet private keys

SlowMist Chief Information Security Officer 23pds said attackers are exploiting the Darksword vulnerability through Safari to bypass iOS security protections, take control of devices, and extract private keys and other data from self-custodied crypto wallets. The flaw had previously been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had earlier disclosed that Darksword originally affected iOS 18.4 through 18.7. According to 23pds, attackers have now adapted the exploit to iOS 26.5, though that claim has not been officially verified. The attack chain typically starts with social engineering: once a user clicks a malicious link sent through social media or messaging apps, the device may be rooted and wallet data extracted. SlowMist urged users to update their phones promptly and avoid visiting links sent by strangers. Separately, Bitcoin.com News reported that three investors who downloaded fake wallet apps from Apple’s official App Store lost nearly $1.8 million in Bitcoin and have sued Apple.

80
SlowMist warns Darksword exploit may now target iOS 26.5 and steal wallet private keys
SlowMist
2026-09-21 19:21:50

SlowMist warns Darksword exploit can bypass iOS protections and extract wallet private keys

SlowMist Chief Information Security Officer 23pds said attackers are exploiting the Darksword vulnerability to bypass iOS security protections through Safari, seize control of devices, and extract private keys and other data from self-custodied crypto wallets. He said the exploit has been used in attacks targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google Threat Intelligence Group had previously disclosed that Darksword originally affected only iOS 18.4 through 18.7. 23pds also said attackers have adapted the exploit to iOS 26.5, though that claim has not been officially verified. According to him, the attack chain usually starts with social engineering: users click malicious links sent through social media or messaging apps, after which a device may be rooted and wallet data extracted. He urged users to update their phones promptly and avoid opening website links sent by strangers. Separately, three investors who lost nearly $1.8 million in Bitcoin after downloading a fake wallet app from Apple’s official App Store have filed a lawsuit against Apple.

80
SlowMist warns Darksword exploit can bypass iOS protections and extract wallet private keys
SlowMist
2026-09-21 01:58:08

SlowMist says App Store-listed FomoPeek carried modules that could steal wallet data across apps

SlowMist said in a Sept. 20 report that FomoPeek, an on-chain monitoring app distributed through Apple’s App Store, included two malicious modules in versions 1.1 and 1.2 that could remotely fetch instructions, attempt kernel exploits, escape sandbox restrictions, decrypt Keychain data and collect information from other apps. The security firm said the case began after multiple users reported stolen assets and private key exposure, with some of the affected users having used those two versions before the thefts. According to the report, FomoPeek presented itself as a standard crypto tracking product. It had an App Store listing, a website, and an official X account, and marketed itself as a read-only whale tracker for Solana, Ethereum and TRON wallets that did not require seed phrases or wallet connections. SlowMist said its isolated testing retrieved a collection list covering 19 wallet and note-taking apps and captured an uploaded archive containing Apple Notes data. The report also traced one main attacker address analyzed by MistTrack. SlowMist said the address had been active since Sept. 15 and had received a cumulative 579,984.34 USDT by the time the report was published. Funds touched Ethereum, BNB Chain and Arbitrum, with part of the flow moving through FixedFloat and KuCoin. SlowMist advised users who had run FomoPeek 1.1 or 1.2 to treat related seed phrases, private keys and credentials as compromised and migrate assets on a separate trusted device.

1331
SlowMist says App Store-listed FomoPeek carried modules that could steal wallet data across apps
FomoPeek
2026-09-20 12:12:26

SlowMist and OKX security team say FomoPeek iOS app carried malicious code

SlowMist TI and the OKX security team said a joint investigation found malicious code embedded in FomoPeek versions 1.1 to 1.2, linking the app to multiple cases involving leaked private keys and stolen assets. According to the findings, the app included a hidden module unrelated to its stated business functions, including an iOS kernel exploitation framework that could automatically choose attack methods based on device model and system version. The reported impact range covers iOS 12.0 to 18.7 and iOS 26.0 to 26.1. If the attack succeeds, the malicious app may break out of the iOS sandbox, obtain and decrypt Keychain data, read files from other apps, and steal sensitive information such as private keys, seed phrases, account credentials, chat records, and local files. Investigators also said FomoPeek connected to hidden servers unrelated to its public service and received remote commands. Captured plaintext traffic showed the attack functions were active and ran automatically on a regular basis, with older iOS versions facing relatively higher risk.

130
SlowMist and OKX security team say FomoPeek iOS app carried malicious code
Binance Walle
2026-09-19 15:09:59

Binance Wallet warns iPhone users to check for FomoPeek app after security disclosure

Binance Wallet has issued a security alert asking iPhone users to check whether they have installed the FomoPeek app, after a recently disclosed incident flagged by the community. According to security firms including SlowMist, versions 1.1 to 1.2 of the third-party app contain malicious code that can exploit an iOS vulnerability to gain the highest level of device privileges. If successful, the malware may access sensitive data stored on the device, including private keys, seed phrases, login credentials, chat records, and files. The notice says the threat targets the device itself rather than a single app, meaning data across all applications on an affected iPhone or iPad could be exposed. Binance Wallet asked users to check two points: whether they are using an iPhone or iPad running iOS 26.x or earlier, and whether they have installed FomoPeek. Users who meet both conditions are advised to delete the app immediately, avoid reinstalling it, update iOS to the latest version, and, if they use a self-custodial wallet, create a new wallet on a device that never had the app installed before moving assets to a new address. Binance also told users to preserve the affected device and related evidence if they notice suspicious asset activity and contact customer support for investigation.

120
Binance Wallet warns iPhone users to check for FomoPeek app after security disclosure
Apple
2026-09-16 00:47:20

Apple ships iOS 27 with holiday alarms, smoother performance, but no China Apple Intelligence rollout yet

Apple released the final version of iOS 27 in the early hours of Sept. 15 Beijing time, three months after its WWDC debut. In a detailed hands-on review, Chinese tech outlet Lei Technology said the update is defined less by headline AI features and more by a long list of practical refinements that regular users will actually notice. Among the changes highlighted were long-requested holiday alarm scheduling in the Clock app, frame extraction from videos in Photos, more customizable camera shortcuts, separate volume controls for alarms and alerts, adjustable transparency for the Liquid Glass interface, richer weather breakdowns, character-component input in the built-in Pinyin keyboard, manual QR code storage in Wallet, finer AirPods noise-control tuning, and time-limited location sharing in Find My. The outlet also pointed to what it called the most important upgrade: better smoothness, with Apple claiming app launch speeds can improve by as much as 30% and photo loading by as much as 70%. The report said iOS 27 still has bugs, though fewer than iOS 26, and argued that users already on iOS 26 may want to upgrade while people on much older versions should think more carefully. Compatibility still goes back to the iPhone 11, but, citing a response relayed by China News Service-affiliated Zhongxin Jingwei, the article said Apple customer service does not recommend upgrading devices older than the iPhone 13. It also stressed that updating to iOS 27 does not automatically bring Apple’s newest AI features: Apple Intelligence has not launched on mainland China devices, the oldest supported model remains the iPhone 15 Pro, and on-device AI models for iOS 27 require 12 GB of memory, limiting support to a smaller list of newer phones.

310
Apple ships iOS 27 with holiday alarms, smoother performance, but no China Apple Intelligence rollout yet
AI developmen
2026-07-26 03:17:21

UK engineer built an app with AI in six hours, then spent more than a year getting it ready for the App Store

British software engineer Alex Hyett says he used AI to build a working habit-tracking app in roughly six hours over a weekend in March 2025, only to spend more than a year before he felt comfortable shipping it to the App Store. In a video posted on his personal account, Hyett described how the project started as a seemingly simple app idea and turned into the most demanding software engineering exercise he had worked through. The app, later named HabitTed, was created with help from AI tools through a manual back-and-forth workflow rather than fully autonomous coding. Hyett said the early version could already add habits, assign custom icons, mark items complete, handle different goal settings, and support iCloud sync. But once he examined the code and began refactoring it, he ran into a series of deeper issues, including oversized views, inconsistent styling, broken sync behavior after reinstalling the app, inefficient statistics calculations, and a data model that required a migration plan to avoid breaking older records. He said iOS 26 exposed the limits of AI assistance even more clearly, especially when accessibility and dark mode issues surfaced and the model failed to recognize the newly released system version. Hyett’s takeaway was blunt: AI can get a project about 80% of the way there, but the last 20% can consume 80% of the time. He also linked that experience to broader concerns about skill erosion in software development.

1900
UK engineer built an app with AI in six hours, then spent more than a year getting it ready for the App Store