SlowMist and OKX say App Store-listed FomoPeek versions 1.1 and 1.2 carried an iOS exploit framework
SlowMist and the OKX security team said their joint analysis found that FomoPeek, an on-chain whale-tracking app distributed through Apple’s App Store, included a full iOS kernel attack framework in versions 1.1 and 1.2. According to the report, users did not provide mnemonic phrases and did not sign any transactions, yet their assets could still be stolen. SlowMist’s MistTrack data showed a main hacker address active since Sept. 15 that had received 579,984.34 USDT as of publication, with funds still flowing in. The researchers said the malicious components were shipped inside the official App Store builds rather than spread through re-signing or sideloading, and that the framework could communicate with attacker-controlled servers, exploit kernel flaws, escape the sandbox, decrypt Keychain data and collect information across apps. The report also said the command-and-control server targeted 19 wallet and note-taking apps, including Gate Web3, SafePal, OKX Wallet, MetaMask, Trust Wallet, imToken, TokenPocket, TronLink and Apple Notes. SlowMist advised users who installed versions 1.1 or 1.2 to treat old mnemonic phrases and private keys as compromised and move assets to a newly created wallet on a clean device.








