Skip to main content

SlowMist Links Malicious FomoPeek iOS App to $580K Crypto Theft



Security researchers have traced nearly $580,000 in stolen crypto to a malicious iOS application distributed through Apple’s App Store. According to an investigation by blockchain security firm SlowMist, the app—named FomoPeek—contained kernel exploitation capabilities designed to break out of Apple’s sandbox and reach sensitive wallet-related data.


SlowMist says the incident involved multiple attack modules that could elevate privileges and steal data stored by other apps, including items accessible via iOS Keychain mechanisms. The firm also tied onchain activity to a primary hacker address that received 579,984 USDT, with funds later routed across several services and networks.


Key takeaways



  • SlowMist links the FomoPeek iOS app to about 579,984 USDT in stolen funds, based on onchain analysis.

  • The malicious components were distributed in specific app versions released on Sept. 9 and Sept. 12, and removed in version 1.3 released Sept. 17.

  • The exploit framework targeted iOS versions broadly (12.0 to 18.7.2 and 26.0 to 26.1) and included multiple methods for sandbox escape.

  • SlowMist’s tracing indicates cross-network movement, followed by consolidation and transfers through intermediaries such as FixedFloat, KuCoin, and cce.cash.


What researchers say the app did


In its threat-intelligence analysis, SlowMist reports that FomoPeek introduced two malicious modules capable of exploiting iOS vulnerabilities. The firm describes how these components could help the app escape Apple’s sandbox environment, then gain elevated privileges to access sensitive data and files associated with other apps.


The report specifically highlights the ability to reach data stored in the Keychain, a common target for attackers looking to obtain credentials, tokens, or other secrets used by mobile applications. Once those privileges are gained, the scope of theft can broaden quickly—especially for users who already have crypto wallet software or related services installed on the same device.


Version timeline and what changed


SlowMist’s investigation provides a narrow window for when the harmful code was present. The firm says the affected FomoPeek versions were released on Sept. 9 and Sept. 12. It then points to a mitigation step: version 1.3**, released on Sept. 17, that removed the malicious components.


The detail matters for users and defenders because it implies the threat was not continuous across the entire app’s lifecycle. Instead, it appears tied to particular builds—meaning that devices running older versions would be at the highest risk, while later versions may have reduced exposure.


SlowMist also states that its work began after it received reports from users who said they experienced crypto theft and confirmed they had installed FomoPeek builds that fell within the affected period. The firm conducted the technical work together with the OKX security team.


Onchain trail: 579,984 USDT and cross-platform routing


To connect the iOS compromise to real-world losses, SlowMist performed onchain analysis. The firm says it identified a primary hacker address associated with the incident that received approximately 579,984 USDT.


SlowMist reports that this address became active on Sept. 15 and that the stolen funds were handled across multiple blockchain networks before being consolidated. From there, the flow continued through additional hops and addresses designed to obscure the trail.


In the report, SlowMist notes that portions of the funds were directed toward services including FixedFloat, KuCoin, and cce.cash. Other funds were dispersed across further addresses that the firm continued to trace.


While onchain movement cannot prove the full mechanics of the compromise by itself, it does provide a measurable link between the suspected attacker infrastructure and the ultimate transfer behavior. It also helps explain why such incidents often become multi-stage: initial theft on-device can be followed by rapid conversion, relocation, and consolidation efforts across chains and counterparties.


Targets, scope, and the exploit framework


SlowMist says the exploit framework used by FomoPeek included eight attack methods and claimed support for a wide range of iOS versions—specifically 12.0 to 18.7.2 and also 26.0 to 26.1.


That breadth is notable because iOS versions are not uniform, and exploit reliability can vary widely depending on device and patch level. A broader claimed range can indicate an attempt at wide applicability, which increases potential impact beyond a single narrow segment of users.


Still, the report’s most practical takeaway for users is not the list of supported versions—it’s the version-specific presence of the malicious code. If the harmful components were truly removed in version 1.3 on Sept. 17, that suggests updated installs could have helped limit damage going forward.


Cointelegraph attempted to request comments from Apple, SlowMist, and OKX, but did not receive responses before publication.


Readers should watch closely for follow-up disclosures from the security community and, most importantly, verify whether they have installed FomoPeek and which app version is currently on their devices. If a user still has any affected build installed, removing the application and updating to a later version would be a sensible immediate step, alongside reviewing wallet activity for any unusual transfers.



https://www.cryptobreaking.com/slowmist-links-malicious-fomopeek-ios/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=SlowMist%20Links%20Malicious%20FomoPeek%20iOS%20App%20to%20$580K%20Crypto%20Theft%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...