Close Menu
    Facebook X (Twitter) Instagram
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Facebook X (Twitter) Instagram
    Bytecore News
    • Home
    • Crypto News
      • Bitcoin
      • Ethereum
      • Altcoins
      • Blockchain
      • DeFi
    • AI News
    • Stock News
    • Learn
      • AI for Beginners
      • AI Tips
      • Make Money with AI
    • Reviews
    • Tools
      • Best AI Tools
      • Crypto Market Cap List
      • Stock Market Overview
      • Market Heatmap
    • Contact
    Bytecore News
    Home»Crypto News»Blockchain»Malicious iOS App FomoPeek Linked to $580K Crypto Theft
    Cointelegraph
    Blockchain

    Malicious iOS App FomoPeek Linked to $580K Crypto Theft

    September 24, 20263 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email
    coinbase



    [Update 09:15 UTC, Sept. 23: This article was updated with comments from SlowMist on how FomoPeek operated, what its researchers verified and its advice for people who installed affected versions.]

    A malicious iOS app distributed through Apple’s App Store has been linked to nearly $580,000 in stolen crypto after researchers found it contained multiple kernel exploits capable of escaping Apple’s sandbox and accessing sensitive wallet data.

    According to an investigation published by blockchain security firm SlowMist, the app, called FomoPeek, introduced two malicious modules that could exploit iOS vulnerabilities, gain elevated privileges and access Keychain data and files belonging to other apps. 

    SlowMist said the affected versions were released on Sept. 9 and Sept. 12, while version 1.3, released Sept. 17, removed the malicious components.

    binance

    SlowMist said its investigation, conducted with the OKX security team, began after it received reports from users who had suffered asset theft and found that some had previously installed the affected FomoPeek versions.

    The exploit framework included eight attack methods and declared support for iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1.

    FomoPeek targeted wallet and notes app data

    “For FomoPeek specifically — no. No Safari or webpage is involved at all,” SlowMist told Cointelegraph when asked whether the attack required users to open a malicious page. It said the framework loaded when the app launched, while a remote server could control its exploitation and data collection functions.

    SlowMist said the server’s configuration named 19 wallet and note apps as targets, including MetaMask, Trust Wallet, SafePal, OKX Wallet and Apple Notes.

    “We confirmed the framework’s ability to collect application data in our controlled environment, including the Apple Notes container,” the company said. It cautioned that this did not establish that a private key or seed phrase had been extracted from every named wallet.

    SlowMist’s onchain analysis identified a primary hacker address associated with the incident that received about 579,984 USDT. The firm said the address became active on Sept. 15 and that the stolen funds involved multiple blockchain networks before being consolidated and transferred through several addresses and services.

    SlowMist’s investigation found that portions of the funds were transferred toward services including FixedFloat, KuCoin and cce.cash, while other funds were dispersed through additional addresses that the firm continued to trace.

    SlowMist urges affected users to move assets to a new wallet

    For users who installed FomoPeek versions 1.1 or 1.2, SlowMist recommended treating potentially exposed wallet credentials as compromised, creating a new wallet on an unaffected device and moving assets to it.

    “If an attacker has already successfully exploited the device and copied sensitive data off the device, enabling Lockdown Mode or uninstalling the malicious application afterwards cannot retrieve that data,” SlowMist said.

    Cointelegraph reached out to Apple and OKX for comment but did not receive a response before publication.

    Helen Partz contributed reporting.

    Related: Hugging Face hack exposes the open-weight AI cybersecurity paradox



    Source link

    aistudios
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    CryptoExpert
    • Website

    Related Posts

    European Central Bank Connects Tokenized Assets to Central Bank Money – Bitcoin News

    September 23, 2026

    PLTR Price Prediction: AI Sovereignty Premium Meets a Valuation Ceiling — $195 or $165 in 30 Days?

    September 22, 2026

    Optimism Releases Required Op Batcher V1 17 0 Upgrade

    September 21, 2026

    Gen Z are investing like Boomers

    September 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    aistudios
    Latest Posts

    Winners And Losers Of SEC’s New Tokenized Stocks Rules

    September 24, 2026

    A Coding Guide to TypeSafe AI Jev: Typed Decisions, Calibrated Confidence, and Speculative Fan-Out with a System One Model

    September 24, 2026

    10 Stocks Tell You EVERYTHING about the Market

    September 24, 2026

    I Found The LAZIEST Way To Make Money With AI

    September 24, 2026

    AI For Beginners. 5 course to bootstrap you into AI in 2026.

    September 24, 2026
    aistudios
    LEGAL INFORMATION
    • Privacy Policy
    • Terms Of Service
    • Social Media Disclaimer
    • DMCA Compliance
    • Anti-Spam Policy
    Top Insights

    White hats recover 52 Bitcoin from Coldcard exploit, and a new public portal lets victims check eligibility

    September 24, 2026

    Malicious iOS App FomoPeek Linked to $580K Crypto Theft

    September 24, 2026
    aistudios
    Facebook X (Twitter) Instagram Pinterest
    © 2026 BytecoreNews.com - All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.