Key Highlights
- SlowMist received reports of crypto assets being stolen from users who had installed FomoPeek versions 1.1–1.2.
- A joint investigation with OKX identified malicious components inside the affected versions.
- Researchers found an iOS kernel exploitation framework containing eight exploit methods.
SlowMist has warned that FomoPeek versions 1.1–1.2 contained malicious components that could expose sensitive information on affected iOS devices.
In a September 19 post on X, the blockchain security firm said it had received multiple reports of users’ crypto assets being stolen, with some affected users having previously installed FomoPeek versions 1.1–1.2.
SlowMist and the OKX security team later analyzed the affected versions and identified code that was unrelated to the application’s stated functions.
The investigation found an iOS kernel exploitation framework and network connections that SlowMist said were linked to the reported malicious activity.
Malicious modules found inside FomoPeek
SlowMist said two modules discovered in the application were unrelated to FomoPeek’s advertised functions.
One contained an iOS kernel exploitation framework with eight exploit methods, allowing it to select different techniques depending on the device model and iOS version.
SlowMist identified iOS 12.0–18.7 and iOS 26.0–26.1 as affected versions in its analysis.
If an exploit succeeded, the code could reportedly escape the normal iOS application sandbox and access information stored in the device’s Keychain.
Private keys and seed phrases among potentially exposed data
According to the investigation, the reported access was not limited to FomoPeek’s own application data.
SlowMist said potentially accessible information included:
- Private keys
- Seed phrases
- Login credentials
- Chat histories
- Files belonging to other applications
- Keychain data
Access to a private key or seed phrase could allow an attacker to control the associated crypto wallet.
SlowMist also said FomoPeek communicated with servers unrelated to its public-facing services and could receive remote instructions. Analysis of plaintext network traffic reportedly showed that the relevant functionality was configured to run automatically at regular intervals.
OKX identifies similar components
OKX separately warned users on September 19 after receiving reports involving stolen crypto assets.
According to OKX’s Chinese-language account, some affected users had previously downloaded FomoPeek version 1.2, and the incidents involved the exposure of private keys.
OKX said its security team worked with SlowMist to examine the application and identified the same two modules, including the reported kernel exploitation framework.
Neither company disclosed the total value of the reportedly stolen assets.
Users advised to replace wallet credentials
SlowMist and OKX advised users who installed or used the affected versions to treat the associated wallet credentials as potentially compromised.
They recommended that users:
- Review wallet activity for unauthorized transactions.
- Generate a new wallet with a fresh private key and seed phrase on a device that never had FomoPeek installed.
- Transfer remaining assets to the new wallet.
- Update the affected device to the latest available iOS version.
- Avoid reinstalling or using the affected application.
Deleting FomoPeek alone would not invalidate a private key or seed phrase that may already have been accessed.
FomoPeek adds to recent crypto security incidents
The case comes amid a series of security incidents affecting different parts of the crypto ecosystem.
In September, SlowMist reported a Liquid Network vulnerability that let attackers mint about 3,998.5 unbacked L-BTC, attributing the incident to a cache collision involving range proofs.
The firm also reported an attack involving a Solidity Pro VS Code extension distributed through Open VSX in August.
Those incidents involved different attack surfaces, while the FomoPeek investigation concerns potentially malicious software installed on iOS devices.
What affected users should check
The investigation specifically concerns FomoPeek versions 1.1–1.2 and the components identified by SlowMist and OKX.
Users who installed either version should review their wallet activity and assume that private keys or seed phrases stored on the affected device may have been exposed.
For self-custody wallets, transferring remaining funds to a newly generated wallet with fresh credentials removes reliance on the potentially compromised wallet keys. Users should avoid reusing any credentials that were present on the affected device.
Also Read: Cronos Proposes Burning CRO With All Revenue While Funding Staking From Its 70B Reserve
