Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Blockchain News

SlowMist Warns FomoPeek iOS Versions May Expose Crypto Wallet Keys 

SlowMist and OKX found malicious components in FomoPeek versions 1.1–1.2 that could expose sensitive iOS data, including private keys and seed phrases.

Written By Isha Chavda
Edited by Sujha Sundararajan
Published 8 seconds ago
Make The Crypto Times preferred on GoogleGoogle
SlowMist Warns FomoPeek iOS Versions May Expose Crypto Wallet Keys 

Key Highlights

  • SlowMist received reports of crypto assets being stolen from users who had installed FomoPeek versions 1.1–1.2.
  • A joint investigation with OKX identified malicious components inside the affected versions.
  • Researchers found an iOS kernel exploitation framework containing eight exploit methods.

SlowMist has warned that FomoPeek versions 1.1–1.2 contained malicious components that could expose sensitive information on affected iOS devices.

In a September 19 post on X, the blockchain security firm said it had received multiple reports of users’ crypto assets being stolen, with some affected users having previously installed FomoPeek versions 1.1–1.2.

🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨

We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek… pic.twitter.com/g4tmSe376n

— SlowMist (@SlowMist_Team) September 19, 2026

SlowMist and the OKX security team later analyzed the affected versions and identified code that was unrelated to the application’s stated functions.

The investigation found an iOS kernel exploitation framework and network connections that SlowMist said were linked to the reported malicious activity.

Malicious modules found inside FomoPeek

SlowMist said two modules discovered in the application were unrelated to FomoPeek’s advertised functions.

One contained an iOS kernel exploitation framework with eight exploit methods, allowing it to select different techniques depending on the device model and iOS version.

SlowMist identified iOS 12.0–18.7 and iOS 26.0–26.1 as affected versions in its analysis.

If an exploit succeeded, the code could reportedly escape the normal iOS application sandbox and access information stored in the device’s Keychain.

Private keys and seed phrases among potentially exposed data

According to the investigation, the reported access was not limited to FomoPeek’s own application data.

SlowMist said potentially accessible information included:

  • Private keys
  • Seed phrases
  • Login credentials
  • Chat histories
  • Files belonging to other applications
  • Keychain data

Access to a private key or seed phrase could allow an attacker to control the associated crypto wallet.

SlowMist also said FomoPeek communicated with servers unrelated to its public-facing services and could receive remote instructions. Analysis of plaintext network traffic reportedly showed that the relevant functionality was configured to run automatically at regular intervals.

OKX identifies similar components

OKX separately warned users on September 19 after receiving reports involving stolen crypto assets.

According to OKX’s Chinese-language account, some affected users had previously downloaded FomoPeek version 1.2, and the incidents involved the exposure of private keys.

OKX said its security team worked with SlowMist to examine the application and identified the same two modules, including the reported kernel exploitation framework.

Neither company disclosed the total value of the reportedly stolen assets.

Users advised to replace wallet credentials

SlowMist and OKX advised users who installed or used the affected versions to treat the associated wallet credentials as potentially compromised.

They recommended that users:

  1. Review wallet activity for unauthorized transactions.
  2. Generate a new wallet with a fresh private key and seed phrase on a device that never had FomoPeek installed.
  3. Transfer remaining assets to the new wallet.
  4. Update the affected device to the latest available iOS version.
  5. Avoid reinstalling or using the affected application.

Deleting FomoPeek alone would not invalidate a private key or seed phrase that may already have been accessed.

FomoPeek adds to recent crypto security incidents

The case comes amid a series of security incidents affecting different parts of the crypto ecosystem.

In September, SlowMist reported a Liquid Network vulnerability that let attackers mint about 3,998.5 unbacked L-BTC, attributing the incident to a cache collision involving range proofs.

The firm also reported an attack involving a Solidity Pro VS Code extension distributed through Open VSX in August.

Those incidents involved different attack surfaces, while the FomoPeek investigation concerns potentially malicious software installed on iOS devices.

What affected users should check

The investigation specifically concerns FomoPeek versions 1.1–1.2 and the components identified by SlowMist and OKX.

Users who installed either version should review their wallet activity and assume that private keys or seed phrases stored on the affected device may have been exposed.

For self-custody wallets, transferring remaining funds to a newly generated wallet with fresh credentials removes reliance on the potentially compromised wallet keys. Users should avoid reusing any credentials that were present on the affected device.

Also Read: Cronos Proposes Burning CRO With All Revenue While Funding Staking From Its 70B Reserve

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Blockchain
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Cronos Proposes Burning CRO With All Revenue While Funding Staking From Its 70B Reserve
Cronos Proposes Burning CRO With All Revenue While Funding Staking From Its 70B Reserve
The Solana logo with its gradient icon illuminated on a dark textured wall.
Solana (SOL) Price Prediction 2026, 2027–2030: Will It Hit $300 High? 
A metallic Hyperliquid (HYPE) coin with a green stylized symbol sitting on a dark surface.
Hyperliquid (HYPE) Price Prediction 2026, 2027–2030: Is $200 the Next Stop?
Physical crypto coins, Indian Rupee stacks, and handcuffs arranged in front of a Goa Police insignia and Panaji sign post.
ED Charges 5 More in Goa Drug Case Over ₹3.96 Crore Crypto Laundering Route
The yellow and black Binance logo displayed on a sign.
Binance to Launch 24/7 FX Perpetual Futures on Sept. 21

Find Us on Socials

You may also like

a16z-Backed Linera Ceases Operations After Sonar Sale Falls Short

a16z-Backed Linera Ceases Operations After Sonar Sale Falls Short

Gold Zcash cryptocurrency coin with Z symbol against a digital blockchain network background

Zcash NU7 Mainnet Upgrade Targets November 5 With 25-Second Blocks

Hooded hacker using a Chainanalysis-branded laptop with flags of North Korea and Iran in the background.

Blockchain Dead Drops Surge 440% as State-Linked Actors Expand Use 

Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.

Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information