Newsroom
24 September, 2026 / News / AI / Tags: slowmist, fomopeek, malicious, versions, kernel

Security researchers linked versions of the App Store app FomoPeek to the theft of almost $580,000 in crypto after finding it used iOS kernel exploits to access data from other apps
A malicious application distributed through Apple’s App Store under the name FomoPeek has been connected to the theft of nearly $580,000 in cryptocurrency. Blockchain security firm SlowMist reported that specific versions of the app contained modules capable of exploiting iOS kernel vulnerabilities, escaping the system sandbox, and accessing sensitive data from other applications, including crypto wallets and note-taking tools.
The investigation, conducted jointly with the OKX security team, began after reports from users who lost assets and had previously installed the affected software. SlowMist identified the primary attacker address linked to the incident, which received approximately 579,984 USDT. That address became active on September 15, with funds moved across multiple blockchain networks before consolidation and transfers through services including FixedFloat, KuCoin and cce.cash.
Versions 1.1, released on September 9, and 1.2, released on September 12, included two malicious modules named apptrace and libapptracecore along with an exploit framework containing eight attack methods. The framework declared support for iOS versions from 12.0 to 18.7.2 and from 26.0 to 26.1. It selected methods based on device model and operating system version to gain elevated privileges, access Keychain data, and reach files belonging to other apps.
A remote server controlled the exploitation and data collection functions, which activated when the app launched. No interaction with Safari or any webpage was required. In a controlled test environment, researchers confirmed the framework’s ability to collect application data, including the Apple Notes container. The server configuration listed 19 wallet and note apps as targets, among them MetaMask, Trust Wallet, SafePal, OKX Wallet and Apple Notes.
SlowMist stated that while the framework demonstrated the capacity to gather such data, this did not prove that private keys or seed phrases were extracted from every named wallet in every case. Version 1.3, released on September 17, removed the malicious components.
Early reports had associated the malware with the official FOMO iOS application. SlowMist later clarified that the malicious software belonged to FomoPeek, a separate app marketed as a read-only crypto wallet monitor, and was not part of FOMO’s official product. The distinction matters for users assessing whether they installed the compromised software. The affected versions remained available on the App Store between September 9 and September 17.
Some descriptions noted similarities between the malicious component and the DarkSword malware family, which has previously been linked to efforts to steal seed phrases and private keys.
SlowMist advised anyone who installed FomoPeek versions 1.1 or 1.2 to treat potentially exposed wallet credentials as compromised. The firm recommended creating a new wallet on an unaffected device and transferring assets to it. Enabling Lockdown Mode or uninstalling the application after the fact cannot recover data already copied off the device by an attacker.
The number of devices successfully exploited and the precise share of the $580,000 total attributable solely to FomoPeek have not been disclosed. On-chain tracing of the remaining funds continues.









