BNB $791.98 +0.75%
XRP $1.62 +6.80%
ETH $2,759.26 +1.19%
BTC $86,514.48 +1.49%
BNB $791.98 +0.75%
XRP $1.62 +6.80%
ETH $2,759.26 +1.19%
BTC $86,514.48 +1.49%
BREAKING
stable coins

FomoPeek iOS App Steals $580K in Crypto Before Apple Takes Action

FomoPeek iOS App Drained Nearly $580K in Crypto Before Apple Pulled It
FomoPeek iOS App Drained Nearly $580K in Crypto Before Apple Pulled It

Community Trust ScoreVerified

92%
Real
Verified12 votes
Updated 1 hour ago

A malicious app made it onto Apple’s App Store. It stole close to $580,000 in cryptocurrency before anyone caught it. And the people who built it clearly knew what they were doing.

Blockchain security firm SlowMist broke the story, working alongside the OKX security team after users started reporting asset theft. The investigation found that FomoPeek — the name of the app — carried two harmful modules buried inside it. Those modules exploited flaws in iOS’s security architecture, letting the app gain elevated privileges and dig into Keychain data. That’s the encrypted storage layer where iPhones keep passwords, private keys, and other sensitive credentials. Once the app got in there, cryptocurrency wallets were basically exposed. SlowMist traced the problem to two specific versions: one released September 9, another on September 12. A third version, 1.3, dropped on September 17 and had the malicious components removed — but by then, the damage was done.

The hacker’s primary address received around 579,984 USDT.

Advertisement

That address went active on September 15, just days after the compromised versions hit the App Store. SlowMist’s on-chain analysis tracked the stolen funds moving across multiple blockchain networks, then getting consolidated and pushed through a series of addresses and services. Some of it ended up on FixedFloat. Some went to KuCoin. Some moved through cce.cash. The firm is still tracing additional transfers. It’s a messy trail, probably intentional, and recovering dispersed assets from this kind of multi-hop laundering is genuinely hard.

Eight Attack Methods, Broad iOS Coverage

The exploit framework wasn’t a quick, sloppy job. FomoPeek’s attack toolkit included eight separate methods, and the app targeted iOS versions ranging from 12.0 all the way up to 18.7.2, plus 26.0 to 26.1. That’s a wide net. Covering that many iOS versions takes real effort and suggests the people behind it wanted to hit as many devices as possible, not just a narrow slice of users running one specific software build.

What makes this particularly ugly is the sandbox escape. iOS apps are supposed to be isolated from each other — one app can’t just read another app’s files. FomoPeek broke that. It accessed files belonging to other applications on the same device, not just its own data. Getting out of Apple’s sandbox is technically difficult, and the fact that FomoPeek pulled it off points to a pretty sophisticated operation. Not some script kiddie. Someone who understood iOS internals.

The joint investigation between SlowMist and OKX’s security team was what actually pieced this together. Their combined on-chain and technical analysis traced the main hacker address and mapped out how nearly 580,000 USDT moved through the system. Still, tracing funds is one thing. Getting them back is another.

Apple and OKX Haven’t Said a Word

Apple, SlowMist, and OKX were all contacted for comment. None of them responded. That silence is frustrating, because there are real questions here that don’t have answers yet. How did FomoPeek pass App Store review? What specifically did the malicious modules look like in the binary? What’s Apple doing to catch this kind of exploit before it reaches users? Unclear.

The app was live in compromised form for roughly a week — September 9 through September 17. That’s not a long window, but it was long enough. Users who downloaded either the September 9 or September 12 versions and had crypto wallets on their devices were at risk. Some of them lost money. The exact number of victims isn’t specified in SlowMist’s findings, and the firm didn’t break down individual losses.

What’s clear is that the Keychain access was the critical piece. Crypto users often store seed phrases or private keys in password managers or apps that rely on Keychain for protection. If an app can reach into that layer, it can grab everything it needs to drain a wallet without the user doing anything wrong. No phishing link. No fake website. Just a malicious app running quietly in the background.

App stores — Apple’s included — have long been pitched as safer than sideloading or browser-based installs. The FomoPeek case is a direct hit to that argument. Vetting processes exist, but they clearly didn’t catch this one. And the funds are still moving.

SlowMist says it’s continuing to monitor the transfers.

Frequently Asked Questions

What iOS versions were targeted by the FomoPeek exploit?

The exploit framework targeted iOS versions from 12.0 up to 18.7.2, as well as versions 26.0 to 26.1, covering a broad range of devices.

Which platforms received the stolen funds from FomoPeek?

SlowMist’s on-chain analysis traced stolen funds moving through FixedFloat, KuCoin, and cce.cash, among other addresses still under investigation.

Why It Matters

The emergence of the FomoPeek app highlights the ongoing vulnerabilities in mobile application security, particularly within the cryptocurrency space, where users are often targeted by sophisticated attacks. The incident underscores the importance of robust security measures and thorough vetting processes by app stores, as the theft of significant amounts of crypto can erode consumer trust and potentially impact market dynamics. As the crypto ecosystem continues to grow, ensuring the integrity of platforms that facilitate transactions and holdings will be crucial for safeguarding user assets and fostering broader adoption.

Community Trust IndexModerate Confidence
92%
Real
Real92%8%Fake
12 community signals

James Thorp

James Thorp is a passionate crypto journalist from South Africa specializing in Litecoin, Dash, and emerging digital assets. With years of experience covering the crypto markets, James delivers in-depth analysis and breaking news on altcoins, blockchain adoption, and decentralized payment networks for The Currency Analytics.

Advertisement

Related Stories