stable coins

Story: FomoPeek iOS App Steals $580K in Crypto Before Apple Takes Action

By James Thorp

1 / 15

Eight Attack Methods, Broad iOS Coverage. The exploit framework wasn't a quick, sloppy job. FomoPeek's attack toolkit included eight…

2 / 15

Apple and OKX Haven't Said a Word. Apple, SlowMist, and OKX were all contacted for comment. None of them responded.

3 / 15

A malicious app made it onto Apple's App Store. It stole close to $580,000 in cryptocurrency before anyone caught it. And the people who built it clearly knew what they were doing.

4 / 15

Blockchain security firm SlowMist broke the story, working alongside the OKX security team after users started reporting asset theft.

5 / 15

The hacker's primary address received around 579,984 USDT.

6 / 15

That address went active on September 15, just days after the compromised versions hit the App Store.

7 / 15

The exploit framework wasn't a quick, sloppy job. FomoPeek's attack toolkit included eight separate methods, and the app targeted iOS versions ranging from 12.

8 / 15

What makes this particularly ugly is the sandbox escape. iOS apps are supposed to be isolated from each other — one app can't just read another app's files. FomoPeek broke that.

9 / 15

See also: Darksword iOS Exploit Threatens Crypto Wallets as Apple Faces $1.8M Lawsuit

10 / 15

The joint investigation between SlowMist and OKX's security team was what actually pieced this together.

11 / 15

Apple, SlowMist, and OKX were all contacted for comment. None of them responded. That silence is frustrating, because there are real questions here that don't have answers yet.

12 / 15

The app was live in compromised form for roughly a week — September 9 through September 17. That's not a long window, but it was long enough.

13 / 15

What's clear is that the Keychain access was the critical piece. Crypto users often store seed phrases or private keys in password managers or apps that rely on Keychain for…

14 / 15

See also: Prediction Markets Set to Soar to $10 Trillion by 2035, Driven by Crypto Contracts

15 / 15

App stores — Apple's included — have long been pitched as safer than sideloading or browser-based installs. The FomoPeek case is a direct hit to that argument.

The Currency Analytics

Want the full story?