
A malicious iOS app named FomoPeek, distributed through Apple's App Store, was found to contain kernel exploits that stole nearly $580,000 in cryptocurrency by accessing wallet data and Keychain information, according to a SlowMist investigation with OKX security team.
AI-generated summary
The FomoPeek app was distributed through Apple's App Store and contained malicious modules designed to exploit iOS kernel vulnerabilities to steal cryptocurrency wallet data.
A malicious iOS app distributed through Apple’s App Store has been linked to nearly $580,000 in stolen crypto after researchers found it contained multiple kernel exploits capable of escaping Apple’s sandbox and accessing sensitive wallet data.
According to an investigation published by blockchain security firm SlowMist, the app, called FomoPeek, introduced two malicious modules that could exploit iOS vulnerabilities, gain elevated privileges and access Keychain data and files belonging to other apps.
SlowMist said the affected versions were released on Sept. 9 and Sept. 12, while version 1.3, released Sept. 17, removed the malicious components.
SlowMist said its investigation, conducted with the OKX security team, began after it received reports from users who had suffered asset theft and found that some had previously installed the affected FomoPeek versions.
The exploit framework included eight attack methods and declared support for iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1.
SlowMist’s onchain analysis identified a primary hacker address associated with the incident that received about 579,984 USDT. The firm said the address became active on Sept. 15 and that the stolen funds involved multiple blockchain networks before being consolidated and transferred through several addresses and services.
SlowMist said portions of the funds were transferred toward services including FixedFloat, KuCoin and cce.cash, while other funds were dispersed through additional addresses that the firm continued to trace.
Cointelegraph reached out to Apple, SlowMist and OKX for comment but did not receive a response before publication.
AI outlook — possibilities, not facts
Apple will likely enhance its app review process to detect similar kernel-level exploits in future submissions
Likely · Within weeks
iOS users with cryptocurrency wallets may increase adoption of hardware wallets or air-gapped storage solutions
Possible · Within months

XRP Ledger validators have conditionally activated the BatchV1_1 amendment for Sept. 29 at 14:06:41 UTC, converting a previously identified security flaw into a live test of the network's amendment process. The fix addresses a critical authorization vulnerability that could have allowed unauthorized transactions if activated on mainnet. Activation depends on maintaining over 80% validator support for two weeks, with current support at 30 of 35 trusted validators. The update enables atomic transaction flows while requiring client software upgrades to avoid consensus disruption.

Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman are expected to brief the UN Security Council on Wednesday on AI risks and international security implications, with Hugging Face CEO Clément Delangue and Yoshua Bengio also participating. Chinese AI firms DeepSeek and Moonshot have been invited to speak, though DeepSeek's founder will not attend. France is convening the meeting as global concerns grow over advanced AI systems and potential loss of human control.

Blockchain security firm SlowMist discovered malicious code in versions 1.1 and 1.2 of the FomoPeek iPhone app, which was distributed via Apple's App Store and marketed as a cryptocurrency transaction tracker. The app contained hidden modules enabling iOS sandbox escapes to steal private keys and sensitive data, leading to approximately $579,900 in USDT theft traced to attacker address 0x6d37f2C5e8F8546b648D317295565dA95975f4BB. Crypto platforms including Binance and OKX have warned users to remove the app, update iOS, and move assets to new wallets.

The UN Security Council will hear briefings from AI executives including Sam Altman, Dario Amodei, Yoshua Bengio, and Clément Delangue on risks posed by artificial intelligence, such as autonomous cyberattacks, election interference, and weapon design. The session, organized by France, also includes invited statements from Chinese firms DeepSeek and Moonshot. Amodei advocated for slowing AI development and restricting chip exports to China, while Trump dismissed AI risks as a 'hoax'.

White-hat actors have moved 40.71 BTC worth $3.31 million from the Coldcard hardware wallet exploit into a recovery effort labeled 'Crypto Recovery Trust,' according to Galaxy Research. The funds represent 2.8% of the total $130 million theft stemming from a 2021 firmware flaw that generated weak seed phrases on Coinkite devices.

OpenAI released GPT-6 Sol and GPT-6 Luna models on Tuesday, minutes after Anthropic launched Claude Opus 5.5. Sol and Luna are positioned as cheaper, faster alternatives to GPT-6 Astra, with API costs reduced by 50% compared to GPT-5.6 promotional rates. OpenAI claims Sol outperforms Claude Opus 5 on AutomationBench and Agents' Last Exam at significantly lower cost per task, and both models are now available in ChatGPT Work and Codex for paid tiers, with Luna also reaching free users via desktop app.