Breaking
TR1 person died and 2 people were injured as a result of an argument in MilasITHurricane Polo alert: US embassy warns citizens in MexicoKRJapanese Prime Minister Takaichi meets with US President Trump in New York... Reconfirmation of joint response to Chinese export regulationsCNLi Peiling was beaten by her ex-husband and sent to the emergency room. Wu Fan lamented that she was kind but suffered from domestic violence for a long time.CNA US F-16 crashed at a German base. The pilot ejected and three fighter jets diverted to land.RUTrump threatens to 'annihilate' Iran if nuclear deal fails, cites post-election timelineUSTechCrunch Founder Summit Announces Boston Agenda with Sessions on Fundraising, AI, and LeadershipAUManchester City Women draw Bayern Munich in controversial Champions League opener amid flare incidentBRWoman is arrested for abandonment of an incapacitated person after leaving children aged 6 and 10 with a 79-year-old in BotucatuCNJiang Wanan's son's use of the exchange student quota caused controversy over privileges. His father only refunded the money but not the quota and was accused of bandit logic.TR1 person died and 2 people were injured as a result of an argument in MilasITHurricane Polo alert: US embassy warns citizens in MexicoKRJapanese Prime Minister Takaichi meets with US President Trump in New York... Reconfirmation of joint response to Chinese export regulationsCNLi Peiling was beaten by her ex-husband and sent to the emergency room. Wu Fan lamented that she was kind but suffered from domestic violence for a long time.CNA US F-16 crashed at a German base. The pilot ejected and three fighter jets diverted to land.RUTrump threatens to 'annihilate' Iran if nuclear deal fails, cites post-election timelineUSTechCrunch Founder Summit Announces Boston Agenda with Sessions on Fundraising, AI, and LeadershipAUManchester City Women draw Bayern Munich in controversial Champions League opener amid flare incidentBRWoman is arrested for abandonment of an incapacitated person after leaving children aged 6 and 10 with a 79-year-old in BotucatuCNJiang Wanan's son's use of the exchange student quota caused controversy over privileges. His father only refunded the money but not the quota and was accused of bandit logic.
BackMalicious iPhone App FomoPeek Linked to $580,000 in Stolen USDT
Malicious iPhone App FomoPeek Linked to $580,000 in Stolen USDT
Urgent
CryptoSlate46 minutes agoTech2 min read

Malicious iPhone App FomoPeek Linked to $580,000 in Stolen USDT

Quick Look

  • Blockchain security firm SlowMist discovered malicious code in versions 1.1 and 1.2 of the FomoPeek iPhone app, which was distributed via Apple's App Store and marketed as a cryptocurrency transaction tracker.
  • The app contained hidden modules enabling iOS sandbox escapes to steal private keys and sensitive data, leading to approximately $579,900 in USDT theft traced to attacker address 0x6d37f2C5e8F8546b648D317295565dA95975f4BB.
  • Crypto platforms including Binance and OKX have warned users to remove the app, update iOS, and move assets to new wallets.

AI-generated summary

Why It Matters

FomoPeek was marketed as a read-only cryptocurrency transaction tracker for Ethereum, Solana, and Tron, distributed through Apple's App Store. Versions 1.1 and 1.2 contained hidden malicious modules not present in the original release or later removed in version 1.3.

Font size

Fomopeek, a malicious iPhone app distributed through Apple’s App Store, has been linked to nearly $580,000 in stolen USDT.

Blockchain security firm SlowMist began investigating the app over the weekend after receiving reports of stolen assets linked to exposed private keys.

Some victims had previously installed versions 1.1 or 1.2 of the Fomopeek app, which was marketed as a read-only tool for tracking large cryptocurrency transactions across Ethereum, Solana and Tron.

What is Fomopeek?

Working with security researchers at crypto exchange OKX, SlowMist found two modules embedded in those versions that had no connection to FomoPeek’s advertised monitoring functions.

One communicated with external command-and-control infrastructure, while the other contained a kernel exploitation framework with eight attack methods that could adjust to the victim’s iPhone model and operating-system version.

A successful exploit could escape Apple’s application sandbox and reach Keychain information and files belonging to other apps. That created a route to locally stored private keys, seed phrases, and login credentials without requiring users to connect a wallet or enter those details into FomoPeek.

SlowMist founder Yu Xian said the risk extended to passwords stored in Apple’s Keychain and encrypted files held by other applications. An attacker who obtained both could potentially unlock wallet credentials and other sensitive information stored on the device.

He explained:

“After a successful attack, the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain (Keychain), and access data files from other apps on the device. Private keys, mnemonic phrases, login credentials, chat histories, files, and other user data stored on the device may all face the risk of leakage as a result. Additionally, the app connects to covert servers unrelated to its public business functions to receive remote instructions.”

The malicious components were not present in FomoPeek’s original release. SlowMist found them in version 1.1, released Sept. 9, and version 1.2 on Sept. 12, before removing them in version 1.3 on Sept. 17.

Researchers also found that the framework could receive instructions from a remote server, including settings that governed whether exploitation was enabled and how often it would run.

Nearly $580,000 stolen

The technical findings were followed by an on-chain trail showing that attackers had already converted that access into losses.

Blockchain analysis firm Salus identified 0x6d37f2C5e8F8546b648D317295565dA95975f4BB as the attacker address and estimated proceeds from the incident at about 579,900 USDT.

Salus traced 401,028 USDT through three intermediary addresses to FixedFloat. Another 20,000 USDT moved in two transactions through deposit addresses before being consolidated into a KuCoin hot wallet.

A further 111,458 USDT was routed through an address Salus associated with an escrow platform, while another 10,000 USDT passed through the CCE mixing service before reaching addresses linked to an escrow service.

Salus said its analysis also indicated that the group behind the FomoPeek incident had been involved in a separate private-key theft in June. Investigators are still determining whether the same technique was used in that attack.

Crypto platforms warn users as custody debate returns

The losses and the potential reach of the exploit have prompted warnings from several crypto platforms, including Binance, OKX, Gate, Bitget Wallet and Rabby.

Binance warned:

“The third-party app FomoPeek (versions 1.1–1.2) contains malicious code that can exploit iOS system vulnerabilities to gain the highest level of device privileges, potentially accessing sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, files, and more. Please note that this type of malware targets the device itself. If an attack succeeds, data from all apps on the affected device may be accessed.”

In light of this, the crypto firms have broadly issued the same guidance, urging crypto users to remove FomoPeek, update iOS, and move assets to newly created wallets on devices where the compromised app was never installed.

These fresh credentials are necessary because deleting the app or patching the operating system cannot invalidate a private key that may already have been copied.

Meanwhile, the incident also comes two months after on-chain investigator ZachXBT argued that a separate iPhone dedicated to crypto could be preferable to existing hardware wallets for storing funds and signing transactions.

His recommendation relied on keeping the device isolated from everyday browsing, messaging, and other activity that could expand the attack surface.

FomoPeek exposes a different weakness in that model. The app was itself built for crypto users and distributed through Apple’s official marketplace, yet researchers say it contained tooling capable of breaching the barriers separating applications on the device.

That does not establish that dedicated crypto iPhones are inherently less secure than hardware wallets. However, it shows that isolation offers limited protection if software installed on the device can compromise the operating system itself.

For affected users, the immediate focus is now on containing further losses and tracing the stolen funds.

Salus continues to follow addresses linked to the remaining proceeds, while Binance and other platforms monitor for deposits that could give investigators another opportunity to track or restrict the movement of the stolen USDT.

What to Watch

AI outlook — possibilities, not facts

  • Apple will remove FomoPeek from the App Store and issue a security advisory.

    Very likely · Within days

  • More victims will come forward as blockchain tracing continues.

    Likely · Within weeks

Open Questions

  • Who is behind the FomoPeek attack group?
  • Are there other compromised apps in the App Store using similar techniques?
  • Has Apple taken action to remove the app or improve App Store screening?
  • What specific iOS vulnerabilities were exploited?

Related Topics

This article was originally published by CryptoSlate.

Related Stories

UN Security Council to Hear from AI Leaders on Risks of Uncontrolled Systems
Developing·

UN Security Council to Hear from AI Leaders on Risks of Uncontrolled Systems

The UN Security Council will hear briefings from AI executives including Sam Altman, Dario Amodei, Yoshua Bengio, and Clément Delangue on risks posed by artificial intelligence, such as autonomous cyberattacks, election interference, and weapon design. The session, organized by France, also includes invited statements from Chinese firms DeepSeek and Moonshot. Amodei advocated for slowing AI development and restricting chip exports to China, while Trump dismissed AI risks as a 'hoax'.

Decrypt
2 min read
OpenAI launches GPT-6 Sol and Luna, positions them as cheaper alternatives to GPT-6 Astra and Anthropic's Claude models
BREAKING·

OpenAI launches GPT-6 Sol and Luna, positions them as cheaper alternatives to GPT-6 Astra and Anthropic's Claude models

OpenAI released GPT-6 Sol and GPT-6 Luna models on Tuesday, minutes after Anthropic launched Claude Opus 5.5. Sol and Luna are positioned as cheaper, faster alternatives to GPT-6 Astra, with API costs reduced by 50% compared to GPT-5.6 promotional rates. OpenAI claims Sol outperforms Claude Opus 5 on AutomationBench and Agents' Last Exam at significantly lower cost per task, and both models are now available in ChatGPT Work and Codex for paid tiers, with Luna also reaching free users via desktop app.

Decrypt
2 min read
Anthropic launches Claude Opus 5.5, claiming performance parity with pricier Fable 5.1 at lower cost
Developing·

Anthropic launches Claude Opus 5.5, claiming performance parity with pricier Fable 5.1 at lower cost

Anthropic released Claude Opus 5.5, stating it performs at the level of its priciest flagship model Fable 5.1 on most tasks while costing 20% less to run than Opus 5 and 60% less than Fable 5.1. The model leads in agentic coding benchmarks like Terminal-Bench 4.0 and FrontierCode, and is now live across AWS, Google Cloud, and Azure, with Sonnet 5.5 and Haiku 5.5 to follow.

Decrypt
2 min read
More on this topicfomopeek