iPhone App Leads to Crypto Theft of Half a Million Euros - Here's What We Know Now
The iPhone app FomoPeek has been linked to the theft of nearly $580,000 (approximately €500,000) in crypto. Researchers found hidden software in versions 1.1 and 1.2 that could breach the security of iPhones and read crypto keys from other apps.
In Brief:
FomoPeek was available in the App Store and posed as an innocent crypto tracker.
The app could read data from Apple's Keychain and other apps after a successful attack.
Users of versions 1.1 and 1.2 need to create new keys on a clean device and move their crypto.
Confirmed App Attack Follows Safari Warning
Yesterday, there was talk of a potentially dangerous Safari vulnerability. In that reported attack, a malicious webpage could breach the browser's shielding. This would put recovery phrases and crypto keys at risk.
The case surrounding FomoPeek seems unrelated but shows a similar danger. Here, the attack did not start with a malicious website but with an app from Apple's official store.
SlowMist and the security team of crypto exchange OKX actually found the malicious code. There is no indication that both reports concern the same vulnerability or attackers.
SlowMist
@SlowMist_Team
·Follow
🚨 SlowMist TI Alert: FomoPeek App v1.1--1.2 Asset Theft 🚨 We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek Show more
7:26 AM · Sep 19, 2026
246
Reply
Copy link
Read 50 replies
Innocent Tracker Breached Its Shielding
FomoPeek was marketed as a tracking app that only read public data. Users could track large transactions on Solana, Ethereum, and TRON without linking a wallet or entering a recovery phrase.
However, according to SlowMist's warning, versions 1.1 and 1.2 contained two hidden components. One of them had eight ways to exploit vulnerabilities in iOS. The app could automatically choose an attack that matched the device and the iOS version used.
After a successful attack, FomoPeek could escape the digital shielding that normally separates apps from each other. The software could then read Apple's Keychain and files from other apps.
This put private keys, recovery phrases, and login credentials at risk, even if they were never entered in FomoPeek itself.
Nearly $580,000 (approximately €500,000) in crypto was sent to the attackers' main address. The total amount of damage is not known.
International Cyber Digest
@IntCyberDigest
·Follow
‼️ BREAKING: An app on Apple's official App Store was serving iPhone users malware designed to steal crypto wallet keys. SlowMist and OKX found FomoPeek versions 1.1 and 1.2, distributed Sept 9--17, hid a kernel exploit framework built to escape the iOS sandbox, decrypt the Show more
4:59 PM · Sep 22, 2026
1.3K
Reply
Copy link
Read 37 replies
New Wallet Must Be on Clean Device
Simply deleting the app is not enough. A stolen key remains usable. SlowMist therefore advises creating a new crypto wallet with new keys on a trusted device that has never had FomoPeek installed.
After that, funds should be moved as quickly as possible. Users are also advised to update iOS and not to reinstall FomoPeek.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Apple and Google Strengthen Talent in Payment and Web3 Strategies, Stablecoin Knowledge Required for Hiring

Bitpace Partners with Fireblocks for Cross-Border Payments with Stablecoins

Hyperliquid open interest reaches record $18 billion: What’s driving activity?
How Did a Hacker Create 46 Billion Fake Bitcoin in the Symbiosis Exploit? Decodes Bitcoin Hacker With WEEX Now
How two Symbiosis bridge bugs let a hacker mint 46.1 billion unbacked syBTC, drain Bitcoin pools and expose critical bridge risks.

This Cycle May Not Be Led by Bitcoin?

Yield Curve Approaches Inversion, TGA and Fed Tools Become New Focus in US Treasury Market

AI Agent Battle Begins: Amazon Blocks Meta's AI Agent, E-commerce Entry War Escalates
![[Interview] Lee Yun-ho, CEO of KIP: "We need to set the stage before the STO market opens... sharing RWA know-how with financial companies"](/public-static/3_1a7f0699b3.png?format=avif)
[Interview] Lee Yun-ho, CEO of KIP: "We need to set the stage before the STO market opens... sharing RWA know-how with financial companies"

Coinmetrics Report: The Competition of Tokenized Stocks and Their Future Development Path

Transfer of 27,372 ETH: Does FTX Still Have $400 Million in Liquidation Ammo?

In 12 tests, PQLN makes Bitcoin's Lightning Network communication levels resistant to quantum computers

Brevo Hacking: After Trezor, Paymium Customer Data Leaked

What is Fin.com? Understanding Cross-Border Payment Infrastructure via API

Proposal to Expropriate Digital Assets in Special Cases

Circle Foundation launches first U.S. grants for AI

Uniswap (UNI) Price Jumps Toward $10 as CME Futures Launch Nears: What Traders Need to Know

The Surge of AVAX: 'Wall Street on the Chain' Becomes the New Main Line

XRPL fixes critical pre-mainnet flaw, but client apps remain at risk

CME Plans BCH and UNI Futures on October 19 | WEEX TradFi Daily Brief (September 23, 2026)
Global markets on September 23 focus on a Nasdaq high and an expansion of crypto futures. The Nasdaq closed higher on September 22 for a second straight closing high. Memory names such as Micron and SanDisk plus AI hardware lifted risk appetite. Brent eased to about $98 and WTI to about $94.6. Bitcoin was near $86,200 and Ethereum near $2,750. Investors are watching CME’s planned October 19 BCH/UNI futures and the impact of delayed compute-futures review on NVDA and CME.

Kakao Pay and Kakao Bank Partner with Fireblocks to Begin Verification of KRW Stablecoin Project

On the Same Day, Three Conditional Approvals: OCC Standardizes Stablecoin Bank Licensing

Bernstein Research Report: Why Can Gold Still Surge to $5,700 Even with Continued Rate Hikes by the Fed?

Masayoshi Son is borrowing money again, betting billions on OpenAI

Cryptocurrencies Will 'Devour' AI, Says Cardano Founder

Coinbase, Ripple, and a16z Fund Plan to Revive Clarity After Its Failure

Pi Network KYC and wallet fixes target over 900,000 users

Inside Coinbase’s $250 Billion Playbook for Post-Quantum Bitcoin Custody

The IMF opens an office in Venezuela to supervise an economy that has already migrated to USDT

Changes in SAS, crypto, and activity definition: the Government eases procedures to open a business

Zcash's shielded activity reached a four-year high
Apple and Google Strengthen Talent in Payment and Web3 Strategies, Stablecoin Knowledge Required for Hiring
Bitpace Partners with Fireblocks for Cross-Border Payments with Stablecoins
Hyperliquid open interest reaches record $18 billion: What’s driving activity?
How Did a Hacker Create 46 Billion Fake Bitcoin in the Symbiosis Exploit? Decodes Bitcoin Hacker With WEEX Now
How two Symbiosis bridge bugs let a hacker mint 46.1 billion unbacked syBTC, drain Bitcoin pools and expose critical bridge risks.





