Loading market data...
Back to Feed
CRYPTO NEWS

Malicious iOS App FomoPeek Linked to $580K Crypto Theft

Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
AI-generated editorial illustration for Malicious iOS App FomoPeek Linked to $580K Crypto Theft
AI-generated editorial illustration.
Visit source

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.

$580K$580,000USDT

Summary

A malicious iOS app named FomoPeek, distributed through Apple's App Store, has been linked to nearly $580,000 in stolen cryptocurrency. Security firm SlowMist investigated the app, finding it contained kernel exploits that bypassed Apple's sandbox to access sensitive wallet data from other apps. The malicious components were present in versions released on Sept. 9 and 12, but removed in version 1.3 on Sept. 17.

Why it matters

This incident highlights the risks of malicious apps exploiting iOS vulnerabilities to steal crypto assets directly from users’ devices without requiring interaction with webpages. SlowMist’s findings underscore the threat such exploits pose to wallet security and the potential for significant financial losses.

Key context

SlowMist’s investigation began after reports from victims who suffered asset theft and had installed affected FomoPeek versions. The exploit framework supports iOS versions from 12.0 to 18.7.2 and targeted 19 wallet and note apps including MetaMask, Trust Wallet, SafePal, OKX Wallet, and Apple Notes. The hacking involved elevated privileges and data collection controlled remotely by a server.

Key numbers and entities

The hacker’s primary address received about 579,984 USDT. Funds were transferred through multiple blockchain networks and partially moved to services including FixedFloat, KuCoin, and cce.cash. SlowMist collaborated with the OKX security team for the investigation. Apple and OKX did not comment before publication.

What remains unclear

It is unknown whether private keys or seed phrases were extracted from all targeted wallets. The identity of the attacker and the full extent of the stolen assets remain under investigation, with SlowMist continuing to trace additional addresses. There is no information on Apple's response or actions following the discovery.

Read the original source

> JOIN THE ALPHA

Get a free crypto news briefing in your inbox. No fake subscriber counts — just the latest source-backed headlines we cache.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]