iPhone App Leads to Crypto Theft of Half a Million Euros - Here's What We Know Now
The iPhone app FomoPeek has been linked to the theft of nearly $580,000 (approximately €500,000) in crypto. Researchers found hidden software in versions 1.1 and 1.2 that could breach the security of iPhones and read crypto keys from other apps.
In Brief:
FomoPeek was available in the App Store and posed as an innocent crypto tracker.
The app could read data from Apple's Keychain and other apps after a successful attack.
Users of versions 1.1 and 1.2 need to create new keys on a clean device and move their crypto.
Confirmed App Attack Follows Safari Warning
Yesterday, there was talk of a potentially dangerous Safari vulnerability. In that reported attack, a malicious webpage could breach the browser's shielding. This would put recovery phrases and crypto keys at risk.
The case surrounding FomoPeek seems unrelated but shows a similar danger. Here, the attack did not start with a malicious website but with an app from Apple's official store.
SlowMist and the security team of crypto exchange OKX actually found the malicious code. There is no indication that both reports concern the same vulnerability or attackers.
SlowMist
@SlowMist_Team
·Follow
🚨 SlowMist TI Alert: FomoPeek App v1.1--1.2 Asset Theft 🚨 We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek Show more
7:26 AM · Sep 19, 2026
246
Reply
Copy link
Read 50 replies
Innocent Tracker Breached Its Shielding
FomoPeek was marketed as a tracking app that only read public data. Users could track large transactions on Solana, Ethereum, and TRON without linking a wallet or entering a recovery phrase.
However, according to SlowMist's warning, versions 1.1 and 1.2 contained two hidden components. One of them had eight ways to exploit vulnerabilities in iOS. The app could automatically choose an attack that matched the device and the iOS version used.
After a successful attack, FomoPeek could escape the digital shielding that normally separates apps from each other. The software could then read Apple's Keychain and files from other apps.
This put private keys, recovery phrases, and login credentials at risk, even if they were never entered in FomoPeek itself.
Nearly $580,000 (approximately €500,000) in crypto was sent to the attackers' main address. The total amount of damage is not known.
International Cyber Digest
@IntCyberDigest
·Follow
‼️ BREAKING: An app on Apple's official App Store was serving iPhone users malware designed to steal crypto wallet keys. SlowMist and OKX found FomoPeek versions 1.1 and 1.2, distributed Sept 9--17, hid a kernel exploit framework built to escape the iOS sandbox, decrypt the Show more
4:59 PM · Sep 22, 2026
1.3K
Reply
Copy link
Read 37 replies
-- Price
New Wallet Must Be on Clean Device
Simply deleting the app is not enough. A stolen key remains usable. SlowMist therefore advises creating a new crypto wallet with new keys on a trusted device that has never had FomoPeek installed.
After that, funds should be moved as quickly as possible. Users are also advised to update iOS and not to reinstall FomoPeek.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

CFTC's Seliger Urges Preparation for Asset Tokenization Expansion

How Crypto Stopped Waiting for Congress and Learned to Love the Regulators

Backpack CEO Plans to Bring the Entire Stock Market to Solana

Solana’s Alpenglow upgrade reaches devnet with 150ms finality target

DoubleZero to Return 45% of Shred Service Revenue, Firmly Supporting Solana

Solana Foundation Appoints Former Binance CMO and Polygon Executive for Institutional Strategy

According to Ripple's CEO, XRP's utility is not always the best for payments

Solana DEX volume spike hides circular trades, and automated bots are blamed

30-Year Mortgage Rate Rises to 7.45%

Block Adds Bitcoin Lightning to AI Agents' Payments

Ansem Optimistic About Solana DeFi, Believes It Is Undervalued

DoubleZero Launches Dedicated Market Data Source for Hyperliquid

Solana Foundation Appoints Former Binance and Polygon Executives to Drive Institutional Adoption and Payments Business

Bitcoin, Ethereum, Solana: How Institutions Manage Their Cryptos

Solana Dominates Ethereum on Fees, but ETH Maintains Lead on Burn

BTC Share Drops to 44.2%, ETH Share in the Americas Rises to 38.5%

Hack VC Co-founder Has Not Contacted Hsin-Ju for Over 10 Months, Overseas Use of USD Stablecoin Considered

Crypto: NEAR Partners with Ondo for Tokenized and Confidential U.S. Stocks

MoonPay Acquires North Capital for US Securities Licenses

SharpLink CEO Predicts AI-Driven Trading Will Focus on Ethereum Ecosystem

071 Labs to Host 'PERPDEX NIGHT' in Gangnam on October 1

ETH, SOL burn totals do not reflect true supply change

Solana Alpenglow Upgrade Enters Public Testnet, Transaction Finality Reduced to 150 Milliseconds

Moscow Exchange Launches Perpetual Futures for Bitcoin, Ethereum, Solana, XRP, and Tron

Ignas Exits Robinhood Meme Stock LP Position, Funds Shift to Solana

Ignas: Meme Coins Face Death Risk as Popularity Wanes

21Shares: Privacy coins grow nearly 5x in one year

Crypto firms put $206 million behind the midterms: here’s who their political machine is backing

Kazakhstan's Crypto Market Trading Volume Reaches $10.58 Billion, Web3 Ecosystem Enters Global Top Ten










