Sun. Sep 20th, 2026

FomoPeek iOS App Contained Active Kernel Exploit Framework

ByMichael Lebowitz

September 19, 2026 #FomoPeek
Crypto Hack

FomoPeek Versions 1.1–1.2 Linked to Crypto Theft Reports

Security researchers have warned that versions 1.1 and 1.2 of FomoPeek, an iPhone application marketed as a read-only crypto whale tracker, contained malicious code capable of exploiting the iOS kernel and accessing sensitive information belonging to other applications on the same device.

SlowMist issued the alert on September 19 after receiving multiple reports of stolen cryptocurrency involving private-key exposure. Some of the affected users had previously installed or used FomoPeek versions 1.1–1.2. A joint investigation by SlowMist and the OKX security team subsequently found what SlowMist described as clear evidence that malicious code had been embedded in the application.

The finding adds a different attack surface to recent crypto security incidents, because the risk was not limited to users entering wallet credentials into a phishing page or sending assets to a fraudulent address. Researchers say the application itself contained tooling capable of breaking through the security boundaries intended to separate iOS apps from one another.

SlowMist said FomoPeek bundled two modules unrelated to the application’s normal business functions. One contained a professional iOS kernel exploitation framework incorporating eight different exploit methods. The framework could automatically choose an attack path depending on the device model and operating-system version.

The security firm listed exploit coverage spanning iOS 12.0 through 18.7 and iOS 26.0 through 26.1, while cautioning that devices running older versions generally faced greater risk. That range describes the exploit framework identified by researchers; FomoPeek’s recent App Store listing itself required iOS 16.0 or later.

If exploitation succeeded, SlowMist said the application could escape the normal iOS sandbox, access and decrypt Keychain data and read files belonging to other applications on the device. The potentially exposed information included private keys, recovery seed phrases, login credentials, chat histories and other files.

That makes the incident materially different from a conventional malicious-wallet application. FomoPeek advertised itself as a monitoring tool that did not execute trades, custody funds or collect deposits. Its App Store description said users could track public wallet addresses across Solana, Ethereum and TRON, receive alerts about transfers and swaps, and follow smart-money activity using public blockchain and market data.

In other words, a user had no obvious reason to import a wallet seed phrase into FomoPeek in the first place.

The concern is that, according to SlowMist’s analysis, that separation may not have mattered once the application obtained deeper control over the device. Credentials stored elsewhere on the iPhone could potentially become accessible even though they had never been intentionally shared with FomoPeek.

The App Store privacy section added another notable contrast. The developer declared that the application collected no data, although Apple’s listing clearly states that such privacy information is supplied by the developer and has not been verified by Apple. The listing identified WhaleScanv as the developer and Porter Manufacturing, L.L.C. as the seller.

SlowMist also said the malicious components connected to hidden servers unrelated to FomoPeek’s public-facing services and could receive remote instructions. More importantly, plaintext network traffic captured during the investigation indicated that the attack functionality was enabled and configured to execute automatically at regular intervals.

That distinguishes the case from a dormant proof-of-concept or an accidentally included security-testing library. Researchers were warning about functionality they said was operational.

No aggregate value has been disclosed for the cryptocurrency reportedly stolen, and SlowMist has not published a complete victim count or public list of affected wallet addresses. The warning therefore establishes multiple theft reports and exposure of private keys, but does not yet provide enough information to quantify the total financial impact.

Binance subsequently issued its own warning to iPhone users, emphasizing that the malware targeted the device rather than merely the FomoPeek application. Gate also said its security team examined the application and identified high-risk malicious behavior, although Gate said it had not detected FomoPeek-related losses involving its own application or customers.

The incident comes as crypto companies are dealing with attacks across increasingly varied infrastructure. Recent cases have included an internal system breach at a Bitcoin payments provider and an alleged unauthorized crypto transfer from a self-custody wallet. The FomoPeek case is more unsettling because the suspected point of compromise sits below the wallet application itself: the operating environment of the phone.

SlowMist advised anyone who installed or used versions 1.1–1.2 to inspect accounts for suspicious activity, stop using the application and update iOS. For self-custody assets, the firm recommended generating entirely new private keys and recovery phrases on a trusted device that never had FomoPeek installed, then moving remaining assets to those new wallets.

Apple released iOS 27 and iOS 26.7 on September 14, including numerous security fixes. However, neither SlowMist nor Apple has publicly identified which specific CVEs, if any, correspond to the eight exploit methods found inside FomoPeek.

Analysis: A “Read-Only” Crypto App Just Broke the Usual Security Assumption

The most important part of the FomoPeek story is not simply that another crypto application contained malware. It is that the application apparently did not need users to trust it with their cryptocurrency in the conventional sense.

“Read-only” is normally a powerful reassurance. If an application receives only public wallet addresses, cannot sign transactions and never sees a recovery phrase, the financial damage it can cause should theoretically be limited.

That logic depends on the operating system doing its job.

Once an application can escape its sandbox and reach data belonging to other applications, its stated product permissions become almost irrelevant. A whale tracker can potentially become a wallet attack vector. The user may have followed every obvious rule — never imported a seed phrase, never approved a transaction and never gave the tracker custody — and still face exposure because the malicious code attacked the phone rather than the wallet interface.

That is a more serious security model than the one involved in many phishing attacks. Phishing generally still needs the victim to do something: open a link, reveal a recovery phrase, approve a transaction or install malicious software. FomoPeek users did install software, but the application’s advertised functionality gave them little reason to believe that installation could put unrelated wallet credentials at risk.

The incident also exposes the limits of app-store trust signals. Seeing an application inside Apple’s ecosystem, seeing “Data Not Collected,” and reading that it does not custody assets can all reduce suspicion. None of those signals is equivalent to a forensic guarantee about what every code path inside an application will do.

For crypto investors, that matters because the value concentrated on one device can be unusually high. An iPhone may simultaneously contain self-custody wallets, exchange applications, password managers, authentication credentials, messaging histories and records showing where assets are held. A sufficiently deep device compromise therefore creates several possible paths toward financial loss.

This is different from a bridge exploit or a protocol exploit, where the vulnerable system and the pool of assets at risk are usually easier to define. Here, every affected phone may have contained a completely different combination of wallets, accounts and credentials.

That also makes the final loss figure difficult to establish. Researchers would need to connect installations and successful exploitation to specific wallet compromises and then distinguish FomoPeek-related thefts from the constant background level of phishing, seed exposure and other wallet compromises.

The next important disclosure is therefore technical. Researchers need to identify exactly which vulnerabilities the framework used, which device and iOS combinations successfully executed each exploit, what information was exfiltrated and how the command-and-control infrastructure operated. As previous security bugs have demonstrated, understanding the precise failure condition is what allows platforms and users to determine whether they were actually exposed rather than simply potentially vulnerable.

The second question is distribution. How many people installed versions 1.1 and 1.2, in which countries, and for how long were those versions available? Without that denominator, multiple theft reports could represent a relatively contained incident or only the first visible part of a much wider compromise.

Most importantly, deleting the application does not reverse disclosure of a private key that has already occurred. A stolen password can be changed. A compromised crypto private key cannot be made secret again. The assets have to move to a wallet controlled by an entirely new key.

That is why FomoPeek is more consequential than its small, seemingly harmless product description suggests. The application was sold to users as a window into other people’s wallets. According to SlowMist’s analysis, the dangerous functionality was actually looking inward — at the device on which it had been installed.

More Posts

Michael Lebowitz is a financial markets analyst and digital finance writer specializing in cryptocurrencies, blockchain ecosystems, prediction markets, and emerging fintech platforms. He began his career as a forex and equities trader, developing a deep understanding of market dynamics, risk cycles, and capital flows across traditional financial markets.

In 2013, Michael transitioned his focus to cryptocurrencies, recognizing early the structural similarities—and critical differences—between legacy markets and blockchain-based financial systems. Since then, his work has concentrated on crypto-native market behavior, including memecoin cycles, on-chain activity, liquidity mechanics, and the role of prediction markets in pricing political, economic, and technological outcomes.

Alongside digital assets, Michael continues to follow developments in online trading and financial technology, particularly where traditional market infrastructure intersects with decentralized systems. His analysis emphasizes incentive design, trader psychology, and market structure rather than short-term price action, helping readers better understand how speculative narratives form, evolve, and unwind in fast-moving crypto markets.

Leave a Reply

Your email address will not be published. Required fields are marked *