Sun. Sep 20th, 2026

SlowMist and OKX Link FomoPeek iOS App to Active Crypto Theft Campaign

ByMichael Lebowitz

September 19, 2026 #OKX
OKXOKXOKX

SlowMist and OKX security researchers have linked versions 1.1 and 1.2 of the FomoPeek iOS app to an active crypto-theft campaign, warning that malicious code embedded in the software could escape Apple’s normal app sandbox and expose private keys, seed phrases and other sensitive data stored on affected devices.

SlowMist issued the alert on Sept. 19 after receiving multiple reports from users who said crypto assets had been stolen. The blockchain security firm said its investigation found private-key exposure in the affected cases and that some victims had previously installed or used FomoPeek 1.1 or 1.2. A joint technical review with OKX then found malicious components inside the app that were unrelated to its advertised functions.

Eight iOS Exploit Methods Found Inside FomoPeek

One component contained what SlowMist described as an iOS kernel exploitation framework with eight different exploit methods. According to the firm, the framework can automatically select an attack technique based on the iPhone model and iOS version. SlowMist identified iOS 12.0 through 18.7 and iOS 26.0 through 26.1 as affected ranges, while warning that older operating-system versions carry greater risk.

If exploitation succeeds, the app may break out of the iOS sandbox, access and decrypt Keychain data and read files belonging to other apps. SlowMist said that could expose private keys, recovery phrases, login credentials, chat histories and files stored on the device.

The investigation also found connections to hidden servers that SlowMist said were unrelated to FomoPeek’s public-facing service. The firm said plaintext network traffic captured during analysis showed the malicious functionality was enabled and configured to run automatically at regular intervals. Neither SlowMist nor OKX has disclosed an aggregate dollar value for the reported thefts.

A “Read-Only” Crypto App With Device-Level Risk

The findings stand in sharp contrast to how FomoPeek was presented to users. Apple’s App Store listing described the product as a free, iPhone-only “Whale Tracker & Smart Alerts” app for monitoring large wallets and on-chain activity across Solana, Ethereum and TRON. The listing called the service “read-only” and said it did not execute trades, custody funds or collect deposits.

That distinction is central to the incident. Users did not need to give FomoPeek custody of their crypto for the software to become a potential threat to assets held elsewhere on the same phone. If the kernel exploit worked as researchers describe, the risk came from device-level access rather than from FomoPeek’s stated wallet-tracking features.

The App Store version history shows FomoPeek 1.1 and 1.2 were released only days before the Sept. 19 warning. Apple’s listing also carried a developer-provided privacy statement saying the app did not collect data, while noting that the privacy information had not been verified by Apple.

SlowMist advised anyone who installed or used versions 1.1 or 1.2 to check for abnormal account activity, create new wallet credentials on a trusted device that has never had FomoPeek installed, move remaining assets to the new wallet, update iOS and stop using the app. Simply deleting the app does not neutralize a private key or seed phrase that may already have been exposed.

Apple currently lists iOS 27 as its latest mobile operating system, released on Sept. 14. Binance also circulated a security advisory after the SlowMist disclosure, warning that the malware targets the device itself and advising self-custody users who installed FomoPeek to generate a new wallet on a clean device.

The incident adds another layer to the broader self-custody security problem. Recent cases have shown attackers targeting seed phrases through phishing, third-party infrastructure and flaws in wallet key generation. FomoPeek is different because it potentially turns an apparently low-risk monitoring app into a route toward sensitive information held by other applications on the same device.

Analysis: A Read-Only App Becoming a Wallet Threat Changes the Risk Model

The most uncomfortable part of the FomoPeek case is how little the advertised product itself had to do with custody.

A whale-tracking app is exactly the sort of software many crypto users would place in the low-risk bucket. It watches public addresses. It sends alerts. It does not ask to hold funds. On paper, there is no obvious reason it should threaten another wallet installed on the phone.

That assumption is what this incident attacks.

If SlowMist and OKX’s technical findings are correct, the malicious code was not trying to beat a wallet at the wallet layer. It was trying to beat the operating system beneath it. Once an attacker escapes the sandbox and reaches Keychain data or other app files, the security model changes completely.

This is also why the story should not be reduced to “another malicious crypto app.” Crypto investors have already seen seed theft attempted through a Trezor phishing campaign, a wider Brevo breach that gave attackers access to trusted communication infrastructure, and Coldcard RNG losses tied to weak wallet-seed generation. Those incidents hit different parts of the stack. FomoPeek potentially hits the device itself.

That makes mobile operational security much more important for serious holders. Keeping a seed phrase out of cloud storage is sensible. Using a reputable wallet is sensible. Avoiding obvious phishing links is sensible. But none of those precautions fully solves a compromised operating environment.

The lesson is not that every iPhone wallet is unsafe or that App Store software should automatically be treated as malicious. The evidence is much narrower: researchers say two specific FomoPeek versions contained an active exploitation framework, and multiple theft reports led them to investigate. There is still no public aggregate loss figure, no full victim count and no detailed public accounting of every exploit used.

Those gaps matter. Investors should resist turning a confirmed malicious-app finding into unsupported claims about the scale of the campaign or the safety of iOS generally.

Still, the remediation advice is unusually telling. SlowMist is not telling affected users to uninstall and move on. It is telling them to generate entirely new keys on a different trusted device and transfer assets there. That is the appropriate response when credential exposure is plausible because once a private key has been copied, there is no patch that makes the old key secret again.

For the crypto industry, this incident reinforces a broader pattern visible in other recent security failures, including the Swiss Bitcoin Pay breach: the weakest point is often not the blockchain. It is the surrounding infrastructure, software and devices people use to reach it.

The next question is whether investigators publish affected-wallet addresses, theft addresses, command-and-control infrastructure or additional malicious app versions. Those details would allow blockchain analysts to estimate losses, map victim clusters and potentially identify where stolen assets moved.

Until then, the investor takeaway is simple. “Read-only” describes what an app says its business function is. It does not describe what malicious code inside that app can do once it is running on the same device as your keys.

More Posts

Michael Lebowitz is a financial markets analyst and digital finance writer specializing in cryptocurrencies, blockchain ecosystems, prediction markets, and emerging fintech platforms. He began his career as a forex and equities trader, developing a deep understanding of market dynamics, risk cycles, and capital flows across traditional financial markets.

In 2013, Michael transitioned his focus to cryptocurrencies, recognizing early the structural similarities—and critical differences—between legacy markets and blockchain-based financial systems. Since then, his work has concentrated on crypto-native market behavior, including memecoin cycles, on-chain activity, liquidity mechanics, and the role of prediction markets in pricing political, economic, and technological outcomes.

Alongside digital assets, Michael continues to follow developments in online trading and financial technology, particularly where traditional market infrastructure intersects with decentralized systems. His analysis emphasizes incentive design, trader psychology, and market structure rather than short-term price action, helping readers better understand how speculative narratives form, evolve, and unwind in fast-moving crypto markets.

Leave a Reply

Your email address will not be published. Required fields are marked *