Malicious FomoPeek iOS App Stole $580K in Crypto via Kernel Exploits
Blockchain security firm SlowMist has linked a malicious iOS application called FomoPeek to nearly $580,000 in stolen cryptocurrency, revealing a sophisticated attack that exploited Apple's sandbox protections. Distributed through the official App Store, the app introduced two malicious modules capable of exploiting iOS kernel vulnerabilities, gaining elevated privileges, and accessing sensitive data including Keychain credentials and files belonging to other applications. The investigation was conducted in collaboration with the OKX security team after multiple users reported unexplained asset theft.
According to SlowMist's findings, the compromised versions of FomoPeek were released on September 9 and September 12, while version 1.3, published on September 17, removed the malicious components. The embedded exploit framework included eight distinct attack methods and declared compatibility with iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1. SlowMist noted that the malicious code targeted known iOS kernel exploits to escape Apple's sandbox environment, a technique that allows apps to operate in isolation from one another and from the underlying system.
SlowMist's onchain analysis identified a primary hacker wallet address associated with the incident, which received approximately 579,984 USDT and became active on September 15. The stolen funds traversed multiple blockchain networks before being consolidated and laundered through several addresses and services, including FixedFloat, KuCoin, and cce.cash. The security firm stated it continues to trace additional addresses linked to the operation.
The incident highlights persistent vulnerabilities in app store ecosystems, where malicious software can bypass review processes and reach millions of users. Cointelegraph reached out to Apple, SlowMist, and OKX for comment but did not receive a response before publication. The breach follows a growing trend of supply-chain attacks targeting crypto holders through seemingly legitimate mobile applications, underscoring the importance of verifying app developers and limiting Keychain access for third-party software.
Read Full Article at CoinTelegraph →