A malicious iOS application named FomoPeek, distributed through Apple’s App Store, has been linked to the theft of approximately $580,000 in cryptocurrency. Blockchain security firm SlowMist reported that the app contained two malicious modules capable of exploiting iOS vulnerabilities to escape Apple’s sandbox, gain elevated privileges, and access Keychain data as well as files belonging to other applications. The investigation, conducted in collaboration with the OKX security team, began after users reported asset losses following the installation of specific app versions.

The affected versions were released on September 9 and September 12, while version 1.3, released on September 17, removed the malicious components. The exploit framework utilized eight attack methods and declared support for iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1. On-chain analysis identified a primary hacker address that received about 579,984 USDT, becoming active on September 15. The stolen funds involved multiple blockchain networks before being consolidated and transferred through several addresses and services, including FixedFloat, KuCoin, and cce.cash. Cointelegraph reached out to Apple, SlowMist, and OKX for comment but did not receive a response before publication.