A malicious iOS application named FomoPeek, distributed through Apple’s App Store, has been linked to the theft of approximately $580,000 in cryptocurrency. Blockchain security firm SlowMist reported that the app contained two malicious modules capable of exploiting iOS vulnerabilities to escape Apple’s sandbox, gain elevated privileges, and access Keychain data as well as files belonging to other applications. The investigation, conducted in collaboration with the OKX security team, began after users reported asset losses following the installation of specific app versions.
The affected versions were released on September 9 and September 12, while version 1.3, released on September 17, removed the malicious components. The exploit framework utilized eight attack methods and declared support for iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1. On-chain analysis identified a primary hacker address that received about 579,984 USDT, becoming active on September 15. The stolen funds involved multiple blockchain networks before being consolidated and transferred through several addresses and services, including FixedFloat, KuCoin, and cce.cash. Cointelegraph reached out to Apple, SlowMist, and OKX for comment but did not receive a response before publication.
The discovery of FomoPeek underscores the persistent risk posed by sophisticated supply chain attacks within closed ecosystems like the Apple App Store. By leveraging kernel exploits to bypass sandbox restrictions and access Keychain data, the malware demonstrated an ability to compromise user credentials and private keys directly at the operating system level. This incident highlights that distribution through official channels does not guarantee security, particularly when attackers utilize advanced techniques to evade detection during the review process. The removal of malicious code in subsequent versions suggests a deliberate attempt to maintain the app's presence while limiting exposure, complicating forensic efforts for victims who installed earlier iterations.
From an institutional compliance perspective, the consolidation of stolen funds across multiple blockchains and their transfer through known mixing services and exchanges such as KuCoin and FixedFloat illustrates ongoing challenges in tracking illicit flows. While the specific attribution to FomoPeek provides a clear vector for this loss, the broader implication is the need for enhanced monitoring of high-risk transaction patterns associated with newly compromised wallets. Security firms and exchanges must continue to refine their detection mechanisms for rapid fund dispersal tactics, ensuring that regulatory frameworks keep pace with evolving exploitation methods targeting mobile infrastructure.


