Key facts
- A malicious iOS app called FomoPeek has been linked to the theft of nearly $580,000 in cryptocurrency.
- The app used kernel exploits to bypass Apple's sandbox and access sensitive data.
- SlowMist and the OKX security team investigated the incident after receiving user reports.
- Affected FomoPeek versions were released on September 9 and September 12; a clean version was released September 17.
- A primary hacker address received approximately 579,984 USDT.
- Stolen funds were transferred through services including FixedFloat, KuCoin, and cce.cash.
A malicious iOS application named FomoPeek, which was distributed through Apple's App Store, has been implicated in the theft of approximately $580,000 in cryptocurrency. Blockchain security firm SlowMist reported that the app contained two malicious modules that exploited iOS vulnerabilities, allowing them to bypass Apple's security sandbox and access sensitive data, including Keychain data and files from other applications.
According to SlowMist's investigation, which was conducted in collaboration with the OKX security team, affected versions of FomoPeek were released on September 9 and September 12. A subsequent version, 1.3, released on September 17, reportedly removed the malicious components. The investigation was prompted by user reports of asset theft, with some victims having previously installed the compromised FomoPeek versions.
The exploit framework within the app featured eight attack methods and declared compatibility with iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1. SlowMist's on-chain analysis traced the stolen funds to a primary hacker address that received about 579,984 USDT. This address became active on September 15, and the funds were moved across multiple blockchain networks before being consolidated and transferred through various addresses and services, including FixedFloat, KuCoin, and cce.cash.