$580K Crypto Heist: Malicious iOS App Exploits Kernel Vulnerabilities
A malicious iOS app named FomoPeek was used to steal nearly $580,000 in cryptocurrency from users who installed specific versions of the app.
According to blockchain security firm SlowMist, the app contained kernel exploits that allowed it to break out of Apple's sandbox and access sensitive wallet data.
The malicious components were part of FomoPeek releases issued on September 9 and 12, but were removed in version 1.3 released on September 17.
SlowMist's investigation found that the attackers used kernel-level exploits to target protected data, including iOS Keychain entries and files belonging to other apps.