FomoPeek iOS App Exposed Users to Private Key Theft via Hidden Exploit
A crypto tracking app called FomoPeek exposed users to private key theft through hidden iOS exploit in versions 1.1-1.2.
The malicious code was capable of exposing private keys, mnemonic phrases, and other sensitive credentials stored on iOS devices, security researchers confirmed on September 19, 2026.
FomoPeek marketed itself as a read-only tracking tool that allowed users to monitor on-chain wallet activity across Solana, Ethereum, and TRON, but investigators found the app bundled a sophisticated iOS kernel exploit framework that drew on eight separate attack methods.
The framework targeted iOS versions 12.0 through 18.7 and 26.0 through 26.1, with users on older builds facing elevated exposure. Once active, the exploit bypassed iOS security mechanisms to access and decrypt the iOS Keychain, the system component where apps store passwords, tokens, and cryptographic keys.