FomoPeek iPhone App Hides Malicious Code to Steal Crypto Credentials
A security firm has discovered that the FomoPeek iPhone app contained malicious code designed to steal cryptocurrency credentials from infected devices. The app, marketed as a tool for monitoring whale wallets across Solana, Ethereum, and TRON, had two hidden modules unrelated to its advertised functions.
SlowMist, a blockchain security firm, linked versions 1.1 and 1.2 of the app to reported crypto thefts after a joint investigation with OKX's security team. The malicious code contained an iOS kernel exploitation framework with eight distinct attack methods, capable of adapting to different device models and operating-system versions.
The exploit could escape Apple's security sandbox, decrypt Keychain information, and read data belonging to other apps. This potentially exposed material included private keys, recovery phrases, login credentials, chat records, and other files stored on the device.