Fomopeek iPhone App Steals $580K in USDT via Exploited iOS Vulnerabilities
A malicious iPhone app called Fomopeek has been linked to nearly $580,000 in stolen USDT. The app was distributed through Apple's App Store and was marketed as a read-only tool for tracking large cryptocurrency transactions. However, security researchers at SlowMist discovered that versions 1.1 and 1.2 of the app contained two modules with no connection to its advertised monitoring functions.
The first module communicated with external command-and-control infrastructure, while the second contained a kernel exploitation framework with eight attack methods that could adjust to the victim's iPhone model and operating-system version.
A successful exploit could escape Apple's application sandbox and reach Keychain information and files belonging to other apps. This created a route to locally stored private keys, seed phrases, and login credentials without requiring users to connect a wallet or enter those details into FomoPeek.
SlowMist founder Yu Xian warned that the risk extended to passwords stored in Apple's Keychain and encrypted files held by other applications. An attacker who obtained both could potentially unlock wallet credentials and other sensitive information stored on the device.