FomoPeek Malware Exposes Crypto Wallets via Keychain
Malicious code was discovered in FomoPeek versions 1.1 and 1.2, which were distributed via the App Store. The security firm SlowMist found that deleting the app does not protect wallets once private keys or recovery phrases leak.
Affected crypto users need to create new wallets on clean devices to secure their funds against stolen keys. The malicious code targeted wallet secrets stored in Apple's Keychain, allowing it to escape the app's sandbox and decrypt sensitive data.
SlowMist analyzed eight exploit methods used by FomoPeek's malicious framework, which could read files belonging to other apps and deliver remote commands to hidden servers. Users who installed affected versions of FomoPeek are at risk even without entering a seed phrase into the app.