iPhone App FomoPeek Exposed Users to Crypto Theft via Malicious Code
A security analysis of an iPhone app called FomoPeek has revealed that it contained malicious code, allowing hackers to access other apps and sensitive wallet data.
FomoPeek presented itself as a 'read-only on-chain monitoring and alerting tool' that did not require users to connect a wallet or provide a seed phrase.
However, the app's code was capable of bypassing iPhone security protections, collecting information from other apps, and sending it to a remote server.
The malicious modules were found in two official App Store versions of FomoPeek: 1.1, released on September 9, and 1.2, released on September 12.
A wallet linked to the attacker received $579,984.34 in USDT across several blockchain networks, with funds still flowing in when the report was published.