Blockchain security firm SlowMist has warned that versions 1.1 and 1.2 of FomoPeek, an iOS application marketed for monitoring crypto whale wallets, contained malicious modules capable of attacking the operating system itself. The affected App Store builds carried an iOS kernel exploitation framework designed to escape Apple’s application sandbox and access sensitive information belonging to other apps. FomoPeek advertised read-only monitoring across Solana, Ethereum and TRON and did not require users to connect a wallet.
In the joint investigation disclosed by SlowMist and OKX, researchers identified two embedded modules, apptrace and libapptracecore, unrelated to FomoPeek’s stated functionality. The framework contained eight exploitation strategies and could select an attack path according to the device model and iOS version. SlowMist traced the malicious code to FomoPeek v1.1, released September 9, and v1.2, released September 12.
🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨
We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek… pic.twitter.com/g4tmSe376n
— SlowMist (@SlowMist_Team) September 19, 2026
Kernel Exploit Could Reach Data From Other Apps
If exploitation succeeded, the malware could obtain privileges outside FomoPeek’s normal sandbox, decrypt accessible Keychain data and collect files associated with other applications. That means a read-only market tracker could potentially expose private keys, seed phrases, login credentials, chat records and other sensitive data stored elsewhere on the same device. SlowMist’s isolated testing retrieved a collection list targeting 19 wallet and note-taking applications and demonstrated the packaging and upload of Apple Notes data.
The exploit framework’s code declared support for iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1, although FomoPeek itself required iOS 16 or later. The theoretical vulnerability range was therefore broader than the population of devices that could actually install the application. SlowMist said older iOS releases generally faced greater risk, while the framework also included device profiles covering relatively recent iPhones and iPads.
Researchers also found command-and-control infrastructure capable of receiving device information and remotely configuring the malicious functionality. The attacker could control exploit activation and periodic execution without releasing another FomoPeek update. SlowMist’s initial alert said captured traffic indicated attack functionality was active, while subsequent technical testing demonstrated that the C2 system could remotely toggle the exploit and change its execution interval.
Users Told to Replace Exposed Wallet Keys
The investigation began after multiple users reported stolen assets associated with private-key exposure. MistTrack analysis later linked a primary attacker address to approximately 579,984 USDT in received funds across the investigated flows. That figure represents funds traced to the identified address and should not automatically be treated as a complete accounting of all victim losses.
SlowMist found that v1.0 did not contain the malicious modules and that v1.3 removed both frameworks before the public warning was issued. Users who installed v1.1 or v1.2 are nevertheless advised to treat potentially exposed keys and credentials as compromised rather than assuming an application update reverses earlier data theft. The incident resembles previous mobile threats, including cases where fraudulent wallet applications exposed users’ recovery phrases, although FomoPeek’s kernel-level attack represents a different security boundary.
SlowMist and Binance Wallet recommend checking accounts for unauthorized activity, generating entirely new wallet credentials on a trusted device that never installed FomoPeek, moving remaining assets, updating iOS and avoiding further use or reinstallation of the app. The critical remediation step is key rotation on a clean device, not simply deleting FomoPeek from the potentially compromised phone. Users who detect suspicious transfers are also advised to preserve the affected device and related evidence for forensic investigation.
