Malicious iOS App Linked to $580K Crypto Theft

Security researchers discovered that a malicious iOS app distributed via Apple’s App Store, named FomoPeek, used multiple kernel exploits to escape the sandbox and steal cryptocurrency. The app’s compromised versions were released in early September, and the stolen funds were traced to a single wal…

By Felo News Desk · Published

In a striking reminder that even the most trusted app ecosystems can harbor hidden threats, security researchers uncovered a malicious iOS application that was able to bypass Apple’s sandbox protections and siphon cryptocurrency from users’ wallets. The app, identified as FomoPeek, was distributed through Apple’s official App Store and was found to contain a suite of kernel exploits that allowed it to gain elevated privileges, read sensitive data from the iOS Keychain, and access files belonging to other apps.

How the Attack Worked

SlowMist, a blockchain security firm, and the OKX security team conducted a detailed investigation after receiving complaints from users who reported significant losses. The researchers traced the attack back to two malicious modules that were embedded in the app’s code. These modules leveraged eight distinct attack methods, each designed to target a specific iOS vulnerability. The exploit framework was compatible with a wide range of iOS versions, from 12.0 up to 18.7.2 and 26.0 to 26.1, effectively covering the vast majority of devices in use at the time.

The core of the attack was a kernel exploit that allowed the app to escape the sandbox—a security boundary that normally isolates apps from each other and from the operating system. By breaking out of this boundary, FomoPeek could read the Keychain, a secure storage area that holds passwords, private keys, and other sensitive data. Once the attacker had access to the Keychain, the app could retrieve private keys for cryptocurrency wallets and use them to transfer funds.

Timeline of the Malicious Versions

The compromised versions of FomoPeek were released on September 9 and September 12. A subsequent update, version 1.3, was published on September 17 and removed the malicious components. However, by the time the update was rolled out, the damage had already been done. The researchers found that the attack began shortly after the initial releases, with the primary hacker address becoming active on September 15.

On-chain analysis performed by SlowMist revealed that the stolen funds were primarily in USDT (Tether), with a total of 579,984 USDT transferred to a single wallet address. The funds were not moved directly to a single destination; instead, they were shuffled through multiple addresses and services, including FixedFloat, KuCoin, and cce.cash. This layering made it difficult for investigators to trace the money’s final destination, but it also indicated that the attackers were attempting to launder the proceeds.

Impact on Users and the Crypto Community

While the exact number of affected users is not publicly known, the magnitude of the theft—nearly $580,000—highlights the vulnerability of mobile cryptocurrency wallets. Many users rely on iOS apps for convenience and security, assuming that the App Store’s review process provides a robust safeguard. This incident demonstrates that malicious actors can still find ways to slip through, especially when sophisticated kernel exploits are involved.

For the broader crypto ecosystem, the FomoPeek case underscores the importance of multi-layered security. Developers are urged to implement additional safeguards such as hardware-backed key storage, secure enclave usage, and continuous monitoring for unusual app behavior. Users, on the other hand, should remain vigilant, verify app permissions, and consider using hardware wallets for large holdings.

What Happens Next?

Apple has not yet responded to inquiries from Cointelegraph, and neither SlowMist nor OKX have issued public statements beyond the initial findings. The investigation is ongoing, with researchers continuing to trace the flow of stolen funds and identify any additional compromised devices. Law enforcement agencies may also be involved as the case progresses, especially if the stolen funds are linked to known criminal networks.

In the meantime, the crypto community is watching closely. The incident serves as a wake-up call for app developers, security teams, and users alike to reassess the security posture of mobile cryptocurrency applications and to advocate for stricter vetting processes within app marketplaces.

Key facts

  • Malicious iOS app FomoPeek used kernel exploits to escape sandbox
  • Compromised versions released Sept. 9 and 12, fixed in Sept. 17
  • Attack stole nearly $580,000 in USDT via a single wallet address
  • Funds were layered through multiple exchanges and services
  • Apple, SlowMist, and OKX have yet to release detailed statements

Why it matters

The FomoPeek incident reveals that even trusted app stores can distribute malware capable of bypassing core security mechanisms, posing a serious risk to users who store valuable digital assets on mobile devices.

Frequently asked questions

What is FomoPeek?

FomoPeek is a malicious iOS application that was distributed through Apple’s official App Store and contained multiple kernel exploits designed to bypass the operating system’s sandbox and access sensitive data.

How many users were affected?

The exact number of affected users is not publicly disclosed, but the total value of stolen funds was nearly $580,000, indicating a significant impact.

What can users do to protect themselves?

Users should verify app permissions, keep their devices updated, use hardware wallets for large holdings, and monitor their accounts for unauthorized activity.

Has Apple responded?

Apple has not yet issued a public statement regarding the incident.

Sources

  • [1] cointelegraph.com — originally reported as “Malicious iOS App FomoPeek Linked to $580K Crypto Theft”

More from Business

Felo News, House 42, Bridge Colony, Kot Lakhpat, Lahore, Pakistan
+92 308 4354717 · felopronews@gmail.com