Browse categories
AIAltcoinsAnalysisBitcoinCryptoDeFiEthereumExchangesFundingGoldInstitutionalLayer 2MacroMarketsMemecoinsMiningNewsOn-ChainPaymentsRegulationRWASecurityStablecoinsTradFi
BTC$81,806.00 1.13%
ETH$2,646.98 1.87%
BNB$766.75 1.00%
SOL$111.76 0.03%
XRP$1.43 3.71%
ADA$0.2292 4.74%
BTC$81,806.00 1.13%
ETH$2,646.98 1.87%
BNB$766.75 1.00%
SOL$111.76 0.03%
XRP$1.43 3.71%
ADA$0.2292 4.74%

FomoPeek App Found Using iOS Exploit to Steal Private Keys

Security researchers from SlowMist and OKX have identified malicious code in FomoPeek versions 1.1 and 1.2 that allows attackers to steal sensitive credentials from iOS devices.

Users of the whale tracking app FomoPeek are being warned that versions 1.1 and 1.2 contain malicious code designed to compromise private keys and mnemonic phrases. The alert, issued on September 19, 2026, by SlowMist and the OKX security team, follows reports of asset theft linked to the application.

While FomoPeek was marketed as a read-only tool for monitoring on-chain activity across Solana, Ethereum, and TRON, investigators discovered it contains a sophisticated iOS kernel exploit framework. This framework utilizes eight different attack methods to bypass iOS security and access the system Keychain, where passwords and cryptographic keys are stored.

The exploit targets a wide range of iOS versions, specifically 12.0 through 18.7 and 26.0 through 26.1. Researchers confirmed that the malware was actively connecting to remote servers to receive real-time commands during their investigation.

The danger of the app stems from its ability to access the shared iOS Keychain, which allows the malware to reach sensitive data even though the app itself does not execute trades or hold funds directly. Because the exploit can access cached credentials, any private keys or seed phrases stored on a compromised device are at risk.

SlowMist and OKX have advised affected users to immediately transfer their assets to new wallets created on a clean device that has never had FomoPeek installed. Users are also urged to uninstall the app, revoke existing wallet permissions, and monitor their transaction history for unauthorized activity.

The technical complexity of the FomoPeek malware, which includes active remote command execution and multiple exploit methods, marks a notable escalation in the tactics used to target crypto users.

Crypto Research
@cryptoresearch
47.5K members · Free real-time crypto news and price alerts, the moment they break.
Join
975,489
Total members across the Channels
@ChartsSignalsTrading
116K members
Join
@OnlyFinance_Pro
91.9K members
Join
@Nakamoto_Signals
76.9K members
Join
@BlackBlockMarkets
76.3K members
Join
@Bitunix_Trades
72.8K members
Join
View all channels