FomoPeek app versions 1.1–1.2 exposed users to private key theft through hidden iOS exploit

1 hour ago 2



An app that promised to help crypto users monitor whale wallets turned out to be doing some monitoring of its own. FomoPeek versions 1.1 and 1.2 contain malicious code capable of exposing private keys, mnemonic phrases, and other sensitive credentials stored on iOS devices, security researchers confirmed on September 19, 2026. The public alert came jointly from blockchain security firm SlowMist and the OKX security team, triggered by multiple user reports of asset theft that investigators traced back to malware embedded in the app. What the malware actually does FomoPeek marketed itself as a read-only tracking tool: monitor on-chain wallet activity across Solana, Ethereum, and TRON, get smart alerts on whale movements, never touch your funds. The pitch was clean. The reality was considerably less so. Investigators found the app bundles a sophisticated iOS kernel exploit framework that draws on eight separate attack methods. Which method runs depends on the target device model and iOS version, giving the malware flexibility most security tools aren’t built to anticipate. The framework targets iOS versions 12.0 through 18.7 and 26.0 through 26.1, with users on older builds facing ele...

Read Entire Article