Blockchain security firm SlowMist identified malicious code in FomoPeek versions 1.1 and 1.2, distributed through the Apple App Store. The app, presented as a read-only crypto wallet monitoring tool, contained modules designed to bypass iPhone security protections and collect data from other applications on the device.
FomoPeek promised users a wallet monitoring experience without requiring wallet connections or seed phrases. However, analysis revealed the app could access information from other apps and send it to a remote server. SlowMist and OKX's security team investigated after receiving reports of stolen assets and exposed private keys.
How the Malicious Code Operated
Researchers found that malicious modules retrieved encrypted server addresses and received instructions on which data to collect. During testing in an isolated environment, the code targeted 19 wallet and note-taking applications. Investigators documented the app uploading Apple Notes data from the test device.
The exploitation code within FomoPeek shared the name DarkSwordStrategy with DarkSword, an iOS exploit chain documented by Google Threat Intelligence Group in March.
Financial Trail and Timeline
SlowMist traced cryptocurrency to a wallet identified as the attacker's primary address. The address became active on September 15 and received 579,984.34 USDT across multiple blockchain networks. Funds continued flowing into the address when SlowMist published its findings on September 20.
FomoPeek version 1.1 was released on September 9, and version 1.2 on September 12. The malicious modules were absent from version 1.0 and removed in version 1.3, released on September 17.
Recommendations for Affected Users
SlowMist advised users of the affected versions to treat seed phrases, private keys, and sensitive credentials stored on those devices as potentially compromised. The firm recommended creating a new wallet on a secure device that never ran the malicious versions and transferring assets from wallets whose keys may have been exposed.
Users who deleted or updated the app may still face exposure, as information already transmitted cannot be retrieved by removing the application.


