- SlowMist found malicious code in FomoPeek versions 1.1 and 1.2 distributed via the App Store.
- Deleting FomoPeek does not protect wallets once private keys or recovery phrases leak.
- Affected crypto users need new wallets on clean devices to secure funds against stolen keys.
Crypto users who installed affected versions of FomoPeek face a risk that survives deleting the app. SlowMist has warned that two versions contained malicious code targeting wallet secrets. Affected users should move funds to a new wallet created on a clean device.
The security firm issued its September 19 alert after investigating reports of stolen assets with OKX. Some victims had used FomoPeek versions 1.1 or 1.2, and the cases examined involved exposed private keys.
Why Deleting FomoPeek Is Not Enough
Removing the app does not cancel a stolen private key or recovery phrase. Those credentials give access to the original wallet from another device. Updating iOS addresses software security, but it does not replace wallet credentials already copied by an attacker.
FomoPeek presented itself as a tool for tracking large wallets across Solana, Ethereum, and TRON. Its listing described alerts for activity involving public wallet addresses.
FomoPeek Versions and Their iOS Keychain Risk
SlowMist’s analysis found the malicious modules in official App Store releases. Version 1.1 introduced them on September 9, and version 1.2 retained them on September 12. Version 1.3 removed both modules on September 17.
The initial warning named iOS 12.0–18.7 and iOS 26.0–26.1 as affected ranges. Older operating systems carried greater risk, according to the firm.
The detailed report extended the code’s declared coverage to iOS 18.7.2, alongside iOS 26.0–26.1. That describes the framework’s intended targets. It does not establish that every device running those versions suffered a successful attack.
Apple’s Keychain stores sensitive items such as passwords, keys, and login tokens. Normal access is restricted through app permissions and access groups. Its encryption and access controls are designed to prevent an unrelated app from freely reading those records.
How Malware Exposed Wallet Data and Old Keys
Researchers found eight exploit methods inside FomoPeek’s malicious framework. The code selected an approach based on the device model and iOS version. SlowMist said a successful exploit could escape the app’s sandbox, decrypt Keychain data, and read files belonging to other apps.
The threatened information included private keys, recovery phrases, login credentials, and chat records. SlowMist also found connections to hidden servers that delivered remote commands, separate from FomoPeek’s advertised services.
The reported design therefore put users at risk even without entering a seed phrase into FomoPeek. Its code targeted secrets stored elsewhere on the phone, including information held by legitimate wallet apps.
During later testing, the server’s exploitation switch was off. Researchers enabled it in an isolated environment to examine subsequent behavior. They obtained a list targeting 19 wallet and note-taking apps and captured an upload containing Apple Notes data.
However, importing the old recovery phrase into another wallet app restores the same accounts. Adding another account under that phrase also leaves it tied to the exposed secret. A new wallet address alone therefore does not establish that the underlying credentials have changed.
What Crypto Users Should Do After a Wallet Attack
Asset transfers also need to cover holdings beyond the main balance. Tokens on other networks, NFTs, and funds held in DeFi positions require separate checks. MetaMask’s migration guide advises reviewing holdings and accounting for transaction fees and locked positions.
Fresh recovery phrases also need secure backups. MetaMask tells users to record the words in the correct order and keep them private. Its migration guidance warns against placing a recovery phrase in cloud-synced notes.
SlowMist urged users to stop using FomoPeek and avoid reinstalling it. It also advised changing affected login credentials. Victims should contact official support and preserve the device, app version, installation dates, and transaction records for investigation.
As previously reported, the DarkSword and Coruna attacks used a different delivery method. Both relied on malicious webpages to exploit vulnerable iPhones. Google documented DarkSword variants targeting iOS 18.4–18.7, while Coruna exploit chains targeted iOS 13.0–17.2.1.
FomoPeek carried its malicious components inside an installed app. SlowMist also found a strategy named DarkSwordStrategy in its framework. The app therefore adds a separate exposure route to the browser attacks described in earlier reporting.
Related: How to Secure an iPhone Crypto Wallet Against Malware and Web-Based Exploits
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.