iPhone Crypto Users Urged to Move Funds After FomoPeek Malware Exposes Wallet Keys
SlowMist says FomoPeek versions 1.1–1.2 contained malicious code capable of stealing private keys, seed phrases, and credentials from iPhones.
SlowMist says FomoPeek versions 1.1–1.2 contained malicious code capable of stealing private keys, seed phrases, and credentials from iPhones.
Researchers found an iOS kernel exploitation framework with eight attack methods, potentially affecting iOS versions from 12.0 through 18.7 and iOS 26.0–26.1.
Researchers found an iOS kernel exploitation framework with eight attack methods, potentially affecting iOS versions from 12.0 through 18.7 and iOS 26.0–26.1.
Binance has urged affected self-custody users to generate entirely new wallet credentials on a clean device and move their remaining crypto.
Binance has urged affected self-custody users to generate entirely new wallet credentials on a clean device and move their remaining crypto.
Crypto users who installed the iPhone app FomoPeek are being urged to move their funds after security researchers discovered malware that can bypass Apple's app protections and extract cryptocurrency wallet credentials .
Blockchain security firm SlowMist issued the warning on Sept. 19 after receiving multiple reports of stolen crypto involving users who had previously installed FomoPeek versions 1.1 or 1.2.
A subsequent investigation conducted with OKX's security team uncovered two suspicious modules unrelated to the app's advertised functions.
FomoPeek markets itself as a read-only tool for monitoring whale wallets across Ethereum, Solana and TRON, promising users onchain alerts without taking custody of their assets .
Researchers say the malicious versions were doing considerably more.
Eight Exploits Could Break Out of Apple's Sandbox
SlowMist found one hidden module containing an iOS kernel exploitation framework with eight separate attack methods.
The malware could select an exploit based on the iPhone model and operating-system version. SlowMist's analysis covered devices running iOS 12.0–18.7 and iOS 26.0–26.1.
If exploitation succeeded, FomoPeek could escape Apple's application sandbox — the security boundary normally designed to prevent one app from accessing another app's private information.
From there, researchers said the malware could decrypt Keychain data and access private keys, recovery phrases, login credentials, chat histories, and files from other applications.
That makes the incident particularly dangerous for crypto holders. An attacker obtaining a wallet's private key or recovery phrase does not need continued access to the victim's iPhone. The credentials can be imported elsewhere to control the same blockchain assets.
Researchers also detected connections to hidden servers unrelated to FomoPeek's advertised service. SlowMist said captured network traffic indicated that the malicious functionality was active and configured to execute automatically at regular intervals.
Binance Says Move Crypto to New Wallets
Binance has now issued its own warning to iPhone and iPad users who installed FomoPeek.
Affected users are advised to delete the app, avoid reinstalling it, and update their devices to the latest iOS release.
More importantly, Binance recommends that self-custody users create an entirely new wallet on a device that never had FomoPeek installed and transfer their assets to the new address.
Simply deleting FomoPeek may not be enough.
Once a private key or seed phrase has been copied, the credential itself must be considered compromised.
Reinstalling the same wallet on another phone using the old recovery phrase would therefore recreate the same vulnerable wallet.
Gate issued similar guidance, saying its risk-control systems had detected no losses among its own users, while warning that FomoPeek could put other wallet applications on an infected device at risk.
SlowMist has not disclosed the total amount stolen or the number of successfully compromised devices.
For users who installed versions 1.1 or 1.2, however, the security response goes beyond removing a malicious app: the wallet keys themselves may need to be replaced.
Top Trending Crypto Articles
Check Out Our Recommended Exchanges Here
Check Out Our Recommended Exchanges Here
How To Buy Crypto with a Credit Card Now
How To Buy Crypto with a Credit Card Now
See Our Picks for the Best Crypto Gambling Sites
See Our Picks for the Best Crypto Gambling Sites
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
