FomoPeek Malware Hid iOS Exploits Inside an App Store Crypto App

FomoPeek Malware Hid iOS Exploits Inside an App Store Crypto App

September 29, 2026 • 4 min read

A cryptocurrency-tracking app distributed through Apple’s official App Store contained a sophisticated iOS exploitation framework capable of reaching information outside the app’s normal sandbox, according to research from SlowMist and the OKX security team.

The app, called FomoPeek, presented itself as a read-only tool for monitoring large wallet transactions across networks including Ethereum, Solana and TRON. Its public-facing pitch suggested a fairly ordinary crypto alert app. Behind that interface, however, researchers found two additional modules with capabilities that had nothing to do with tracking wallet activity.

The malicious code appeared in FomoPeek versions 1.1 and 1.2. SlowMist says version 1.0 did not contain the modules, version 1.1 introduced them on September 9, version 1.2 retained them on September 12, and version 1.3 removed them on September 17. Historical app packages examined by the researchers indicated that the affected builds came through the official App Store rather than from a third-party re-signed or sideloaded copy.

Hidden Malware Inside an Official App Store Build

SlowMist identified two embedded frameworks named apptrace and libapptracecore. Together, the modules supported remote configuration, kernel exploitation, sandbox escape, Keychain decryption and collection of data belonging to other apps.

That is significantly more dangerous than a conventional phishing screen. iOS normally isolates applications from one another, preventing a random app from simply opening another app’s private files. A successful kernel exploit can break through those restrictions and give malicious code access well beyond the permissions the user believes they granted.

According to SlowMist, the framework contained eight exploitation strategies and selected an approach based on the device model and iOS version. The code declared support spanning iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1, although that declared range should not be read as proof that every exploit worked against every device in it.

Remote Commands and a List of Wallet Targets

The malware also contacted remote infrastructure for instructions. During SlowMist’s testing, the command server returned a configuration with exploitation disabled. Researchers then enabled the relevant switches inside an isolated test environment so they could observe what the hidden framework was designed to do.

Once activated, the sample obtained a collection list containing 19 cryptocurrency wallet and note-taking applications. Targets included MetaMask, Trust Wallet, SafePal, OKX Wallet and Apple Notes. Researchers demonstrated the collection chain using Apple Notes, showing that FomoPeek could reach another app’s container, package the data and upload it to the attacker’s server.

That test establishes that the malware could perform cross-app data collection. It does not prove that FomoPeek successfully extracted a private key or seed phrase from every wallet on the list. Cointelegraph noted the same distinction in its reporting after receiving additional clarification from SlowMist.

About $580,000 in Attacker-Linked Funds

Blockchain tracing conducted during the investigation identified an attacker-linked address that received approximately 579,984 USDT, or roughly $580,000. Cointelegraph reported that portions of the funds were traced across multiple blockchain networks and services as researchers followed the movement of the assets.

The figure gives a rough sense of the financial activity connected to the case. Researchers were also investigating reports from users who had installed the affected FomoPeek versions and later reported stolen cryptocurrency or exposed private keys.

Deleting the App Does Not Undo a Data Leak

For users who installed FomoPeek 1.1 or 1.2, simply deleting the app or upgrading to a clean version cannot undo data that may already have been copied from the phone. If a private key, recovery phrase or other credential was successfully collected and transmitted, the attacker could continue using it after FomoPeek itself is gone.

SlowMist recommends treating relevant seed phrases, private keys and sensitive credentials as potentially compromised. Crypto assets should be moved to newly generated wallets created on a trusted device, and affected users should update iOS to the newest version available for their hardware.

A Reminder That App Store Review Is Not a Guarantee

FomoPeek is notable because the malicious code was not found in some sketchy sideloaded copy. Researchers say it was present in signed builds distributed through Apple’s own App Store.

The version history also suggests a particularly difficult review problem: the first release was clean, the next two versions introduced the malicious frameworks, and a later update removed them. To a user, the app still looked like the same harmless crypto tracker throughout.

Apple’s App Store remains a much safer source of iPhone software than unknown download sites, but FomoPeek shows why “downloaded from the App Store” should not be treated as an absolute security guarantee. In rare cases, sophisticated malicious code can still make it through the front door.