Press Enter to search · ESC to close

Crypto

FomoPeek iOS App Found Shipping Kernel Exploit Framework, Exposing Private Keys

SlowMist and OKX security teams confirmed that FomoPeek iOS app versions 1.1–1.2 contain malicious code embedding an eight-exploit kernel attack framework targeting iOS 12.0–18. The malware is designed to exfiltrate private keys and seed phrases, raising fresh concerns about mobile supply-chain attacks in crypto.

Malicious Code Found in FomoPeek iOS App Versions 1.1–1.2

Security researchers at SlowMist, working alongside OKX’s security team, have confirmed that versions 1.1 through 1.2 of the FomoPeek iOS application contain malicious code. The compromised builds embed an iOS kernel attack framework bundling eight distinct exploit chains, targeting devices running iOS 12.0 through iOS 18. The malware’s apparent objective is the extraction of sensitive user data — most critically, cryptocurrency private keys and seed phrases stored on affected devices.

What the Malware Does

The embedded framework is not a generic jailbreak toolkit. It is purpose-built to escalate privileges at the kernel level, bypass iOS sandbox protections, and reach the secure storage areas where wallets and key management apps keep their secrets. Eight separate exploit paths are included, suggesting the operators designed the payload to maximize device coverage across a wide span of iOS releases — a level of engineering rarely seen in consumer-facing crypto apps.

  • Affected versions: FomoPeek 1.1–1.2
  • Targeted systems: iOS 12.0–18
  • Capability: Kernel-level privilege escalation via 8 exploit chains
  • Risk: Private key and seed phrase exfiltration

Why This Matters for the Broader Market

This incident sits at the intersection of two trends that have defined the past two years of crypto security. First, the attack surface has shifted decisively toward mobile. As retail users migrate from browser extensions to mobile wallets and trading apps, the phone has become the primary vault for private keys. Second, supply-chain attacks on app builds — malicious code injected before or during distribution — are increasingly common and far harder for users to detect than phishing links or fake websites.

The involvement of OKX’s security team is notable. Exchange security units are increasingly functioning as de facto incident responders for the wider ecosystem, a role once played almost exclusively by independent audit firms. Their collaboration with SlowMist signals that the industry is consolidating threat intelligence rather than working in silos.

Forward-Looking Perspective

Users who installed FomoPeek 1.1 or 1.2 should treat any keys or seed phrases generated or stored on those devices as compromised. The correct response is to migrate funds to a freshly generated wallet on a clean, fully updated device — not merely to uninstall the app, since exfiltrated keys remain valid indefinitely.

Looking ahead, expect app store review processes and mobile wallet vendors to face renewed pressure to implement build-provenance verification and reproducible builds. Until such standards are widely adopted, the gap between what a crypto app claims to do and what its binary actually executes will remain one of the most dangerous blind spots in the ecosystem.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback