Malicious Code Found in FomoPeek iOS App Versions 1.1–1.2
TREE NEWS reports: Security researchers at SlowMist, working alongside OKX’s security team, have confirmed that versions 1.1 through 1.2 of the FomoPeek iOS application contain malicious code. The compromised builds embed an iOS kernel attack framework bundling eight distinct exploit chains, targeting devices running iOS 12.0 through iOS 18. The malware’s apparent objective is the extraction of sensitive user data — most critically, cryptocurrency private keys and seed phrases stored on affected devices.
What the Malware Does
The embedded framework is not a generic jailbreak toolkit. It is purpose-built to escalate privileges at the kernel level, bypass iOS sandbox protections, and reach the secure storage areas where wallets and key management apps keep their secrets. Eight separate exploit paths are included, suggesting the operators designed the payload to maximize device coverage across a wide span of iOS releases — a level of engineering rarely seen in consumer-facing crypto apps.
- Affected versions: FomoPeek 1.1–1.2
- Targeted systems: iOS 12.0–18
- Capability: Kernel-level privilege escalation via 8 exploit chains
- Risk: Private key and seed phrase exfiltration
Why This Matters for the Broader Market
This incident sits at the intersection of two trends that have defined the past two years of crypto security. First, the attack surface has shifted decisively toward mobile. As retail users migrate from browser extensions to mobile wallets and trading apps, the phone has become the primary vault for private keys. Second, supply-chain attacks on app builds — malicious code injected before or during distribution — are increasingly common and far harder for users to detect than phishing links or fake websites.
The involvement of OKX’s security team is notable. Exchange security units are increasingly functioning as de facto incident responders for the wider ecosystem, a role once played almost exclusively by independent audit firms. Their collaboration with SlowMist signals that the industry is consolidating threat intelligence rather than working in silos.
Forward-Looking Perspective
Users who installed FomoPeek 1.1 or 1.2 should treat any keys or seed phrases generated or stored on those devices as compromised. The correct response is to migrate funds to a freshly generated wallet on a clean, fully updated device — not merely to uninstall the app, since exfiltrated keys remain valid indefinitely.
Looking ahead, expect app store review processes and mobile wallet vendors to face renewed pressure to implement build-provenance verification and reproducible builds. Until such standards are widely adopted, the gap between what a crypto app claims to do and what its binary actually executes will remain one of the most dangerous blind spots in the ecosystem.




