Loading prices…
🩸BEARISH

FomoPeek Malware Steals Nearly $580K in USDT

The breach reached beyond a wallet app: researchers say it could expose Keychain data, seed phrases and credentials, forcing affected users to create new wallets.

FomoPeek, a malicious iPhone app distributed through Apple's App Store, was linked to nearly $580,000 in stolen USDT after versions 1.1 and 1.2 embedded tools capable of escaping the iOS application sandbox. SlowMist and OKX researchers found command-and-control functionality and a kernel exploitation framework with eight attack methods tailored to the victim's iPhone model and operating system. Salus estimated attacker proceeds at about 579,900 USDT.

Why it matters

The exploit could reach Apple's Keychain, files held by other apps, private keys, seed phrases and login credentials without requiring users to connect a wallet or type those details into FomoPeek. The app was marketed as a read-only tracker for large transactions across Ethereum, Solana and Tron, making its presence in Apple's official marketplace especially significant for crypto users who rely on app isolation.

FomoPeek version 1.1 was released on Sept. 9 and version 1.2 on Sept. 12. The malicious components were removed in version 1.3 on Sept. 17, but deleting the app or updating iOS cannot invalidate credentials that may already have been copied.

Market impact

Salus traced 401,028 USDT through intermediary addresses to FixedFloat, while other funds moved toward a KuCoin hot wallet, an escrow platform and the CCE mixing service. The incident has prompted warnings from Binance, OKX, Gate, Bitget Wallet and Rabby.

Affected users are being urged to remove FomoPeek, update iOS and move funds to newly created wallets on devices where the app was never installed. The case also challenges the assumption that a dedicated crypto iPhone is automatically safe: device isolation offers limited protection when installed software can compromise the operating system.

Related tokens
$USDT $ETH $SOL $TRX

Frequently asked questions

  1. What was FomoPeek marketed as before the malicious code was found?

    FomoPeek was marketed as a read-only tool for tracking large cryptocurrency transactions across Ethereum, Solana and Tron.

  2. Which FomoPeek versions contained the malicious components?

    Researchers found the malicious components in versions 1.1 and 1.2. They were removed in version 1.3.

  3. What information could the iPhone exploit expose?

    The exploit could reach Apple Keychain data, private keys, seed phrases, login credentials and files belonging to other apps.

  4. How much USDT did investigators link to the attack?

    Salus estimated attacker proceeds at about 579,900 USDT, or nearly $580,000.

  5. What should users do if FomoPeek was installed?

    Users should remove FomoPeek, update iOS and move assets to newly created wallets on a device where the app was never installed. Deleting the app cannot invalidate copied credentials.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 48m ago
Open original →