Malicious Crypto App Found on Apple’s App Store

FomoPeek versions 1.1 and 1.2 contained hidden iOS kernel-exploit malware that could escape the sandbox and access private keys, seed phrases and data from other apps.

The app posed as a read-only whale tracker for Solana, Ethereum and TRON. Version 1.0 was clean, while the malware appeared on September 9 and was removed in version 1.3 on September 17.

SlowMist found the malware could target at least 19 wallet and notes apps and remotely upload stolen data. SlowMist and OKX issued an alert on September 19 after reports of multiple victims, with Binance Wallet and Gate also warning users.

Anyone who installed 1.1 or 1.2 should treat their wallet keys and seed phrases as compromised, create a new wallet on a clean device and move remaining assets. Uninstalling the app or updating iOS alone does not undo previous access.