Confirmed *worse than just sandbox escape, it's kernel exploit chain*. $NIL $NOM $LSK
*SlowMist + OKX Security Sep 20 investigation:*
- *App:* *FomoPeek — read-only on-chain monitoring/alerting tool, no wallet connect/seed needed* — *malicious in App Store versions 1.1 Sep 9 + 1.2 Sep 12* — *cleaned v1.3 Sep 17 removed modules* — *both malicious modules signed same Apple developer identity, App Store encryption retained = inside official distribution not sideload*
- *Exploit:* *2 malicious modules, 8 attack methods, support iOS 12.0-18.7.2 + 26.0-26.1* — *kernel exploits → escape sandbox → privilege elevation → access Keychain + files of other apps*
- *Targets in config: 19 apps — MetaMask, Trust Wallet, SafePal, OKX Wallet, Apple Notes etc* — confirmed in lab *collected Apple Notes data container and uploaded to remote server* — *remote control capability server can direct exploit post-launch*
- *On-chain:* *Primary hacker address active Sep 15 → 579,984.34 USDT total receipts (not only FomoPeek theft but main linked) cross-chain consolidation* — funds flowing at time of report — *routed via FixedFloat, KuCoin, http://cce.cash, swaps*
- *Investigation started from user theft reports where victims had installed those versions*
*Immediate actions if you installed Sep 9-15:*
1. *Delete FomoPeek now* — don't use v1.3 either
2. *Update iOS latest + change iCloud + rotate any seeds that were in MetaMask/Trust/OKX Wallet/Notes on same device* — assume Keychain compromised
3. *Move all assets to fresh wallet generated on clean device, revoke approvals*
*BREAKING 🚨 Malicious FomoPeek iOS App Store versions Sep 9/12 had kernel exploits 8 methods iOS 12-18.7.2 26.0-26.1 escape sandbox steal Keychain 🚨 SlowMist + OKX: $579,984 USDT to hacker addr Sep 15 via FixedFloat KuCoin — targeted MetaMask Trust OKX SafePal Apple Notes — v1.3 Sep 17 removed modules — DELETE app rotate seeds 🛡️*#BinanceWillListHyperliquid(HYPE) #USWeighsPromotingDollarStablecoinsAbroad #BCHJumps28%OnCMEFuturesListing
*SlowMist + OKX Security Sep 20 investigation:*
- *App:* *FomoPeek — read-only on-chain monitoring/alerting tool, no wallet connect/seed needed* — *malicious in App Store versions 1.1 Sep 9 + 1.2 Sep 12* — *cleaned v1.3 Sep 17 removed modules* — *both malicious modules signed same Apple developer identity, App Store encryption retained = inside official distribution not sideload*
- *Exploit:* *2 malicious modules, 8 attack methods, support iOS 12.0-18.7.2 + 26.0-26.1* — *kernel exploits → escape sandbox → privilege elevation → access Keychain + files of other apps*
- *Targets in config: 19 apps — MetaMask, Trust Wallet, SafePal, OKX Wallet, Apple Notes etc* — confirmed in lab *collected Apple Notes data container and uploaded to remote server* — *remote control capability server can direct exploit post-launch*
- *On-chain:* *Primary hacker address active Sep 15 → 579,984.34 USDT total receipts (not only FomoPeek theft but main linked) cross-chain consolidation* — funds flowing at time of report — *routed via FixedFloat, KuCoin, http://cce.cash, swaps*
- *Investigation started from user theft reports where victims had installed those versions*
*Immediate actions if you installed Sep 9-15:*
1. *Delete FomoPeek now* — don't use v1.3 either
2. *Update iOS latest + change iCloud + rotate any seeds that were in MetaMask/Trust/OKX Wallet/Notes on same device* — assume Keychain compromised
3. *Move all assets to fresh wallet generated on clean device, revoke approvals*
*BREAKING 🚨 Malicious FomoPeek iOS App Store versions Sep 9/12 had kernel exploits 8 methods iOS 12-18.7.2 26.0-26.1 escape sandbox steal Keychain 🚨 SlowMist + OKX: $579,984 USDT to hacker addr Sep 15 via FixedFloat KuCoin — targeted MetaMask Trust OKX SafePal Apple Notes — v1.3 Sep 17 removed modules — DELETE app rotate seeds 🛡️*#BinanceWillListHyperliquid(HYPE) #USWeighsPromotingDollarStablecoinsAbroad #BCHJumps28%OnCMEFuturesListing

