Foresight News report: Slow Mist issued a security warning stating that it has recently received multiple reports from FomoPeek users about stolen assets. After conducting a joint investigation with the OKX security team, it found that some affected users had previously installed or used FomoPeek versions 1.1–1.2, and the related applications contain malicious code.
Within FomoPeek, there are modules unrelated to normal business. One of them contains a kernel exploit framework targeting the iOS system, supporting eight different attack methods, and it can automatically select the exploitation method based on the device model and iOS version. Affected systems include iOS 12.0 to 18.7 and iOS 26.0 to 26.1. If the exploitation succeeds, the app may break out of the iOS sandbox and access and decrypt Keychain data, leading to the leakage of private keys, mnemonics, login credentials, and other sensitive files. In addition, FomoPeek also connects to a hidden server unrelated to its public services and can receive remote commands.
According to SlowMist, its analysis of the captured plaintext traffic shows that the relevant attack functionality is currently enabled and will run automatically on a regular basis. Users who have installed or used the FomoPeek 1.1–1.2 versions are advised to immediately check whether their assets show any anomalies. Generate new private keys and recovery seed phrases on a trusted device on which this app has never been installed, and transfer the assets to a new account as soon as possible. Also upgrade to the latest iOS version and do not continue using or reinstalling FomoPeek.
