📰 This time FomoPeek was stolen. What’s most chilling isn’t the fake website, but the fact that users didn’t click malicious contracts and didn’t manually paste their mnemonic phrases—yet the wallet assets on their phones were emptied outright.
According to a post-incident review by SlowMist and the OKX Security team, FomoPeek versions 1.1–1.2 were bundled with iOS kernel exploit code. It can elevate privileges across different device models and iOS versions, break out of the app sandbox, access the system Keychain, even scan other wallet data and notes on the same device, and quietly exfiltrate plaintext private keys.
🔥 What’s even more troublesome is that these attacks don’t necessarily rely on sloppy phishing. Hackers can first promote through KOLs, then lower users’ guard by leveraging real functionality and a referral/reward mechanism. After downloads and target assets reach a certain threshold, they release the malicious code. Honestly, the phrase “big shots are using it” can’t be treated as a security guarantee anymore.
💡 When it comes to private key safety, you still need physical isolation: don’t store mnemonics in your phone photo roll, Notes, cloud drives, email drafts, or chat apps—and don’t copy/paste them between your phone and computer. A safer approach is to manually transcribe them offline, then store the core assets using a metal mnemonic plate, keeping them stored separately.
👀 Devices also need to be segmented. Your primary asset machine should only have system-native tools, official verifiers, and apps paired with your hardware wallet; a secondary “backup” device should be used to browse X, try new tools, and run referral/reward bots. The article’s suggested fund allocation approach is: most funds in cold wallets or multisig; part of it in an isolated environment; and only a small amount in a hot wallet for high-risk interactions.
🤔 Before, would you keep your mnemonic on your phone? And now, would you prepare a dedicated “test-infection machine”?
#Web3安全 #私钥安全 #钱包安全 #FomoPeek
According to a post-incident review by SlowMist and the OKX Security team, FomoPeek versions 1.1–1.2 were bundled with iOS kernel exploit code. It can elevate privileges across different device models and iOS versions, break out of the app sandbox, access the system Keychain, even scan other wallet data and notes on the same device, and quietly exfiltrate plaintext private keys.
🔥 What’s even more troublesome is that these attacks don’t necessarily rely on sloppy phishing. Hackers can first promote through KOLs, then lower users’ guard by leveraging real functionality and a referral/reward mechanism. After downloads and target assets reach a certain threshold, they release the malicious code. Honestly, the phrase “big shots are using it” can’t be treated as a security guarantee anymore.
💡 When it comes to private key safety, you still need physical isolation: don’t store mnemonics in your phone photo roll, Notes, cloud drives, email drafts, or chat apps—and don’t copy/paste them between your phone and computer. A safer approach is to manually transcribe them offline, then store the core assets using a metal mnemonic plate, keeping them stored separately.
👀 Devices also need to be segmented. Your primary asset machine should only have system-native tools, official verifiers, and apps paired with your hardware wallet; a secondary “backup” device should be used to browse X, try new tools, and run referral/reward bots. The article’s suggested fund allocation approach is: most funds in cold wallets or multisig; part of it in an isolated environment; and only a small amount in a hot wallet for high-risk interactions.
🤔 Before, would you keep your mnemonic on your phone? And now, would you prepare a dedicated “test-infection machine”?
#Web3安全 #私钥安全 #钱包安全 #FomoPeek
