An iOS app listed under the “official” name is most afraid of not its download count, but of what it does in places you can’t see.
According to SlowMist, certain affected versions of the FOMO official iOS app were available on the App Store from September 9 to 17. They contain malicious modules capable of stealing mnemonic phrases, private keys, and wallet data, and also have attack capabilities similar to DarkSword. The market interpretation is largely negative for FOMO/FomoPeek and crypto mobile security trust, with no clear token match. The most direct impact on users is the risk to asset security.
If you have used the relevant versions, treat the mnemonic phrases, private keys, and sensitive credentials as already leaked. Move your assets as soon as possible, update them, and review and revoke authorizations. Being on the App Store channel does not equal a secure security audit—what’s worth keeping a closer eye on next is the official response, the scale of victims, and whether Apple-side review accountability follows through.
Will you migrate your assets first, or check and revoke authorizations first?
Figure 1: FOMO iOS app exposed to malicious data-stealing risks · Key takeaways
Image source: https://www.theblockbeats.info/flash/368643
According to SlowMist, certain affected versions of the FOMO official iOS app were available on the App Store from September 9 to 17. They contain malicious modules capable of stealing mnemonic phrases, private keys, and wallet data, and also have attack capabilities similar to DarkSword. The market interpretation is largely negative for FOMO/FomoPeek and crypto mobile security trust, with no clear token match. The most direct impact on users is the risk to asset security.
If you have used the relevant versions, treat the mnemonic phrases, private keys, and sensitive credentials as already leaked. Move your assets as soon as possible, update them, and review and revoke authorizations. Being on the App Store channel does not equal a secure security audit—what’s worth keeping a closer eye on next is the official response, the scale of victims, and whether Apple-side review accountability follows through.
Will you migrate your assets first, or check and revoke authorizations first?
Figure 1: FOMO iOS app exposed to malicious data-stealing risks · Key takeaways
Image source: https://www.theblockbeats.info/flash/368643
