Versions 1.1 and 1.2 included malicious modules
FomoPeek, an iPhone app distributed through Apple’s App Store, was presented as a read-only tool for tracking large transactions on Ethereum, Solana and Tron. SlowMist opened an investigation following reports of stolen assets linked to exposed private keys.
SlowMist and researchers at OKX found two modules in versions 1.1 and 1.2 that were unrelated to the app’s stated functions. One communicated with external command-and-control infrastructure; the other included a kernel exploitation framework with eight attack methods, adaptable to the iPhone model and operating system version.
According to the researchers, a successful attack could bypass the iOS sandbox and access Keychain data and files from other apps, potentially exposing private keys, seed phrases and login credentials. The framework could also receive instructions from a remote server, including settings for activation and exploitation frequency.
The malicious components were present in version 1.1, published on September 9, and version 1.2, published on September 12. They had been removed in version 1.3, published on September 17. Salus identified 0x6d37f2C5e8F8546b648D317295565dA95975f4BB as the attacker’s address and estimated proceeds of around 579,900 USDT.
According to Salus, 401,028 USDT passed through three intermediary addresses to FixedFloat, while another 20,000 USDT were consolidated in a KuCoin hot wallet. Binance, OKX, Gate, Bitget Wallet and Rabby advised users to remove FomoPeek, update iOS and move assets to new wallets created on devices where the app had never been installed.





