According to a disclosure from the security firm SlowMist, the company recently received multiple reports of users’ assets being stolen. Its investigation found that the affected cases involved private-key exposure. Additionally, these users had installed or once installed the FomoPeek application.
Track every Apple CVE the moment it's exploited.
Get free email alertsFomoPeek is not itself a cryptocurrency wallet but a tool that helps users watch and track the movement of on-chain funds. It issues alerts when on-chain information likely to sway the market arises. Yet research revealed that the app harbored two functional modules unrelated to its stated business. SlowMist detailed the findings in its public threat alert.
A Built-In iOS Kernel Exploit Framework for Stealing Data
The iOS kernel-level exploit framework embedded in FomoPeek possesses several different exploitation methods. It automatically selects its attack according to the device model and the iOS version actually in use. If the exploit succeeds, the attack program may escape the iOS sandbox and access and decrypt data in the Keychain. Moreover, it also holds permission to read files on the device belonging to other applications.
This means that all sensitive data stored on the device, such as cryptocurrency wallet private keys, mnemonic or seed phrases, login credentials, chat records, and files, can be stolen by hackers. The data can be uploaded to attacker-controlled servers. FomoPeek can also remotely receive instructions issued by the attacker.
This kernel-level exploit framework can mount attacks against iOS 12.0 to 18.7 and iOS 26.0 to 26.1. That is, it exploits security vulnerabilities Apple has already fixed. If a user always runs the latest iOS version, the flaws are patched. As a result, FomoPeek can no longer exploit them.
Paying KOLs to Recruit More Users to Download
As a new project, FomoPeek struggled to be quickly downloaded and used by more cryptocurrency users. Therefore, the app resorted to paying KOLs to promote it and recruit newcomers. Images seen show a KOL inviting users to download and register FomoPeek with a referral code. After registering, new users could receive a reward of 7 USDT. As for the KOLs, they likely received an even higher reward.
Through this method, FomoPeek could rapidly reach a large number of crypto-community users and lure them into downloading the app. Once installed, it began stealing wallet private keys and transferring users’ assets. For the crypto users whose assets were stolen, this wave of losses proved dire. Many users’ wallets were emptied outright, and the assets are difficult to recover.
iOS Remains Safe, Provided You Always Update
From the current picture, these kernel-level attacks most likely also use the DarkSword series of exploit frameworks, an iOS high-severity security flaw that Google reported in March 2026. After Google’s report to Apple, Apple fixed the vulnerabilities in subsequently released versions. Therefore, users on the latest version are unaffected.
On the whole, the iOS system remains secure, provided the user always runs the latest version and enables automatic updates. It is important not to disable updating entirely out of frustration that iOS grows more sluggish with each release. For crypto users, using an iPhone with the latest iOS carries a higher safety factor. Since asset security is at stake, safety should come first.
Separately, an attacker on the NodeSeek community earlier posted a bogus free-VPS-server campaign that likewise used the DarkSword series of attack frameworks. In other words, this kind of once-rare kernel-level attack has already begun targeting ordinary users. Not downloading applications of unknown origin and not opening unfamiliar websites are also means of defense. However, whatever the case, one should keep iOS properly updated.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!