FomoPeek app versions 1.1–1.2 exposed users to private key theft through hidden iOS exploit

The original uploader was Ladislav Mecir at English Wikipedia. / Wikimedia Commons (CC BY-SA 3.0)

FomoPeek app versions 1.1–1.2 exposed users to private key theft through hidden iOS exploit

SlowMist and OKX security teams confirmed malicious code capable of draining wallets from a tool marketed as a simple whale tracker.

An app that promised to help crypto users monitor whale wallets turned out to be doing some monitoring of its own. FomoPeek versions 1.1 and 1.2 contain malicious code capable of exposing private keys, mnemonic phrases, and other sensitive credentials stored on iOS devices, security researchers confirmed on September 19, 2026.

The public alert came jointly from blockchain security firm SlowMist and the OKX security team, triggered by multiple user reports of asset theft that investigators traced back to malware embedded in the app.

What the malware actually does

FomoPeek marketed itself as a read-only tracking tool: monitor on-chain wallet activity across Solana, Ethereum, and TRON, get smart alerts on whale movements, never touch your funds. The pitch was clean. The reality was considerably less so.

Investigators found the app bundles a sophisticated iOS kernel exploit framework that draws on eight separate attack methods. Which method runs depends on the target device model and iOS version, giving the malware flexibility most security tools aren’t built to anticipate.

Advertisement

The framework targets iOS versions 12.0 through 18.7 and 26.0 through 26.1, with users on older builds facing elevated exposure. Once active, the exploit bypasses iOS security mechanisms to access and decrypt the iOS Keychain, the system component where apps store passwords, tokens, and cryptographic keys.

The more alarming finding: the attack functions were already live during the investigation. The app was actively connecting to remote servers, pulling unauthorized commands in real time. This wasn’t dormant code waiting to be triggered. It was running.

Why a “read-only” tool is still dangerous

Users often assume that apps without trading or transaction functionality carry lower risk. FomoPeek’s design leaned into that assumption. It doesn’t execute trades. It doesn’t hold funds. It asks only to observe.

The iOS Keychain is a shared credential vault. If an exploit framework can reach it, the walls between “just watching” and “actually stealing” collapse entirely. Private keys and seed phrases stored or cached on a compromised device become accessible regardless of which app originally generated them.

What affected users should do now

SlowMist and OKX issued direct guidance: move assets immediately and generate new keys on a device that never had FomoPeek installed. The emphasis on a clean device matters. If the exploit was actively running, any keys generated or stored on the affected phone should be considered compromised, not just at risk.

The standard checklist applies here with unusual urgency. Uninstall the app. Transfer holdings to wallets secured by freshly generated keys on a verified clean device. Revoke any approvals or permissions granted through wallets connected to the affected phone. Review recent transaction histories for unauthorized activity.

One complication: financial losses and specific compromised wallets had not been publicly disclosed as of the alert date.

The broader security picture

The FomoPeek case is notable because of the technical depth involved. Eight exploit methods, active remote command execution, and a cover story centered on a legitimately useful product category represent a meaningful escalation in attacker effort.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
FomoPeek app versions 1.1–1.2 exposed users to private key theft through hidden iOS exploit
FomoPeek app versions 1.1–1.2 exposed users to private key theft through hidden iOS exploit

SlowMist and OKX security teams confirmed malicious code capable of draining wallets from a tool marketed as a simple whale tracker.

The original uploader was Ladislav Mecir at English Wikipedia. / Wikimedia Commons (CC BY-SA 3.0)

An app that promised to help crypto users monitor whale wallets turned out to be doing some monitoring of its own. FomoPeek versions 1.1 and 1.2 contain malicious code capable of exposing private keys, mnemonic phrases, and other sensitive credentials stored on iOS devices, security researchers confirmed on September 19, 2026.

The public alert came jointly from blockchain security firm SlowMist and the OKX security team, triggered by multiple user reports of asset theft that investigators traced back to malware embedded in the app.

What the malware actually does

FomoPeek marketed itself as a read-only tracking tool: monitor on-chain wallet activity across Solana, Ethereum, and TRON, get smart alerts on whale movements, never touch your funds. The pitch was clean. The reality was considerably less so.

Investigators found the app bundles a sophisticated iOS kernel exploit framework that draws on eight separate attack methods. Which method runs depends on the target device model and iOS version, giving the malware flexibility most security tools aren’t built to anticipate.

Advertisement

The framework targets iOS versions 12.0 through 18.7 and 26.0 through 26.1, with users on older builds facing elevated exposure. Once active, the exploit bypasses iOS security mechanisms to access and decrypt the iOS Keychain, the system component where apps store passwords, tokens, and cryptographic keys.

The more alarming finding: the attack functions were already live during the investigation. The app was actively connecting to remote servers, pulling unauthorized commands in real time. This wasn’t dormant code waiting to be triggered. It was running.

Why a “read-only” tool is still dangerous

Users often assume that apps without trading or transaction functionality carry lower risk. FomoPeek’s design leaned into that assumption. It doesn’t execute trades. It doesn’t hold funds. It asks only to observe.

The iOS Keychain is a shared credential vault. If an exploit framework can reach it, the walls between “just watching” and “actually stealing” collapse entirely. Private keys and seed phrases stored or cached on a compromised device become accessible regardless of which app originally generated them.

What affected users should do now

SlowMist and OKX issued direct guidance: move assets immediately and generate new keys on a device that never had FomoPeek installed. The emphasis on a clean device matters. If the exploit was actively running, any keys generated or stored on the affected phone should be considered compromised, not just at risk.

The standard checklist applies here with unusual urgency. Uninstall the app. Transfer holdings to wallets secured by freshly generated keys on a verified clean device. Revoke any approvals or permissions granted through wallets connected to the affected phone. Review recent transaction histories for unauthorized activity.

One complication: financial losses and specific compromised wallets had not been publicly disclosed as of the alert date.

The broader security picture

The FomoPeek case is notable because of the technical depth involved. Eight exploit methods, active remote command execution, and a cover story centered on a legitimately useful product category represent a meaningful escalation in attacker effort.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.