NewsTradingSentimentEventsCommunityBriefing
Markets

FomoPeek App Linked to $580,000 Crypto Theft via Kernel Exploits

By Markets Desk · · 1 min read
A flat vector illustration of a smartphone connected to a server rack.

SlowMist reports a malicious iOS app stole nearly $580,000 by bypassing sandbox security.

Key points

  • Malicious FomoPeek versions stole nearly $580,000 by exploiting iOS kernel flaws.
  • The app accessed Keychain data from other apps to extract wallet credentials.
  • Stolen USDT moved through multiple networks and services before consolidation.

Researchers link a malicious iOS app to the theft of nearly $580,000 in crypto assets. The app exploited kernel vulnerabilities to bypass Apple’s sandbox protection.

SlowMist identified the malware, named FomoPeek, as the source of the breach. It accessed sensitive wallet data from other installed applications on user devices.

Malware bypassed iOS security controls

The app introduced two modules that exploited specific iOS kernel flaws. These exploits allowed the software to gain elevated system privileges.

Once privileged, the app accessed Keychain data and files from other apps. This direct access enabled the theft of cryptographic keys and credentials.

Distribution timeline and version control

Affected versions released on September 9 and 12 contained the malicious code. Version 1.3, released on September 17, removed these components.

The exploit framework supported iOS versions 12.0 through 18.7.2. It also targeted newer versions ranging from 26.0 to 26.1.

Stolen funds moved across networks

One hacker address received approximately 579,984 USDT shortly after the attack began. The funds moved across multiple blockchain networks before consolidation.

SlowMist traced portions of the money to services like FixedFloat and KuCoin. Other funds dispersed through additional addresses that investigators continue to trace.

Based on reporting by Cointelegraph, compiled by the Tradingbird desk.

More from the Markets desk

All desk stories