SlowMist links FomoPeek App Store iOS app to ~$580K crypto theft
By Crypto Wire
September 23, 2026
Blockchain security firm SlowMist, working with the OKX security team, says versions of the iOS whale-watching app FomoPeek that reached users through Apple’s official App Store carried a kernel-level attack framework capable of escaping the sandbox and reading sensitive data from other apps—including crypto wallet material—without users pasting a seed phrase or approving a wallet connect. Same-day coverage from Cointelegraph and regional desks ties a primary attacker address to roughly 579,984 USDT (~$580,000) received after the campaign went live.
FomoPeek marketed itself as a read-only monitor for whale wallets on Solana, Ethereum, and TRON: add public addresses, get alerts, never connect a hot wallet. SlowMist’s reconstruction says that pitch made the install look low-risk. Behind the UI, versions 1.1 (released September 9) and 1.2 (September 12) embedded malicious modules labeled apptrace and libapptracecore, while the clean 1.0 build from August 29 did not. Version 1.3, released September 17, removed those modules and shrank the package from about 10.47 MB to roughly 1.81 MB—a footprint change researchers treat as corroborating evidence that the exploit stack was stripped after social warnings began circulating around September 16.
The reported capability set is what moves this out of ordinary phishing and into Rug Room territory. SlowMist describes remote configuration, iOS kernel exploitation, privilege escalation, sandbox escape, Keychain decryption, and cross-app data collection. The framework allegedly bundled eight attack methods with declared support spanning iOS 12.0 through 18.7.2 and 26.0 through 26.1, choosing paths by device model and OS. Gate and AiCoin write-ups citing the joint probe say the collection list targeted on the order of 19 wallet apps, and dynamic testing reportedly uploaded Apple Notes database files among other artifacts. In short: the theft path does not require a user to type a mnemonic into FomoPeek itself.
On-chain follow-through is attributed to SlowMist’s MistTrack tooling. Researchers say a primary hacker address cluster became active on September 15 and had accumulated about 579,984.34 USDT by report time, with stolen value moving across networks including Ethereum, BNB Chain, Arbitrum, and TRON before consolidation. Downstream hops cited in the coverage stack include transfers toward FixedFloat, KuCoin, and cce.cash, plus additional dispersal addresses still under tracing. That USDT figure is a traced intake total for the identified cluster—not a certified census of every victim’s lifetime loss.
Signing detail matters for collectors who assume “App Store = safe.” SlowMist’s reporting states the malicious modules shipped inside the official App Store binaries and shared the same Apple signing identity as the main program—not a sideloaded IPA or third-party resign. Cointelegraph said Apple, SlowMist, and OKX did not respond to comment requests before its September 23 write-up. Until those parties publish their own statements, desks should attribute the sandbox-escape and Keychain claims to SlowMist/OKX’s investigation rather than to an Apple admission.
Practical hygiene from the same reports: anyone who installed FomoPeek 1.1 or 1.2 should treat exposed keys and credentials as compromised, stop using the app, avoid reinstalling it as a “fix,” create a new wallet on a clean device that never ran the malware builds, migrate assets, rotate related passwords and exchange credentials, and review approvals and transaction history. Updating to 1.3 does not rewind earlier Keychain or cross-app reads. NFT holders who keep high-value collections on the same phone that ran a whale-alert toy are the exact population this class of mobile exploit is built to hit.
Bottom line: SlowMist and OKX say App Store FomoPeek builds 1.1/1.2 hid an iOS kernel attack stack that could steal wallet-adjacent data without a user-entered seed, with MistTrack tying ~$580K in USDT intake to the campaign—another reminder that marketplace safety starts on the device, not only on the mint page.
Disclaimer: This article is provided for informational and educational purposes only. It does not constitute financial, investment, legal, or trading advice. The NFT market is highly volatile, and past performance is not indicative of future results. Readers should conduct their own research and consult qualified professionals before making any decisions related to digital assets. The cover image for this article may have been created using artificial intelligence (AI).

