Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Former Polish Police Officer Charged as Zondacrypto Probe Searches Fuel Depot

    September 23, 2026

    This new concrete is stronger and pulls CO2 from the air

    September 23, 2026

    Allseas books ABL for 60,000-ton topside single-lift ops in next North Sea decom chapter

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Former Polish Police Officer Charged as Zondacrypto Probe Searches Fuel Depot
    • This new concrete is stronger and pulls CO2 from the air
    • Allseas books ABL for 60,000-ton topside single-lift ops in next North Sea decom chapter
    • The Consumer Financial Protection Bureaus’ Business-Friendly Move — ProPublica
    • What Machiavelli Would Say About Trump
    • Israel blasts ‘grotesque absurdity’ of Macron’s UN remarks on West Bank
    • Farmers’ race for £233m funding like ‘scramble for Oasis tickets’
    • UK to launch military squadron to protect satellites in space | Defence policy
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    Malicious iOS App FomoPeek Linked to $580K Crypto Theft

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Crypto & Blockchain No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    [Update 09:15 UTC, Sept. 23: This article was updated with comments from SlowMist on how FomoPeek operated, what its researchers verified and its advice for people who installed affected versions.]

    A malicious iOS app distributed through Apple’s App Store has been linked to nearly $580,000 in stolen crypto after researchers found it contained multiple kernel exploits capable of escaping Apple’s sandbox and accessing sensitive wallet data.

    According to an investigation published by blockchain security firm SlowMist, the app, called FomoPeek, introduced two malicious modules that could exploit iOS vulnerabilities, gain elevated privileges and access Keychain data and files belonging to other apps. 

    SlowMist said the affected versions were released on Sept. 9 and Sept. 12, while version 1.3, released Sept. 17, removed the malicious components.

    SlowMist said its investigation, conducted with the OKX security team, began after it received reports from users who had suffered asset theft and found that some had previously installed the affected FomoPeek versions.

    The exploit framework included eight attack methods and declared support for iOS versions ranging from 12.0 to 18.7.2 and 26.0 to 26.1.

    FomoPeek targeted wallet and notes app data

    “For FomoPeek specifically — no. No Safari or webpage is involved at all,” SlowMist told Cointelegraph when asked whether the attack required users to open a malicious page. It said the framework loaded when the app launched, while a remote server could control its exploitation and data collection functions.

    SlowMist said the server’s configuration named 19 wallet and note apps as targets, including MetaMask, Trust Wallet, SafePal, OKX Wallet and Apple Notes.

    “We confirmed the framework’s ability to collect application data in our controlled environment, including the Apple Notes container,” the company said. It cautioned that this did not establish that a private key or seed phrase had been extracted from every named wallet.

    SlowMist’s onchain analysis identified a primary hacker address associated with the incident that received about 579,984 USDT. The firm said the address became active on Sept. 15 and that the stolen funds involved multiple blockchain networks before being consolidated and transferred through several addresses and services.

    SlowMist’s investigation found that portions of the funds were transferred toward services including FixedFloat, KuCoin and cce.cash, while other funds were dispersed through additional addresses that the firm continued to trace.

    SlowMist urges affected users to move assets to a new wallet

    For users who installed FomoPeek versions 1.1 or 1.2, SlowMist recommended treating potentially exposed wallet credentials as compromised, creating a new wallet on an unaffected device and moving assets to it.

    “If an attacker has already successfully exploited the device and copied sensitive data off the device, enabling Lockdown Mode or uninstalling the malicious application afterwards cannot retrieve that data,” SlowMist said.

    Cointelegraph reached out to Apple and OKX for comment but did not receive a response before publication.

    Helen Partz contributed reporting.

    Related: Hugging Face hack exposes the open-weight AI cybersecurity paradox

    580K app Crypto FomoPeek iOS linked Malicious theft
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Former Polish Police Officer Charged as Zondacrypto Probe Searches Fuel Depot

    Bitcoin Breaks Out as Nasdaq Hits Records and Oil Slides on Iran Hopes

    Binance buys $100 million Circle stake in five-year USDC promotion deal

    OpenAI Launches GPT-6 Sol and Luna Minutes After Anthropic Drops Claude Opus 5.5

    White-Hat Hackers Route Coldcard Exploit Bitcoin Into ‘Recovery Trust’

    Thinktank linked to Reform UK calls for abolition of state pension | Reform UK

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Former Polish Police Officer Charged as Zondacrypto Probe Searches Fuel Depot

    September 23, 2026

    This new concrete is stronger and pulls CO2 from the air

    September 23, 2026

    Allseas books ABL for 60,000-ton topside single-lift ops in next North Sea decom chapter

    September 23, 2026

    The Consumer Financial Protection Bureaus’ Business-Friendly Move — ProPublica

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Former Polish Police Officer Charged as Zondacrypto Probe Searches Fuel Depot

    September 23, 2026

    This new concrete is stronger and pulls CO2 from the air

    September 23, 2026

    Allseas books ABL for 60,000-ton topside single-lift ops in next North Sea decom chapter

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.