Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump, Guterres Address UNGA With Contrasting Messages

    September 23, 2026

    Did Obama ban Fox News from White House briefings? Claim distorts the facts

    September 23, 2026

    Morocco election: How Ceuta, football and Israel have shaped the campaign

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump, Guterres Address UNGA With Contrasting Messages
    • Did Obama ban Fox News from White House briefings? Claim distorts the facts
    • Morocco election: How Ceuta, football and Israel have shaped the campaign
    • Ukraine anger as EU removes Russian oligarchs from sanctions list
    • Snorkel AI triples valuation to $3.5B as demand for AI training data booms
    • Rogue external MFA providers can steal passwords during logins
    • Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT
    • MIT’s tiny flying robot gets 450% faster with AI
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Crypto & Blockchain

    Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Crypto & Blockchain No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Fomopeek, a malicious iPhone app distributed through Apple’s App Store, has been linked to nearly $580,000 in stolen USDT.

    Blockchain security firm SlowMist began investigating the app over the weekend after receiving reports of stolen assets linked to exposed private keys.

    Some victims had previously installed versions 1.1 or 1.2 of the Fomopeek app, which was marketed as a read-only tool for tracking large cryptocurrency transactions across Ethereum, Solana and Tron.

    What is Fomopeek?

    Working with security researchers at crypto exchange OKX, SlowMist found two modules embedded in those versions that had no connection to FomoPeek’s advertised monitoring functions.

    One communicated with external command-and-control infrastructure, while the other contained a kernel exploitation framework with eight attack methods that could adjust to the victim’s iPhone model and operating-system version.

    A successful exploit could escape Apple’s application sandbox and reach Keychain information and files belonging to other apps. That created a route to locally stored private keys, seed phrases, and login credentials without requiring users to connect a wallet or enter those details into FomoPeek.

    SlowMist founder Yu Xian said the risk extended to passwords stored in Apple’s Keychain and encrypted files held by other applications. An attacker who obtained both could potentially unlock wallet credentials and other sensitive information stored on the device.

    He explained:

    “After a successful attack, the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain (Keychain), and access data files from other apps on the device. Private keys, mnemonic phrases, login credentials, chat histories, files, and other user data stored on the device may all face the risk of leakage as a result. Additionally, the app connects to covert servers unrelated to its public business functions to receive remote instructions.”

    The malicious components were not present in FomoPeek’s original release. SlowMist found them in version 1.1, released Sept. 9, and version 1.2 on Sept. 12, before removing them in version 1.3 on Sept. 17.

    Researchers also found that the framework could receive instructions from a remote server, including settings that governed whether exploitation was enabled and how often it would run.

    Nearly $580,000 stolen

    The technical findings were followed by an on-chain trail showing that attackers had already converted that access into losses.

    Blockchain analysis firm Salus identified 0x6d37f2C5e8F8546b648D317295565dA95975f4BB as the attacker address and estimated proceeds from the incident at about 579,900 USDT.

    Salus traced 401,028 USDT through three intermediary addresses to FixedFloat. Another 20,000 USDT moved in two transactions through deposit addresses before being consolidated into a KuCoin hot wallet.

    Fomopeek Stolen Funds Movement
    A cross-chain funds-flow map traces 15 Ethereum and TRON address pairs connected through leaked transfer evidence. Source: Salus

    A further 111,458 USDT was routed through an address Salus associated with an escrow platform, while another 10,000 USDT passed through the CCE mixing service before reaching addresses linked to an escrow service.

    The Catalyst

    What’s moving crypto. Why it matters.

    Get CryptoSlate’s essential stories and what to watch next.

    Published on Substack

    Seven days a week. Unsubscribe anytime.

    Whoops, looks like there was a problem. Please try again.

    Check your inbox.

    Your signup request was sent. If confirmation is required, follow the email from Substack.

    Look in spam or promotions if you don’t see it.

    Salus said its analysis also indicated that the group behind the FomoPeek incident had been involved in a separate private-key theft in June. Investigators are still determining whether the same technique was used in that attack.

    Related Reading

    Crypto phishing scam nets $129 million in USDT then funds mysteriously return

    Crypto platforms warn users as custody debate returns

    The losses and the potential reach of the exploit have prompted warnings from several crypto platforms, including Binance, OKX, Gate, Bitget Wallet and Rabby.

    Binance warned:

    “The third-party app FomoPeek (versions 1.1–1.2) contains malicious code that can exploit iOS system vulnerabilities to gain the highest level of device privileges, potentially accessing sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, files, and more. Please note that this type of malware targets the device itself. If an attack succeeds, data from all apps on the affected device may be accessed.”

    In light of this, the crypto firms have broadly issued the same guidance, urging crypto users to remove FomoPeek, update iOS, and move assets to newly created wallets on devices where the compromised app was never installed.

    These fresh credentials are necessary because deleting the app or patching the operating system cannot invalidate a private key that may already have been copied.

    Meanwhile, the incident also comes two months after on-chain investigator ZachXBT argued that a separate iPhone dedicated to crypto could be preferable to existing hardware wallets for storing funds and signing transactions.

    His recommendation relied on keeping the device isolated from everyday browsing, messaging, and other activity that could expand the attack surface.

    FomoPeek exposes a different weakness in that model. The app was itself built for crypto users and distributed through Apple’s official marketplace, yet researchers say it contained tooling capable of breaching the barriers separating applications on the device.

    That does not establish that dedicated crypto iPhones are inherently less secure than hardware wallets. However, it shows that isolation offers limited protection if software installed on the device can compromise the operating system itself.

    For affected users, the immediate focus is now on containing further losses and tracing the stolen funds.

    Salus continues to follow addresses linked to the remaining proceeds, while Binance and other platforms monitor for deposits that could give investigators another opportunity to track or restrict the movement of the stolen USDT.

    app escapes hijack iOS iPhone rogue Sandbox USDT
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Rogue external MFA providers can steal passwords during logins

    UN Security Council Will Get Advice on AI Risks From Tech Giants Building It

    Bitcoin Investors Buy Nearly $1B In BTC ETFs

    Arch Lending Eyes Tokenized Stocks as Loan Collateral

    Inside Coinbase’s $250 Billion Playbook for Post-Quantum Bitcoin Custody

    Bitcoin Retains $86,000 as Trump Pledges US-Iran Deal After Midterms

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump, Guterres Address UNGA With Contrasting Messages

    September 23, 2026

    Did Obama ban Fox News from White House briefings? Claim distorts the facts

    September 23, 2026

    Morocco election: How Ceuta, football and Israel have shaped the campaign

    September 23, 2026

    Ukraine anger as EU removes Russian oligarchs from sanctions list

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump, Guterres Address UNGA With Contrasting Messages

    September 23, 2026

    Did Obama ban Fox News from White House briefings? Claim distorts the facts

    September 23, 2026

    Morocco election: How Ceuta, football and Israel have shaped the campaign

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.