- Security firm SlowMist says two versions of an iPhone app called FomoPeek, distributed through Apple’s App Store, contained hidden code aimed at data stored on the device.
- A separate analytics firm, Salus, traces roughly 579,900 USDT to an address it attributes to the attacker. That is an estimate of outflows, not an audited loss figure.
- Binance, OKX, Gate, Bitget Wallet and Rabby have told users to delete the app, update iOS and move funds to new wallets on a clean device.
The standard advice about dodgy crypto apps is to download only from the official app store. This one was in the official app store, installed the ordinary way on an iPhone, and researchers say it was quietly reaching for while advertising itself as a read-only transaction tracker.
Sticking to the App Store is the one instruction nearly every safety guide gives, on the basis that Apple reviews what goes in. On this account, that review passed an app carrying code built to defeat the protections iPhones rely on. Anybody who installed it followed the advice as written.
If you had FomoPeek on your phone at any point in September, the practical position is straightforward: treat any wallet whose keys or lived on that device as compromised, and move the funds to a new wallet created on a different, clean device.
What the researchers say they found
FomoPeek was marketed as a monitoring tool, a way to watch large transactions on Ethereum, Solana and Tron. Nothing about that job requires a wallet connection, a seed phrase or a password, which is part of why the app looked harmless.
SlowMist began looking at it after reports of stolen assets linked to exposed private keys. Working with security researchers at the exchange OKX, it says it found two modules in versions 1.1 and 1.2 that had nothing to do with transaction monitoring. One talked to external command-and-control infrastructure. The other was a kernel exploitation framework with eight attack methods that could adapt to the victim’s iPhone model and iOS version.
Every app on an iPhone runs inside a sandbox, a walled-off area where it can see its own files and almost nothing else. That wall is the reason one app cannot read another app’s data, and it is why a wallet app can store a key on the same phone as everything else you have installed.
SlowMist founder Yu Xian said “the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain”. The keychain is where iOS holds passwords and credentials, and where plenty of wallet apps store the key material that controls the coins.
Binance, issuing its own advisory, put it this way: “The third-party app FomoPeek (versions 1.1–1.2) contains malicious code that can exploit iOS system vulnerabilities to gain the highest level of device privileges”.
Two things are worth separating here. Investigators are describing what the framework was built to do. They have not published evidence that every one of those eight methods succeeded against every device and iOS combination in the wild, and the number of people actually affected has not been stated by anyone.
The money, and who is claiming it
The $580,000 in the headlines elsewhere comes from Salus, a analysis firm that identified an address it attributes to the attacker and put the proceeds at roughly 579,900 USDT. Salus also says it traced funds through intermediary addresses to FixedFloat, a KuCoin hot wallet, an escrow platform and the CCE mixing service, and that the same group may have been behind a separate private-key theft in June.
Salus itself describes that June link as unconfirmed. Neither SlowMist nor OKX has corroborated the attribution publicly, and the USDT total is a measure of traced outflows rather than a jointly verified figure for what holders lost. It may move in either direction.
We could not read the original SlowMist and Yu Xian posts directly, because access to the platform was blocked. Everything above is relayed through CryptoSlate’s account of them.
How this differs from the usual version of this story

Most crypto app thefts follow a familiar shape. A fake wallet app is sideloaded from a website or a third-party Android store, or a phishing site asks you to connect a wallet and sign a transaction you do not understand. The defence is behavioural: do not sideload, do not connect, read what you are signing.
None of that applies here. On the researchers’ account, the app never needed you to connect a wallet or type anything in, because it went after material already sitting on the phone. That shifts the failure point from the user’s judgement to the review process that let the app onto the store, and to whoever shipped it.
If you had the app installed
Delete it, update iOS, and assume anything stored on that phone is exposed. Create new wallets on a device that never had FomoPeek on it and move funds there rather than reusing existing addresses. Where you have granted approvals to contracts from an affected wallet, revoking them limits what can be drained later.
A legitimate wallet app will never ask for your seed phrase to “verify”, “restore” or “sync” anything, and a monitoring app has no reason to ask at all. Our guide to self-custody covers how keys are stored and what a clean setup looks like.
In the UK, losses of this kind can be reported to Action Fraud, which passes reports to the National Fraud Intelligence Bureau. Reporting rarely recovers money on its own, but it is how the scale of an incident gets counted.
What to watch
Whether Apple says anything. As of now there is no public acknowledgement from the company about the app’s removal, its review process, or how code of this kind cleared it. That silence is the substantive open question, and it matters more than the exact size of the theft.
Also whether a second firm independently confirms Salus’s attacker address and routing, and whether any of the funds are frozen at the exchanges they passed through. Until that happens, treat 579,900 USDT as one firm’s reading of the chain.