Source: Binance Wallet Official Security Advisory
⚠ IPHONE / IPAD USERS

Have You Installed
FomoPeek?

Specific versions of this app were reported to contain malicious code capable of gaining high-level device access and exposing private keys, seed phrases, and login credentials.

Binance Wallet Security Advisory
KEY RISKDEVICE LEVEL

This is a device-level risk, not just a single-wallet risk

If exploited, data from other apps on the affected device—including chats and files—may also be exposed.

BINANCE WALLET ORIGINAL
“Delete the FomoPeek app and do not reinstall it. Update your iOS to the latest available version.”
— Binance Wallet Security Advisory
Illustration of device-level malware attempting to reach a crypto wallet inside an iPhone
Editorial illustration — device-level malware can expose more than one wallet or app.
MAIN REPORT · COINTELEGRAPH

Malicious iOS app linked to crypto theft after escaping Apple’s sandbox

4 MIN READ
Reported Sep 23, 2026Read the original report ↗

Cointelegraph reported that FomoPeek, an iOS application distributed through Apple’s App Store, was linked by researchers to nearly $580,000 in stolen cryptocurrency. The report was based on an investigation from blockchain security firm SlowMist, which analyzed versions 1.1 and 1.2 after users reported unexplained asset losses.

The central risk was not a fake wallet-connect prompt or a user voluntarily entering a seed phrase. Researchers said the affected versions contained two hidden modules capable of exploiting vulnerabilities in iOS. If successful, the exploit chain could escape the normal application sandbox, obtain elevated device privileges and reach information stored outside FomoPeek itself.

Why a “read-only” app could still threaten wallets

FomoPeek was presented as a tool for monitoring blockchain activity. That description may have made the app appear lower risk because it did not need to control a wallet directly. SlowMist’s analysis, however, indicated that the malicious components could access Keychain data and files belonging to other applications. That potentially exposed private keys, recovery phrases, login credentials, notes and other sensitive material stored on the same device.

The researchers also described remote-control behavior. The malicious modules could communicate with concealed servers and receive configuration instructions, meaning the behavior did not need to remain identical every time the app ran. This is why the incident is treated as a device-level compromise rather than a problem isolated to one application.

What affected users should understand

Deleting the application stops future use, but it cannot make previously exposed credentials secret again. Anyone who installed an affected version should treat relevant wallet credentials as potentially compromised, update iOS, review accounts for unexpected activity, and create new wallet keys on a separate clean device before migrating assets.

The reported loss figure and technical conclusions reflect information available when Cointelegraph published its report. Users should continue checking the latest notices from SlowMist, Binance Wallet and other official security channels.

ORIGINAL EXCERPTS

Source comments & reactions

3 SOURCES
COMMUNITY REACTION
“Imagine downloading an application just to monitor ‘whales’ freely moving their coins, only to lose yours in the process.”
Bitcointalk community member ↗

Community comments are personal opinions. Official notices and security research should carry more weight when assessing risk.

10-Second Risk Check

1. Are you using an iPhone or iPad?

2. Have you ever installed FomoPeek 1.1–1.2?

If both conditions apply, act immediately

1

Delete FomoPeek and do not reinstall it

Stop using the app immediately, but do not assume deletion alone fully removes the risk.

2

Update iOS to the latest available version

Check System Settings and install Apple security updates promptly.

3

Create a new wallet on a clean device and migrate assets

Self-custody users should create a new wallet on a device that never had the app installed, then transfer assets to the new address.

4

Preserve the device and evidence if anomalies appear

If suspicious asset activity appears, preserve the affected device, transaction records, and related evidence, then contact Binance Support.

Potentially Exposed Information

The official advisory lists risks including, but not limited to:

Private keys and seed phrasesLogin credentialsChat historyFiles on the device

This page is a structured summary of Binance Wallet’s official advisory. It does not replace the original notice, security-firm analysis, or professional incident response.

View official source ↗