Malicious iOS app linked to crypto theft after escaping Apple’s sandbox
Cointelegraph reported that FomoPeek, an iOS application distributed through Apple’s App Store, was linked by researchers to nearly $580,000 in stolen cryptocurrency. The report was based on an investigation from blockchain security firm SlowMist, which analyzed versions 1.1 and 1.2 after users reported unexplained asset losses.
The central risk was not a fake wallet-connect prompt or a user voluntarily entering a seed phrase. Researchers said the affected versions contained two hidden modules capable of exploiting vulnerabilities in iOS. If successful, the exploit chain could escape the normal application sandbox, obtain elevated device privileges and reach information stored outside FomoPeek itself.
Why a “read-only” app could still threaten wallets
FomoPeek was presented as a tool for monitoring blockchain activity. That description may have made the app appear lower risk because it did not need to control a wallet directly. SlowMist’s analysis, however, indicated that the malicious components could access Keychain data and files belonging to other applications. That potentially exposed private keys, recovery phrases, login credentials, notes and other sensitive material stored on the same device.
The researchers also described remote-control behavior. The malicious modules could communicate with concealed servers and receive configuration instructions, meaning the behavior did not need to remain identical every time the app ran. This is why the incident is treated as a device-level compromise rather than a problem isolated to one application.
What affected users should understand
Deleting the application stops future use, but it cannot make previously exposed credentials secret again. Anyone who installed an affected version should treat relevant wallet credentials as potentially compromised, update iOS, review accounts for unexpected activity, and create new wallet keys on a separate clean device before migrating assets.
The reported loss figure and technical conclusions reflect information available when Cointelegraph published its report. Users should continue checking the latest notices from SlowMist, Binance Wallet and other official security channels.
