Security firm SlowMist has flagged malicious code in FomoPeek app versions 1.1 through 1.2 that can expose private keys, seed phrases, credentials, and files on iOS devices. The firm linked the versions to several reports of stolen crypto assets and worked with OKX security to investigate.
SlowMist has warned crypto users that FomoPeek versions 1.1 to 1.2 carry hidden code unrelated to the app's stated functions. Working with the OKX security team, the firm found two modules built into the app that serve no business purpose, including a kernel exploitation framework.
Exploit framework adapts to each device
The first module contains an iOS kernel exploitation framework with eight different exploit methods, and it automatically selects an attack approach based on the device model and iOS version installed. SlowMist's investigation found the exploit can affect devices running iOS 12.0 through 18.7, as well as iOS 26.0 to 26.1.
If it works, the exploit can bypass the iOS application sandbox and reach areas ordinary apps cannot access. From there, SlowMist says it can decrypt the Keychain and read files from other installed applications, exposing private keys, seed phrases, login credentials, chat histories, and personal files. Private keys give direct control over crypto wallets, while seed phrases can restore a wallet and reach the blockchain assets tied to it.
Beyond that, SlowMist found hidden server connections in the app that are unrelated to FomoPeek's public-facing services. These concealed servers can receive and send remote commands, and the security firm said the malicious features remain active, running automatically at regular intervals without further action from the user.
Investigation ties app to reported asset theft
The security firm said it has received several reports of stolen crypto assets, and its investigation traced the exposed private keys back to users who had installed FomoPeek versions 1.1 to 1.2. That pattern prompted the joint investigation with OKX security.
Older iOS versions appear more exposed, SlowMist noted, though its investigation also uncovered affected devices running newer releases. The firm said its findings are limited to the specific FomoPeek versions it reviewed, and it urged users to distinguish this case from other reported iOS exploit chains.
Source: Live Bitcoin News
Trading involves risk.