How FomoPeek Reached the App Store With Malicious Code

People who installed FomoPeek to monitor crypto wallets may have exposed data stored in other iPhone apps. In a threat intelligence analysis published on Sept. 20, blockchain security firm SlowMist reported finding malicious modules in versions 1.1 and 1.2 distributed through the Apple App Store.

FomoPeek presented itself as a “read-only on-chain monitoring and alerting tool” that did not require users to connect a wallet or provide a seed phrase. That description concealed code capable of bypassing iPhone security protections, collecting information from other apps and sending it to a remote server, according to SlowMist. The firm and OKX’s security team investigated after receiving reports of stolen assets and exposed private keys.

To establish which downloads carried the code, investigators compared copies of FomoPeek’s App Store releases. The app and the two malicious modules had been signed by the same Apple developer identity, and the downloaded files retained App Store encryption records. That evidence placed the modules inside the officially distributed app, rather than in a copy altered after download.

SlowMist also traced funds to a wallet it identified as the attacker’s primary address. The address became active Sept. 15 and received 579,984.34 USDT across several blockchain networks, with funds still flowing in when SlowMist published its report. Investigators followed transfers through swaps and other addresses. The amount is the wallet’s total receipts, not a confirmed tally of crypto stolen through FomoPeek.

What Investigators Saw When They Tested the App

SlowMist then examined how the hidden modules operated. One retrieved an encrypted server address from Bitbucket, sent information about the iPhone, and requested instructions. The server could select data to collect and control whether the app attempted to exploit the device.

During the observed test, the server had exploitation switched off. Researchers enabled it in an isolated environment to examine the remaining steps. The app then received a list targeting 19 wallet and note-taking apps. Investigators captured an upload of the Apple Notes data container, decrypted the network traffic, and reconstructed the archive sent from the test device. Those findings show what the code could do when activated; they do not establish which data it collected from other users’ phones.

The app’s code included an exploitation strategy named DarkSwordStrategy, which shares its name with DarkSword, an iOS exploit chain documented by Google Threat Intelligence Group in March.

The threat to crypto wallets is direct: An attacker who obtains a private key or recovery phrase can access assets controlled by it. Earlier reporting on DarkSword described SlowMist’s warning that attackers could use iOS exploits to reach private keys. FomoPeek added another concern by carrying its malicious modules in official App Store releases.

Affected Versions and the Risk to Existing Wallets

SlowMist found the modules in FomoPeek version 1.1, released Sept. 9, and version 1.2, released Sept. 12. They were absent from version 1.0 and removed in version 1.3 on Sept. 17. Anyone who used either affected version may still face exposure after deleting or updating the app, as information already transmitted cannot be retrieved by removing the app.

Other fraudulent App Store downloads have put crypto holdings at risk through different methods. In July, three investors alleged losses from a counterfeit Sparrow Wallet app after entering their recovery phrases. In that case, users supplied the information directly; FomoPeek’s hidden code was designed to collect data beyond its own app.

An investigator also linked a fake Ledger app to reported crypto thefts in April. Both the Ledger and Sparrow cases involved counterfeit wallet apps. FomoPeek appeared to be a monitoring tool, so its users had no stated reason to expect it to access private information held elsewhere on their phones.

SlowMist advised users of FomoPeek versions 1.1 and 1.2 to treat seed phrases, private keys, and sensitive credentials stored on those devices as potentially compromised. While cold storage keeps keys offline, the firm’s immediate recommendation was to create a new wallet on a secure device that never ran the affected app and transfer assets from wallets whose keys may have been exposed.