Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Tether

    SlowMist: FomoPeek iOS Malware Tied to $580K Crypto Theft

    3 minutes ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Slowmist: Fomopeek Ios Malware Tied To $580k Crypto Theft
    Slowmist: Fomopeek Ios Malware Tied To $580k Crypto Theft

    Apple’s App Store has once again been used as a delivery channel for a crypto theft operation. According to an investigation by blockchain security firm SlowMist, a malicious iOS app named FomoPeek was linked to nearly $580,000 in stolen crypto, with the attackers using kernel-level exploits to break out of Apple’s sandbox and reach sensitive wallet data.

    SlowMist says the compromise targeted specific app versions, while a later release removed the malicious components. The incident highlights a persistent risk for mobile users: even when an app is distributed through official stores, flaws at the operating-system level can enable attackers to access data that should remain protected.

    Key takeaways

    • SlowMist links FomoPeek to about 579,984 USDT stolen after the app contained kernel exploits capable of escaping iOS sandbox protections.
    • Only certain versions were affected: SlowMist points to releases on Sept. 9 and Sept. 12, with version 1.3 released on Sept. 17 removing the malicious modules.
    • The malicious code targeted protected data: researchers report access to iOS Keychain data and files belonging to other apps.
    • Onchain tracing shows cross-network movement: funds were routed through multiple blockchains and later consolidated through several addresses and services.

    What SlowMist found inside the FomoPeek app

    In its threat intelligence analysis, SlowMist said FomoPeek included multiple malicious modules designed to exploit iOS vulnerabilities. The goal, according to the report, was to gain elevated privileges and escape the constraints of Apple’s application sandbox.

    Once the app achieved this elevated access, SlowMist reports it could reach Keychain data as well as files belonging to other apps. For users, that matters because Keychain entries often store credentials and other sensitive material used by wallets and related services—data that normally remains isolated from third-party applications.

    SlowMist said the malicious components were part of the app releases issued on Sept. 9 and Sept. 12. The firm added that version 1.3, released on Sept. 17, removed the harmful elements.

    Release timing and the window of exposure

    SlowMist’s timeline indicates the attack depended on users installing (or keeping) the affected FomoPeek versions rather than a permanently compromised build. The firm said its investigation began after it received reports from users who experienced asset theft and confirmed that at least some of those users had installed one of the vulnerable releases.

    This distinction is important for practical risk management. Even if a malicious app is later patched or sanitized, the harm can already be done during the earlier window—especially when the app can exploit kernel weaknesses and access protected data. For mobile users and wallet operators, the lesson is that version-by-version scrutiny can be just as critical as store-level distribution.

    Exploit framework details and affected iOS ranges

    SlowMist said the exploit framework it observed featured eight attack methods. The report describes intended support for a broad set of iOS versions, including 12.0 to 18.7.2 and 26.0 to 26.1.

    The breadth of those ranges underscores why kernel exploitation is so difficult to contain. When an attacker can target multiple configurations, the same malicious app can potentially work across a larger portion of the installed base, increasing the likelihood of successful compromise.

    Onchain analysis: nearly $580,000 in stolen crypto

    Beyond the app-side findings, SlowMist analyzed the associated blockchain activity. The firm identified a primary hacker address tied to the incident that received approximately 579,984 USDT.

    According to SlowMist, the address became active on Sept. 15—after the initial affected releases—suggesting the theft activity followed the period during which users could have installed vulnerable versions. SlowMist further said the stolen funds were spread across multiple blockchain networks before being consolidated through additional addresses and services.

    SlowMist reported that portions of the funds were routed toward services including FixedFloat, KuCoin, and cce.cash, while other portions were dispersed through additional addresses that the firm continued to trace.

    For investors, traders, and compliance teams, this pattern is typical of efforts to obscure fund trails: attackers frequently move value across networks, fragment flows through intermediaries, and then consolidate proceeds in ways that make attribution harder.

    Attempts to get responses

    Cointelegraph said it reached out to Apple, SlowMist, and OKX for comment. The outlet reported that it did not receive a response before publication.

    SlowMist’s investigation was conducted together with the OKX security team, according to the report. The collaboration points to how incident response in crypto increasingly blends onchain forensics with software security research—especially when attacks originate in mainstream distribution channels like app stores.

    Users who installed FomoPeek on iOS versions before the reported removal on Sept. 17 should consider reviewing wallet permissions and checking whether any accounts show unauthorized activity. The key uncertainty going forward is whether additional malicious versions or related packages exist outside the specific releases SlowMist identified—and whether Apple or the broader mobile security community will accelerate defenses against kernel-exploit delivery through app-store software.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Blackrock Says Ai Could Spur Crypto Demand, Despite Low Focus

    BlackRock Says AI Could Spur Crypto Demand, Despite Low Focus

    1 hour ago
    Canada’s Top Six Banks Investigate Tokenized Cad Deposits

    Canada’s Top Six Banks Investigate Tokenized CAD Deposits

    2 hours ago
    Republican Senator Seeks Probe Of Presidents’ Sons Linked To Crypto

    Republican Senator Seeks Probe of Presidents’ Sons Linked to Crypto

    3 hours ago
    Cftc Warns On Risky Prediction Market “mention” Contracts

    CFTC Warns on Risky Prediction Market “Mention” Contracts

    4 hours ago
    Cftc Warns On Risky Prediction Market “mention” Contracts

    CFTC Warns on Risky Prediction Market “Mention” Contracts

    5 hours ago
    Arch Lending Targets Tokenized Stocks As Next Collateral Market

    Arch Lending Targets Tokenized Stocks as Next Collateral Market

    6 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    7 September 2026

    Latest News

    • SlowMist: FomoPeek iOS Malware Tied to $580K Crypto Theft
    • BlackRock Says AI Could Spur Crypto Demand, Despite Low Focus
    • Canada’s Top Six Banks Investigate Tokenized CAD Deposits
    • Republican Senator Seeks Probe of Presidents’ Sons Linked to Crypto
    • CFTC Warns on Risky Prediction Market “Mention” Contracts
    • CFTC Warns on Risky Prediction Market “Mention” Contracts
    • Arch Lending Targets Tokenized Stocks as Next Collateral Market
    • Republican Senator Demands Probe of Presidents’ Sons Over Crypto Deals
    • Arch Lending Signals Tokenized Stocks as Next Collateral Asset
    • Canada’s Major Banks Pilot Tokenized CAD Deposits for Settlement

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Kraken Pro 300x250
    Crypto.com

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    AVATRADE
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!