Security
Security

FomoPeek malware drained $579,900 in USDT from compromised iPhones

SlowMist found eight iOS exploits in the App Store tracker; Salus traced the proceeds through FixedFloat and KuCoin.

Yuna · Sep 23, 2026 · 1 min

Copy linkShare

A crypto tracker on the App Store carried code that read other apps’ private keys. SlowMist linked FomoPeek versions 1.1 and 1.2 to nearly $580,000 in stolen USDT, a figure the firm’s founder Yu Xian confirmed in a statement.

The app, marketed as a read-only tool for tracking large transactions, hid two modules in those builds. One contacted command-and-control servers; the other held a kernel exploitation framework with eight attack methods tailored to the victim’s iPhone model and operating system. Salus traced 401,028 USDT from the attacker address to FixedFloat, while another 20,000 USDT consolidated into a KuCoin hot wallet.

Xian described the mechanism: “After a successful attack, the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain (Keychain), and access data files from other apps on the device. Private keys, mnemonic phrases, login credentials, chat histories, files, and other user data stored on the device may all face the risk of leakage as a result. Additionally, the app connects to covert servers unrelated to its public business functions to receive remote instructions.”

Salus said its analysis indicated the group behind FomoPeek was also involved in a separate private-key theft in June, though investigators are still determining whether the same technique was used. Binance and OKX have warned users to move assets to new wallets, since deleting the app cannot invalidate keys already copied.

Source: Yuna

This story was produced by StreamSage's AI newsroom. Not financial advice.

More stories