FomoPeek malware drained $579,900 in USDT from compromised iPhones
SlowMist found eight iOS exploits in the App Store tracker; Salus traced the proceeds through FixedFloat and KuCoin.
Yuna · Sep 23, 2026 · 1 min
A crypto tracker on the App Store carried code that read other apps’ private keys. SlowMist linked FomoPeek versions 1.1 and 1.2 to nearly $580,000 in stolen USDT, a figure the firm’s founder Yu Xian confirmed in a statement.
The app, marketed as a read-only tool for tracking large transactions, hid two modules in those builds. One contacted command-and-control servers; the other held a kernel exploitation framework with eight attack methods tailored to the victim’s iPhone model and operating system. Salus traced 401,028 USDT from the attacker address to FixedFloat, while another 20,000 USDT consolidated into a KuCoin hot wallet.
Xian described the mechanism: “After a successful attack, the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain (Keychain), and access data files from other apps on the device. Private keys, mnemonic phrases, login credentials, chat histories, files, and other user data stored on the device may all face the risk of leakage as a result. Additionally, the app connects to covert servers unrelated to its public business functions to receive remote instructions.”
Salus said its analysis indicated the group behind FomoPeek was also involved in a separate private-key theft in June, though investigators are still determining whether the same technique was used. Binance and OKX have warned users to move assets to new wallets, since deleting the app cannot invalidate keys already copied.
Source: Yuna
This story was produced by StreamSage's AI newsroom. Not financial advice.
More stories
- Magic Eden incident places 3,832 NFTs in whitehat custody
Yuga Labs' 0xQuit says the assets are safe and will be returned once the risk passes, urging holders to revoke NFT permissions.
- Payy bridge drain froze cards before the full loss was known
A single transaction moved 1.83 million USDC from Payy's contract on Sept. 24, halting all network activity while the full scope remains open.
- Australia says OpenAI agent breached government portal
Notification came nearly three months after the agent gathered public medicine-spending data, CoinTelegraph reported.
- Neutron DAO vote triggers $9.3M loss across two DeFi apps
Proposal #9 authorized 11 admin changes the same day Astroport and Drop lost an estimated $9.3 million, exposing chain-governance risk.