A malicious iOS application distributed through Apple’s App Store has been linked to approximately $580,000 in stolen cryptocurrency after researchers identified it contained multiple kernel exploits capable of escaping Apple’s sandbox restrictions and accessing sensitive wallet data.
Blockchain security firm SlowMist published an investigation into the app, called FomoPeek, which it said carried two malicious modules able to exploit iOS vulnerabilities, elevate privileges and access Keychain data and files belonging to other apps. The affected versions were released on Sept. 9 and Sept. 12. A subsequent version, 1.3, was released on Sept. 17 with the malicious components removed, SlowMist said.
The firm’s investigation, conducted jointly with the OKX security team, began after users reported asset theft and disclosed prior installation of the affected FomoPeek builds.
The exploit framework included eight attack methods and claimed support for iOS versions ranging from 12.0 to 18.7.2, as well as versions 26.0 to 26.1, SlowMist said.
Onchain analysis by SlowMist identified a primary hacker address associated with the theft that received roughly 579,984 USDT. The address became active on Sept. 15, and the stolen funds moved across multiple blockchain networks before being consolidated and routed through several addresses and services, according to the firm.
Portions of the funds were directed toward services including FixedFloat, KuCoin and cce.cash, while additional funds were dispersed through other addresses that SlowMist continued to trace.
Apple, SlowMist and OKX were contacted for comment but did not respond before publication.












