← All stories
đŸ“±

Mobile apps and iOS exploits: private keys at risk

The FomoPeek cluster of reports highlights a significant escalation in mobile threats to self‑custody crypto users. Security teams including SlowMist and OKX concluded that FomoPeek versions 1.1 and 1.2 bundled a sophisticated iOS kernel exploitation framework that relied on eight separate exploit methods. Researchers mapped the framework’s declared coverage to devices running iOS 12.0–18.7.2 and 26.0–26.1, and found that the malicious code could escape the iOS sandbox, decrypt Keychain contents and access data held by other applications — including private keys, seed phrases, login credentials, chats and files.

Analysis showed the malicious modules were active in the distributed builds rather than dormant, communicating with infrastructure unrelated to FomoPeek’s public services and able to receive remote instructions to control exploit execution and frequency. Historical app analysis revealed the two malicious modules were absent in FomoPeek 1.0, introduced in 1.1 (build 105) on Sept. 9, retained in 1.2 (build 110) on Sept. 12, and removed in 1.3 (build 111) on Sept. 17. Crucially, the affected 1.1 and 1.2 builds were distributed via Apple’s official App Store.

Industry responses echoed the technical findings. Binance, SlowMist and OKX all advised users who installed FomoPeek to remove the app, avoid reinstalling it, update iOS to the latest available version, and generate new wallets on devices that never had FomoPeek installed before transferring assets. The guidance emphasizes treating keys created or stored on compromised devices as exposed and moving funds to newly generated addresses on clean hardware. Users detecting unusual activity were told to preserve affected devices and evidence before contacting support.

Contextual reporting also ties FomoPeek into a broader pattern of mobile threats against crypto wallets. Prior incidents include a fake app called BOM that reportedly compromised over 13,000 wallets with estimated losses around $1.82 million, campaigns involving SparkKitty and SparkCat that scanned images and used OCR for recovery phrases, and multiple fake wallet apps distributed through official stores; one fake Ledger listing was linked to roughly $9.3 million stolen across victims, and another incident described the loss of about 5.9 BTC from an individual who entered a recovery phrase into a fraudulent application. Unlike impersonation scams that rely on users pasting phrases, FomoPeek demonstrates attackers leveraging OS‑level exploits to collect credentials without explicit user input.

The practical takeaway is straightforward: a useful, read‑only app can still be dangerous if it carries kernel‑level exploits. Protecting assets requires system hygiene, device isolation, creating keys only on clean devices, minimizing hot wallet balances, and revoking approvals where appropriate. The FomoPeek findings underscore that social engineering plus technical exploit capability can bypass assumptions of App Store safety and that custodial responsibility demands layered, physical and procedural defenses.

This summary is composed by the cFlash AI agent from multiple public sources, under human supervision. The content is for informational purposes only and does not constitute investment, financial, legal, or tax advice.

Sources