An iPhone app marketed as a read-only cryptocurrency monitoring tool contained malicious code that could access information held by other apps, including wallet data, researchers have found.
SlowMist, a blockchain security firm, said versions 1.1 and 1.2 of FomoPeek, distributed through the Apple App Store, included hidden modules capable of bypassing iPhone protections, gathering sensitive information and sending it to a remote server.
A wallet identified by investigators as belonging to the attacker received 579,984.34 USDT across several blockchain networks. The address became active on 15 September and was still receiving funds when SlowMist published its threat intelligence analysis on 20 September.
However, the figure represents the wallet’s total receipts and is not a confirmed calculation of cryptocurrency stolen through FomoPeek.
FomoPeek described itself as a “read-only on-chain monitoring and alerting tool”. It did not require users to connect a wallet or enter a seed phrase. SlowMist and OKX’s security team began investigating after reports of stolen assets and exposed private keys.
How the code operated
Researchers compared different App Store releases to establish how the malicious components had been distributed. The app and both modules had been signed using the same Apple developer identity, while the downloaded files retained App Store encryption records.
That evidence indicated the code was included in the officially distributed app, rather than being added to a copy after it had been downloaded.
One module retrieved an encrypted server address from Bitbucket, sent information about the iPhone and waited for further instructions. The server could determine which data should be collected and whether the app should attempt to exploit the device.
During the test observed by researchers, exploitation was disabled. SlowMist enabled the function in an isolated environment and found that the app received a list targeting 19 wallet and note-taking applications.
Investigators captured the upload of an Apple Notes data container, decrypted the network traffic and reconstructed the archive sent from the test iPhone. The test demonstrated what the code was capable of doing when activated, but did not show which information had been collected from other users’ devices.
The code also contained an exploitation strategy called DarkSwordStrategy, the same name used by DarkSword, an iOS exploit chain documented by Google Threat Intelligence Group in March.
The affected versions were released on 9 September and 12 September. The modules were not present in version 1.0 and were removed in version 1.3 on 17 September.
SlowMist said deleting or updating FomoPeek might not remove the risk, because information already transmitted could not be recovered. It advised users of versions 1.1 and 1.2 to assume that seed phrases, private keys and other sensitive credentials stored on those devices may have been compromised.
The firm recommended creating a new wallet on a secure device that had never run the affected app, then transferring assets from wallets whose keys may have been exposed. Cold storage keeps keys offline, but any credentials held on a device running FomoPeek could still be at risk.
Other fraudulent App Store apps have also targeted cryptocurrency users. In July, three investors alleged losses involving a counterfeit Sparrow Wallet app after entering their recovery phrases, while a fake Ledger app was linked by an investigator to reported cryptocurrency thefts in April. Those cases involved counterfeit wallet applications; FomoPeek presented itself as a monitoring tool, giving users no stated reason to expect it to access information in other apps.
