A malicious iPhone application distributed through Apple’s App Store has been linked to the theft of nearly $580,000 in USDT after exploiting vulnerabilities that could allow it to escape Apple’s iOS security protections.
Blockchain security firm SlowMist began investigating FomoPeek over the weekend after receiving reports of stolen assets connected to exposed private keys. The app was promoted as a read-only service for tracking large cryptocurrency transactions on Ethereum, Solana and Tron.
SlowMist, working with security researchers from crypto exchange OKX, found two unrelated modules inside versions 1.1 and 1.2 of the app. One communicated with external command-and-control servers, while the other contained a kernel exploitation framework with eight attack methods designed to adapt to a user’s iPhone model and operating-system version.
The malicious components were absent from the original release. They appeared in version 1.1, issued on Sept. 9, and version 1.2, released on Sept. 12. They were removed in version 1.3 on Sept. 17.
A successful attack could break through iOS application sandboxing and access Keychain data and files belonging to other apps. That potentially exposed locally stored private keys, seed phrases and login credentials without requiring users to connect a wallet or enter those details into FomoPeek.
SlowMist founder Yu Xian said passwords held in Apple’s Keychain and encrypted files stored by other applications could also be at risk.
“After a successful attack, the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain (Keychain), and access data files from other apps on the device,” he said.
“Private keys, mnemonic phrases, login credentials, chat histories, files, and other user data stored on the device may all face the risk of leakage as a result. Additionally, the app connects to covert servers unrelated to its public business functions to receive remote instructions.”
Researchers said the framework could be controlled remotely, with servers able to determine whether exploitation was enabled and how frequently it would run.
Blockchain trail reveals losses
Blockchain analysis firm Salus identified 0x6d37f2C5e8F8546b648D317295565dA95975f4BB as the suspected attacker address and estimated the proceeds at about 579,900 USDT.
It traced 401,028 USDT through three intermediary addresses to FixedFloat. A further 20,000 USDT moved in two transactions through deposit addresses before being consolidated into a KuCoin hot wallet.
Salus also linked 111,458 USDT to an address associated with an escrow platform, while another 10,000 USDT passed through the CCE mixing service before reaching addresses connected to an escrow service. Its cross-chain map identified 15 Ethereum and TRON address pairs connected through leaked transfer evidence.
Salus said the group may also have been involved in a separate private-key theft in June, although investigators are still assessing whether the same method was used.
Binance, OKX, Gate, Bitget Wallet and Rabby have warned users to remove FomoPeek, update iOS and transfer assets to newly created wallets on devices where the app was never installed. Deleting the app or updating the operating system cannot invalidate a private key that may already have been copied.
The incident came two months after on-chain investigator ZachXBT said a separate iPhone dedicated to cryptocurrency could be preferable to existing hardware wallets if kept isolated from daily browsing and messaging.
However, FomoPeek showed that isolation may offer limited protection if installed software can compromise the operating system. Salus continues to track the remaining funds, while Binance and other platforms monitor deposits linked to the stolen USDT.
