Weather     Live Markets

How FomoPeek Reached the App Store With Malicious Code—and What Crypto Users Need to Know

A ‘Read-Only’ Crypto Monitor With a Hidden Mission

On Sept. 20, blockchain security firm SlowMist published a threat intelligence analysis that landed like a warning flare for the crypto community. The company reported finding malicious modules in FomoPeek, an iPhone app designed to monitor on-chain wallet activity. Versions 1.1 and 1.2 of the app, both distributed through Apple’s official App Store, contained code capable of bypassing iPhone security protections and collecting data from other applications installed on the device. The app marketed itself as a “read-only on-chain monitoring and alerting tool,” a description meant to reassure users that it did not require a wallet connection or seed phrase. In reality, according to SlowMist, FomoPeek was doing far more than reading blockchain data.

Investigators from SlowMist and OKX’s security team began looking into the app after receiving reports of stolen assets and exposed private keys. What they found was a carefully constructed piece of malicious software, signed and distributed through the same trusted channel that iPhone users have been taught to rely on. Unlike a counterfeit wallet app or a phishing site that tricks users into entering recovery phrases, FomoPeek was designed to quietly gather information from the victim’s phone and send it to a remote server. The discovery marks one of the more concerning examples of a crypto-related app slipping malicious code past Apple’s App Store review process. It also raises a difficult question for users who thought that downloading an app from Apple’s curated marketplace was enough of a security guarantee.

The app’s “read-only” positioning was key to its deceptive power. Many crypto holders are understandably wary of tools that ask for private keys or recovery phrases. FomoPeek made a point of not asking for those things, which made it look safer than many other wallet services. But the absence of user-supplied credentials did not mean the app was harmless. Under the surface, the binary contained modules that could reach into other apps, collect data, and potentially exploit the device itself. For anyone who installed FomoPeek to monitor their wallets, the very feature that made it seem convenient may have put their assets at risk.

How Investigators Tied the Malicious Code to Official App Store Builds

The first challenge for SlowMist’s researchers was proving that the malicious code was actually part of the App Store release. Cybercriminals sometimes distribute clean apps and then inject malware through updates or sideloaded modifications, but that was not the case here. Investigators compared copies of FomoPeek’s App Store releases and found that the app and the malicious modules had been signed by the same Apple developer identity. The downloaded files also retained App Store encryption records. Together, that evidence placed the modules inside the officially distributed binary rather than in a version modified after download. In other words, the FomoPeek that users downloaded from Apple’s App Store was dangerous out of the box.

The financial trail was no less revealing. SlowMist traced funds to a wallet identified as the attacker’s primary address. The wallet became active on Sept. 15 and had received 579,984.34 USDT across several blockchain networks by the time the report was published. Funds were still flowing into the wallet when the analysis went public. Investigators followed the transfers through swaps and other addresses, mapping out a web of transactions designed to move stolen value. SlowMist was careful to note that the figure represented the wallet’s total receipts, not a confirmed tally of crypto stolen specifically through FomoPeek. Still, the timing and movement of funds added another dimension to the investigation, suggesting that the operation was active and generating revenue.

The combination of forensic evidence and on-chain analysis paints a picture of a well-resourced attacker. Using the same Apple developer identity for the app and its payload ensures that the malicious components remain consistent with the signed binary, making them harder to isolate. The App Store encryption records, which are designed to protect intellectual property and verify distribution, inadvertently became a crucial piece of evidence for investigators. It is a reminder that in the world of mobile malware, every layer of platform security can leave forensic traces.

Inside the Attack Chain: Data Collection, Command-and-Control, and an iOS Exploit Named DarkSword

SlowMist’s technical analysis revealed a multi-stage operation designed for flexibility. One of the malicious modules retrieved an encrypted server address from Bitbucket, a code-hosting platform that is not normally associated with malware. The module then sent information about the iPhone to that server and requested instructions. The server could select which data to collect and, more worryingly, could decide whether the app should attempt an exploit against the device. This gave the attacker fine-grained control over each infected phone. A user could be monitored silently for weeks, or the operation could shift into a more aggressive mode at any moment.

During SlowMist’s observed test, the server had the exploitation feature turned off. Researchers enabled it in an isolated lab environment to study the remaining steps of the attack chain. Once activated, the app received a list targeting 19 wallet and note-taking apps installed on the device. The list itself is a strong indicator of the attacker’s goals: crypto wallets hold private keys and recovery phrases, while note-taking apps often contain secrets, passwords, and other sensitive text that users have stored for convenience. The researchers captured an upload of the Apple Notes data container, decrypted the network traffic, and reconstructed the archive sent from the test device. That exercise showed precisely what the code could do when instructed to do so, although it did not establish which data FomoPeek collected from other users’ phones.

The code also included an exploitation strategy named DarkSwordStrategy, a direct reference to DarkSword, an iOS exploit chain documented by Google Threat Intelligence Group in March. The reuse of publicly disclosed exploit techniques is not unusual in cybercrime, but it is notable in a crypto app distributed through the App Store. It suggests that the operator had access to sophisticated security research and was willing to use the most powerful tools in the iOS attacker’s arsenal. For the average user, the implications are stark: FomoPeek was not merely harvesting contract addresses or token balances. It was built to reach through the iPhone’s security model and pull sensitive data from other applications.

The Direct Threat to Crypto Wallets

For crypto users, the danger of FomoPeek is easy to understand. Anyone who obtains a private key or recovery phrase can gain full control of the associated wallet. This is the fundamental vulnerability of self-custody: the keys are the asset, and whoever holds them is the owner. Apps like FomoPeek are dangerous because they provide a route to those keys without the user ever realizing that anything is wrong. By posing as a read-only monitoring tool, the app bypassed the psychological defenses that many users have developed against wallet-drainer scams.

Earlier reporting on the DarkSword exploit chain had already described SlowMist’s warning that attackers could use iOS exploits to reach private keys stored on mobile devices. FomoPeek brought that risk into the App Store. The app’s malicious modules were designed to access data from other apps, including potentially the data containers used by wallet applications and note-taking tools. If a user had stored a seed phrase in Apple Notes, for example, the malicious code was technically capable of retrieving that information and sending it to the attacker’s server. Even users who never entered a single detail into FomoPeek could be compromised. This is a fundamentally different threat model from a fake wallet app that simply asks users to enter their recovery phrase.

The fact that FomoPeek was available in the App Store adds another layer of concern. The App Store has long been marketed as a closed, controlled environment where apps are reviewed before distribution. That reputation is not entirely undeserved, but FomoPeek demonstrates that malicious code can still slip through. The attackers did not need to convince users to enable developer mode or install a profile from an unknown website. They simply published an app that looked legitimate, wrapped it in a plausible feature set, and waited for victims to find it. For crypto investors, this undermines the assumption that an App Store badge is a reliable shield against malware.

Affected Versions, Fake Wallet Ancestors, and the App Store Problem

SlowMist found the malicious modules in FomoPeek version 1.1, released on Sept. 9, and version 1.2, released on Sept. 12. The modules were not present in version 1.0, and they were removed in version 1.3 on Sept. 17. That timeline suggests the attacker may have added the malicious code after the initial version passed review, then quietly removed it after enough devices were infected. For users, the narrow window of affected versions does not reduce the risk. Anyone who used either version during that period may still be exposed even after deleting or updating the app, because data already transmitted to the attacker cannot be retrieved by removing the software.

FomoPeek is the latest in a string of fraudulent apps targeting crypto users. In July, three investors alleged losses from a counterfeit Sparrow Wallet app after entering their recovery phrases. In April, another investigator linked a fake Ledger app to reported crypto thefts. In those cases, however, the apps were counterfeit wallets, and the victims supplied their recovery phrases voluntarily. The apps captured the information directly. FomoPeek was different. It did not need to ask for secrets because it was engineered to reach into other apps and pull those secrets out. Users had no stated reason to expect that a blockchain monitoring tool would access private information stored elsewhere on their phones. That distinction makes FomoPeek a more menacing evolution of the fake wallet trend.

The broader pattern raises uncomfortable questions about Apple’s ability to police this corner of the App Store. Fraudulent wallets and malicious monitoring tools are not sideloaded apps or jailbreak tricks; they are distributed through the official channel that millions of users trust. SlowMist’s investigation suggests that malicious actors are willing to invest in Apple developer accounts, maintain a public-facing app, and craft code designed to evade review. The FomoPeek case is a reminder that platform security is not a substitute for personal security. Users still need to know what an app is allowed to do, what data it can access, and what the developer could do with that access.

What Users Should Do Now

SlowMist’s advice for anyone who used FomoPeek versions 1.1 or 1.2 was unambiguous: treat seed phrases, private keys, and sensitive credentials stored on the device as potentially compromised. Deleting the app or updating to version 1.3 stops the bleeding, but it does not repair the damage. Information already exfiltrated cannot be un-sent. The firm’s immediate recommendation was to create a new wallet on a secure device that never ran the affected app, then transfer assets away from any wallet whose keys may have been exposed. Cold storage, which keeps private keys offline, can reduce the risk of remote theft, but the first step is moving funds into a fresh wallet created in a clean environment.

The incident also offers lessons for crypto users who never installed FomoPeek. Storing recovery phrases in note-taking apps is risky, especially now that malware exists specifically to target those data containers. Hardware wallets and dedicated signing devices remain the most reliable way to keep private keys out of reach of a compromised phone. But the broader takeaway is a matter of perspective. An app’s presence in the App Store does not mean it is safe. A “read-only” tool that promises not to touch private keys can still be designed to reach into the rest of the device. For an industry that already demands vigilance from its users, the FomoPeek case pushes the bar even higher. Faith in a platform’s security review is not enough; every app is a potential attack surface. In the aftermath of this discovery, the prudent path is clear: audit your apps, rotate your credentials, move your keys to secure hardware, and assume that convenience and safety are not the same thing.

Share.
Leave A Reply

Exit mobile version