
SlowMist Warns FomoPeek iOS App Versions Carried Malicious Code

SlowMist Warns FomoPeek iOS App Versions Carried Malicious Code
WEEX View
- The immediate variable is whether exposed users rotate wallets rather than only updating the app. SlowMist said the malware could access private keys, mnemonic phrases, and credentials, so the main follow-up risk is continued drain attempts against accounts linked to devices that ran the app.
- Markets should also watch for further disclosures on distribution scope, including how the affected builds were obtained and whether any exchange-linked credentials were compromised alongside wallet data. That would shape the operational response for platforms handling suspicious withdrawals or account recovery requests.
- A second signal is whether other mobile crypto apps face similar scrutiny. The case points to mobile-device compromise rather than a single on-chain exploit, which raises broader wallet-security and device-hygiene concerns across the retail user base.
SlowMist issued a theft-risk warning for FomoPeek App versions 1.1 to 1.2 after receiving multiple user reports of stolen assets tied to private key leaks, saying a joint analysis with the OKX security team found the iOS application had been implanted with malicious code.
According to SlowMist, the compromised FomoPeek versions bundled two unrelated modules, including what it described as a professional iOS kernel attack framework with eight exploit schemes. The framework can automatically choose attack methods based on device model and system version, with listed affected iOS versions spanning iOS 12.0 to 18.7 and 26.0 to 26.1.
SlowMist said that if the attack succeeds, the app can bypass iOS sandbox isolation, read and decrypt the system keychain, and access data files from other applications on the device. That could expose stored private keys, mnemonic phrases, login credentials, chat records, and files. The firm also said the application connects to hidden servers for remote commands, and intercepted communications suggest the malicious functions are active.
The warning framed the risk as more than a routine software bug. SlowMist said users running lower iOS versions may face higher potential risk, and urged anyone who downloaded or used the app to check account security immediately, stop using the software, create new accounts and keys on a clean device, and transfer assets out as soon as possible.
Some outside technical reporting has pointed to a possible mnemonic-generation weakness in FomoPeek 1.1 to 1.2, but the warning released by SlowMist focused on implanted malicious code, device compromise, and private key leakage. No verified figure for affected users or total losses was disclosed in the available information.
Why It Matters
This case stands out because it targets the device layer where many retail users manage wallets, credentials, and exchange access in one place. A successful compromise at that level can cut across multiple apps and accounts at once, making the damage harder to contain than a single protocol exploit or phishing incident.
It also adds pressure on wallet providers, exchanges, and security teams to treat mobile distribution and endpoint integrity as a core crypto-security issue. For users, the warning underlines a basic but critical distinction: once keys or seed phrases may have been exposed on a compromised device, remediation may require full key rotation and fund migration rather than a simple app update.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
About WEEX View
WEEX View is a crypto analysis and intelligence hub, covering the latest in Web3, AI, and global markets. Get independent research and in-depth insights to stay ahead of market trends and trading opportunities.
Latest articles
MoreVietnam Targets 2026 Crypto Licenses Under Pilot Framework
Vietnam said it expects to license its first crypto asset service providers in 2026 under a pilot framework, while officials discussed regulatory cooperation with Austria's FMA on investor protection, anti-money laundering, and market supervision.
Switchboard Says It Will Wind Down Oracle Operations
Switchboard said it is ceasing operations, with maintenance for its oracle implementations ending immediately and remaining support scheduled to end on September 25, prompting protocols to migrate to alternatives including Pyth and RedStone.
Bastion Seeks OCC Trust Charter as Stablecoin Regulation Tightens
Bastion is pursuing an OCC national trust bank charter after earlier reports framed the matter as conditional approval, highlighting growing efforts by crypto infrastructure firms to move stablecoin and custody businesses into a federal oversight framework.
Radix Patches Vault Flaw After Cross-Chain Asset Theft
Radix Foundation said it has fixed the vault authorization vulnerability behind an August 31 exploit that let an attacker withdraw third-party assets and move them off-chain through Hyperlane, with network recovery now under way.



