T
iTokenly

FomoPeek (malicious iOS app) hack — September 2026

Verified — 3 sourcesLast checked September 25, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedSeptember 20, 2026
Target typeIndividual holder
Loss$579,984Price at time of incident
MethodSupply chain or frontend compromiseVersions 1.1 and 1.2 of FomoPeek, a crypto-tracking app distributed through Apple's App Store, carried a kernel exploitation framework that could escape the iOS sandbox and read Keychain data and other apps' files, exposing locally stored private keys and recovery phrases
ChainsMultiple chains
OutcomeUnresolved

What happened

FomoPeek, an iPhone app marketed as a read-only tool for watching large crypto transactions on Ethereum, Solana and Tron, shipped malicious code through Apple's App Store in versions 1.1 and 1.2, released on 9 and 12 September 2026, and has been linked to the theft of about $580,000 in USDT from people who installed it. The malicious modules were absent from the original release and were removed in version 1.3 on 17 September.

SlowMist, working with OKX's security team after receiving reports of stolen assets and exposed private keys, published its analysis on 20 September. It found two modules with no connection to the app's advertised functions: one communicated with remote command-and-control servers, and the other contained a kernel exploitation framework with eight attack methods chosen according to the iPhone model and iOS version. A successful exploit could escape the app sandbox, read and decrypt the Keychain and reach files belonging to other apps, including locally stored private keys and recovery phrases, without the victim connecting a wallet or typing anything in. The app and both modules were signed by the same Apple developer identity, which places the code inside the officially distributed app rather than in a copy altered later.

SlowMist identified a primary attacker address, active from 15 September, that had received 579,984.34 USDT across several networks, with funds still arriving when it published. Salus traced 401,028 USDT onward to FixedFloat, 20,000 USDT to a KuCoin hot wallet, 111,458 USDT through an escrow platform and 10,000 USDT through the CCE mixing service. The figure is a floor. Binance, OKX, Gate, Bitget Wallet and Rabby warned users to delete the app, update iOS and move their assets to wallets created on a device that never ran it, since removing the app does not invalidate keys that may already have been copied.

Sources

  1. CryptoSlateSecondary · retrieved 2026-09-25
  2. Bitcoin.com NewsSecondary · retrieved 2026-09-25
  3. CointelegraphSecondary · retrieved 2026-09-25

Changes to this entry

  • Recorded five days after SlowMist's analysis. The amount is the 579,984.34 USDT SlowMist traced to the attacker's primary address; funds were still arriving when it published, so the figure is a floor, and the date is the day that address became active.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "FomoPeek (malicious iOS app) hack — September 2026", iTokenly, accessed 2026-09-25, https://itokenly.com/hacks/fomopeek-ios-app-malware
https://itokenly.com/hacks/fomopeek-ios-app-malware

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.