FomoPeek iOS app exploits vulnerability, steals $580,000 in cryptocurrency
The malicious iOS app FomoPeek exploited a kernel vulnerability to steal $580,000 in cryptocurrency by accessing users' wallet credentials. This incident raises concerns about the security of the Appโฆ
Malicious iOS appโฏFomoPeek, distributed through Appleโs App Store, used kernelโlevel exploits to break out of the sandbox and steal cryptocurrency worth about $580,000, security firm SlowMist reported on Tuesday. The app masqueraded as a โFOMOโโstyle trading tool, prompting users to tap a button that claimed to reveal hidden market opportunities. Once installed, the compromised versions accessed data from other apps, including wallet credentials, and transferred funds to addresses linked to the attackers.
The incident matters because iOS is widely regarded as the most secure mobile platform. Appleโs review process is supposed to block malicious code before it reaches users. Yet the FomoPeek variants slipped through, exploiting a zeroโday kernel flaw that allowed them to bypass the operating systemโs isolation mechanisms. Cryptoโrelated scams have surged as digital assets become more mainstream, and attackers increasingly target mobile wallets where users store large sums. The breach highlights how quickly new threats can emerge when highโvalue assets are involved.
SlowMistโs analysis showed the app leveraged a known iOS kernel vulnerability that was patched in iOSโฏ17.2, but the malicious code was compiled for older versions still in use on many devices. The exploit granted the app systemโlevel privileges, letting it read keychains and intercept OTP messages. Victims reported unauthorized transfers after receiving a โverification codeโ that the app generated itself. Apple has since removed FomoPeek from the App Store and is investigating how the app passed its review. Security experts warned users to update to the latest iOS version and to avoid installing apps that request unnecessary permissions.
Going forward, Apple says it will strengthen its vetting tools and work with security researchers to identify similar threats sooner. Users are advised to delete the app, change wallet passwords, and monitor accounts for suspicious activity. Regulators may also scrutinise the App Storeโs liability for facilitating crypto fraud. The episode underscores the need for continual vigilance as cybercriminals adapt to the growing popularity of mobile finance.
Read Full Story at CoinTelegraph โ


