September 21, 2026

Downloaded from the App Store — lost every key. SlowMist took FomoPeek apart

You signed nothing, clicked no links, typed no seed. You just updated an app from the official App Store. That's how FomoPeek worked — a "whale tracker" for Solana, Ethereum and TRON, whose full analysis SlowMist and OKX Security published on September 20–21.

Timeline:

How the theft worked:

Where it went: 579,984 USDT on the main attacker address (Ethereum, BNB Chain, Arbitrum), 159,000 through the FixedFloat exchanger, part to KuCoin. That's the visible part only — nobody has counted the SOL and TRX.

If FomoPeek 1.1–1.2 was on your iPhone:

Everyone else — 5 minutes:

And the practical part. The loot is being laundered right now through fresh addresses and exchangers. Received coins from an unknown address? Screen the sender before an exchange deposit: a deposit from a "dirty" address gets frozen, and you're the one explaining.

Check an address → https://t.me/amlconsensus_bot?start=en (first check is free)

Source: SlowMist, "Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation", with OKX Security, Sep 20–21, 2026.

Screen your counterparty now

Consensus of sources · verdict across 35 chains · connection graph and full audit · PDF with QR verification

Open @amlconsensus_bot — 1 free check