September 21, 2026
Downloaded from the App Store — lost every key. SlowMist took FomoPeek apart
You signed nothing, clicked no links, typed no seed. You just updated an app from the official App Store. That's how FomoPeek worked — a "whale tracker" for Solana, Ethereum and TRON, whose full analysis SlowMist and OKX Security published on September 20–21.
Timeline:
- Aug 29 — v1.0 passes Apple review. Clean.
- Sep 9 and Sep 12 — updates v1.1 and v1.2 bring two hidden modules: apptrace and libapptracecore. Same developer signature. The update ships to everyone automatically.
- Sep 15 — the main attacker address goes live. Sep 16 — first "my assets are gone" posts.
- Sep 17 — v1.3 without the modules: the bundle shrinks from 10.47 MB to 1.81 MB. Tracks covered.
- Sep 19 — SlowMist + OKX alert, app pulled.
How the theft worked:
- apptrace fetches an encrypted C2 address from Bitbucket, reports the device model and iOS version, receives a config — when and how to attack.
- libapptracecore picks one of 8 kernel exploits for that specific model (iOS 12.0–18.7.2 and 26.0–26.1 are vulnerable), escapes the sandbox and decrypts Keychain — the store where seed phrases and private keys of every wallet on the phone live.
- It lists the 135 installed apps and uploads whole containers of 19 targets: MetaMask, OKX Wallet, Trust, imToken, TokenPocket, TronLink… and Apple Notes — because that's where seed-phrase screenshots live.
- The keys sign transfers from the attacker's server. Changing your iPhone passcode doesn't help — the key is already outside.
Where it went: 579,984 USDT on the main attacker address (Ethereum, BNB Chain, Arbitrum), 159,000 through the FixedFloat exchanger, part to KuCoin. That's the visible part only — nobody has counted the SOL and TRX.
If FomoPeek 1.1–1.2 was on your iPhone:
- treat EVERY key and seed on that phone as compromised, not just the "tracker's";
- create new wallets on a different, clean device and move funds there; never restore the old seeds;
- check sessions on e-mail, exchanges, Apple ID, Google — kill foreign ones, change passwords, app-based 2FA;
- wipe the iPhone to factory and set it up as new, not from a backup.
Everyone else — 5 minutes:
- update iOS to the current release (27);
- delete any "whale tracker / signals / alerts / portfolio" apps installed this summer or fall — that's the disguise;
- find and delete photos and notes with a seed phrase, including "Recently Deleted" and iCloud;
- large sums — hardware wallet with a seed that never touched a phone.
And the practical part. The loot is being laundered right now through fresh addresses and exchangers. Received coins from an unknown address? Screen the sender before an exchange deposit: a deposit from a "dirty" address gets frozen, and you're the one explaining.
Check an address → https://t.me/amlconsensus_bot?start=en (first check is free)
Source: SlowMist, "Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation", with OKX Security, Sep 20–21, 2026.