FomoPeek was sold as a read-only on-chain monitor — connect nothing, hand over no seed phrase. Cute. Two official App Store builds carried modules that bypass iOS protections, scoop data out of other apps and ship it to a remote server. The wallet SlowMist tags as the attacker's has taken in 579,984.34 USDT across several blockchain networks since it went live on Sept 15.
▪️ SlowMist and OKX's security team opened the case after reports of stolen assets and exposed private keys, and published the analysis on Sept 20. So the cleanup started only after the damage was done.
▪️ The app and the malicious modules share one Apple developer signature and kept their App Store encryption records — proof it shipped through Apple, not a sideloaded copy.
▪️ One module pulled an encrypted command server address from Bitbucket, phoned home with the iPhone's specs, then waited for orders on what to grab. Classic staging.
▪️ Exploitation was off in the test; researchers flipped it on in an isolated box, got a hit list of 19 wallet and note-taking apps, and captured an Apple Notes upload.
▪️ Buried in the code: a strategy named DarkSwordStrategy, same name as the DarkSword iOS exploit chain Google Threat Intelligence Group documented in March. Because why not reuse branding.
▪️ SlowMist's figure is the wallet's total receipts across chains, not a confirmed tally of what FomoPeek stole — and funds were still arriving when the report dropped.
📊 Attacker wallet live since:
Sept 15📊 Malicious builds:
1.1 (Sept 9), 1.2 (Sept 12)📊 Cleaned in:
1.3, Sept 17Anyone who ran FomoPeek 1.1 or 1.2 is still exposed after deleting it — whatever left the phone can't be recalled, so treat every seed phrase, private key and credential on that device as burned. Apple's review cleared the modules twice. And it's not a one-off: in July three investors blamed a counterfeit Sparrow Wallet app after typing in their recovery phrases, and in April an investigator tied a fake Ledger app to reported thefts. The badge isn't a firewall.
💬 «read-only on-chain monitoring and alerting tool» — FomoPeek's App Store description
🔮 Apple greenlit this thing twice and only pulled it after researchers screamed. Your seed phrase doesn't care about the App Store badge.
@pixeos