LIVEBTC $86,141 ↗ +0.87%ETH $2,743 ↗ +0.54%SOL $117.92 ↗ +1.33%XRP $1.62 ↗ +6.46%BNB $788.53 ↗ +0.39%HYPE $96.51 ↗ +1.93%ZEC $1,626 ↗ +7.23%STRK $0.04 -1.90%TSLAX $379.16 ↗ +0.83%SPCXB $154.28 ↗ +1.37%BTC $86,141 ↗ +0.87%ETH $2,743 ↗ +0.54%SOL $117.92 ↗ +1.33%XRP $1.62 ↗ +6.46%
Tech3 hours ago

Apple App Store app FomoPeek tied to ~$580,000 crypto theft via iOS kernel exploits

Blockchain security firm SlowMist says infected versions shipped through Apple's review process carried eight attack methods, broke out of the sandbox and drained Keychain data before version 1.3 cleaned them out.

Illustration · generated, not a photograph

Why it mattersA functioning kernel exploit chain slipped past Apple's App Store review, defeating the sandbox isolation that normally stops one app from reading another's wallet keys.

Two contaminated versions of an iOS app called FomoPeek made it through Apple's App Store review process and are now linked to the theft of close to $580,000 in cryptocurrency, according to blockchain security firm SlowMist. The versions carried kernel-level exploits that let the app break out of iOS's sandbox — the security boundary that normally keeps one app from touching another app's data — and reach stored wallet information.

Per SlowMist's investigation, carried out alongside the OKX security team, the compromised builds added two modules designed to escalate privileges and pull down Keychain data and files held by other apps. The probe started after users reported lost assets and researchers noticed several of them had installed the app around the time of the thefts.

The timeline is narrow. SlowMist dates the tainted releases to Sept. 9 and Sept. 12. Version 1.3, published Sept. 17, stripped the malicious code back out. Separately, onchain analysis points to a primary attacker wallet that first moved on Sept. 15 and accumulated roughly 579,984 USDT, a dollar-pegged stablecoin.

The exploitation toolkit behind the attack was substantial. It bundled eight distinct attack methods and advertised compatibility with iOS versions spanning 12.0 through 18.7.2 plus 26.0 through 26.1, meaning devices on current software were potentially in range.

Tracing the money, SlowMist found the stolen funds crossed several blockchain networks before being pooled and shuffled through a chain of addresses and services. Some headed to FixedFloat, a crypto swap service; KuCoin, a centralized exchange; and cce.cash. Other portions were split into additional wallets the firm was still following when it published.

A rare breach of Apple's walled garden

Apps reach the App Store only after Apple's review, which historically screened out overtly hostile code — making a functioning exploit chain slipped past that gate notable. Because kernel exploits grant control over the operating system itself, a sandbox escape of this kind defeats the isolation that would ordinarily prevent a wallpaper app from reading a wallet app's keys.

SlowMist published its findings without stated confirmation from either Apple or OKX, and the questions that remain are pointed ones: how the malicious code survived review, how many users ran the affected builds, and whether further funds will surface as the tracing continues. Cointelegraph reported that it contacted Apple, SlowMist and OKX for comment ahead of publication and received no response.

Source reporting

The outlets whose reporting this account was written from.

Written from the reporting and primary documents credited at the foot of this story. Facts are credited to the outlet or document that established them. How Chainpress works

Emailhttps://www.chainpress.co/article/apple-app-store-app-fomopeek-tied-to-580-000-crypto-theft-via-io-cp
Report a correction →
slowmistokxapple

Related coverage

View all →