BlockBeats news, September 19: SlowMist issued a security alert stating that it has recently received multiple reports of asset theft from FomoPeek users. A joint investigation with the OKX security team found that some affected users had previously installed or used FomoPeek versions 1.1–1.2, and the related applications contained malicious code.
SlowMist stated that FomoPeek contains modules unrelated to its normal business, one of which includes a kernel exploit framework targeting the iOS system, supporting 8 different attack methods and automatically selecting the exploit method based on device model and iOS version. Affected systems include iOS 12.0 to 18.7 and iOS 26.0 to 26.1. If the exploit succeeds, the application may break through the iOS sandbox and access and decrypt Keychain data, thereby causing the leakage of private keys, mnemonic phrases, login credentials, and other sensitive files.
In addition, FomoPeek also connects to hidden servers unrelated to its public services and can receive remote commands. SlowMist stated that its analysis of captured plaintext traffic shows that the related attack functionality is currently enabled and will automatically run periodically.
SlowMist recommends that users who have installed or used FomoPeek versions 1.1–1.2 immediately check whether their assets are abnormal, generate entirely new private keys and mnemonic phrases on a trusted device that has never installed the application, and transfer assets to new accounts as soon as possible, while also upgrading to the latest iOS version and refraining from continuing to use or reinstalling FomoPeek.

