Security researchers have identified Fomopeek, a malicious iPhone application distributed via the Apple App Store, as responsible for the theft of roughly $580,000 in USDT.
SlowMist, a blockchain security firm, launched an investigation into the app over the weekend after reports surfaced about stolen assets tied to compromised private keys.
Several victims had installed versions 1.1 or 1.2 of Fomopeek, an app promoted as a read‑only tracker for large cryptocurrency transactions on Ethereum, Solana, and Tron.
What is Fomopeek?
In collaboration with security researchers from the crypto exchange OKX, SlowMist discovered two modules embedded in those versions that were unrelated to the app’s advertised monitoring capabilities.
One module contacted an external command‑and‑control server, while the other comprised a kernel‑exploitation framework offering eight distinct attack techniques that could be tailored to the specific iPhone model and iOS version of each victim.
A successful exploit could break out of Apple’s application sandbox, accessing Keychain data and files from other applications, thereby obtaining locally stored private keys, seed phrases, and login credentials without the user needing to connect a wallet or input that information into Fomopeek.
SlowMist founder Yu Xian warned that the risk also encompassed passwords saved in Apple’s Keychain and encrypted files held by other apps; an attacker who obtained both could potentially unlock wallet credentials and other sensitive data stored on the device.
“After a successful attack, the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain (Keychain), and access data files from other apps on the device. Private keys, mnemonic phrases, login credentials, chat histories, files, and other user data stored on the device may all face the risk of leakage as a result. Additionally, the app connects to covert servers unrelated to its public business functions to receive remote instructions.”
The malicious components were absent from Fomopeek’s initial release. SlowMist identified them in version 1.1 (released September 9) and version 1.2 (released September 12), and they were removed in version 1.3 on September 17.
Researchers also determined that the framework could receive commands from a remote server, with configurable settings that determined whether exploitation was active and its frequency.
Nearly $580,000 stolen
The technical findings were followed by an on‑chain trail indicating that attackers had already leveraged the access to generate financial losses.
Blockchain analysis firm Salus identified the attacker address 0x6d37f2C5e8F8546b648D317295565dA95975f4BB and estimated the total proceeds at roughly 579,900 USDT.
Salus traced 401,028 USDT through three intermediary addresses to FixedFloat, while an additional 20,000 USDT was moved in two transactions via deposit addresses and later consolidated into a KuCoin hot wallet.

An additional 111,458 USDT was transferred via an address identified by Salus as belonging to an escrow platform, and 10,000 USDT moved through the CCE mixing service before reaching addresses tied to an escrow service.
Salus noted that its analysis also linked the group behind the Fomopeek incident to a separate private‑key theft that occurred in June, though investigators have yet to confirm whether the same method was employed.
Crypto platforms warn users as custody debate returns
The losses and the broad potential reach of the exploit have prompted warnings from a number of crypto platforms, including Binance, OKX, Gate, Bitget Wallet, and Rabby.
Binance warned:
“The third-party app FomoPeek (versions 1.1–1.2) contains malicious code that can exploit iOS system vulnerabilities to gain the highest level of device privileges, potentially accessing sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, files, and more. Please note that this type of malware targets the device itself. If an attack succeeds, data from all apps on the affected device may be accessed.”
In response, the crypto firms issued unified guidance urging users to uninstall FomoPeek, update iOS, and transfer assets to fresh wallets on devices that never hosted the compromised app.
These fresh credentials are required since removing the app or updating iOS cannot invalidate a private key that may already have been copied.
The incident follows two months after on‑chain investigator ZachXBT suggested that a dedicated iPhone could be a preferable option for storing crypto assets and signing transactions compared to traditional hardware wallets.
His recommendation hinged on keeping the device isolated from routine browsing, messaging, and other activities that could enlarge the attack surface.
Fomopeek reveals a different vulnerability in that model; although the app was designed for crypto users and distributed through Apple’s official marketplace, researchers found it contained tools capable of breaching the isolation barriers between applications on the device.
This does not prove that dedicated crypto iPhones are inherently less secure than hardware wallets, but it demonstrates that isolation provides limited protection when software on the device can compromise the operating system.
Affected users now prioritize containing further losses and tracing the stolen funds.
Salus continues to monitor addresses linked to the remaining proceeds, while Binance and other platforms watch for deposits that could provide investigators another chance to track or restrict the movement of the stolen USDT.
Also Read
- Binance Fortifies Circle Alliance with Strategic Investment and Multi-Year Partnership Renewal
- U.S. Bitcoin ETFs Draw Nearly $1 Billion in Single-Day Surge
- Over $161 Million in Long-Dormant Bitcoin Resurfaces Within Two Weeks
- Bitcoin Could Embrace Quantum‑Safe Upgrades While Lightning Privacy Remains Exposed

