Crypto news report · source clearly identified
iPhone Monitoring App FomoPeek Contained Hidden Malware That Harvested Wallet Data
Security researchers discovered that two official App Store releases of the iPhone app FomoPeek included malicious modules capable of accessing other apps and extracting sensitive data, leading to a wallet that received nearly $580,000 in USDT.

Security firm SlowMist reported that the iPhone app FomoPeek, marketed as a read‑only crypto monitoring tool, shipped with hidden code in versions 1.1 and 1.2 that could bypass iOS protections, collect data from other applications, and transmit it to a remote server.
How the Malicious Code Operated
In a controlled test the hidden modules retrieved an encrypted server address, sent device information, and awaited instructions. When activated, the server instructed the app to target 19 wallet‑related and note‑taking apps. The app then uploaded the contents of Apple Notes, demonstrating the ability to exfiltrate data beyond its own sandbox.
Financial Impact
SlowMist traced the exfiltrated data to a wallet it identified as the attacker’s primary address. Since September 15 the address has received 579,984.34 USDT across multiple blockchain networks. The total reflects all receipts to the address, not a confirmed amount stolen directly via the app.
Affected Versions and Recommendations
- Version 1.1 released September 9
- Version 1.2 released September 12
- Version 1.0 was clean; the malicious code was removed in version 1.3 released September 17
Users who installed the affected versions should assume that any seed phrases, private keys, or other credentials stored on the device may be compromised. The recommended response is to generate new wallets on a secure device that never ran FomoPeek and transfer assets from potentially exposed wallets.
Broader Context
FomoPeek joins other fraudulent iOS apps that have put crypto holdings at risk, such as counterfeit Sparrow and Ledger wallets that tricked users into entering recovery phrases. Unlike those cases, FomoPeek’s hidden code harvested data without the user’s explicit input, expanding the threat surface for crypto users on mobile devices.
Source & attribution
News Source
- Publisher
- Bitcoin.com News
- Original date
- September 24, 2026, 12:30 AM
- Original headline
- iPhone Crypto App Hides Malicious Code as Attacker Wallet Nets $580K