Crypto news report · source clearly identified

iPhone Monitoring App FomoPeek Contained Hidden Malware That Harvested Wallet Data

Security researchers discovered that two official App Store releases of the iPhone app FomoPeek included malicious modules capable of accessing other apps and extracting sensitive data, leading to a wallet that received nearly $580,000 in USDT.

Security firm SlowMist reported that the iPhone app FomoPeek, marketed as a read‑only crypto monitoring tool, shipped with hidden code in versions 1.1 and 1.2 that could bypass iOS protections, collect data from other applications, and transmit it to a remote server.

How the Malicious Code Operated

In a controlled test the hidden modules retrieved an encrypted server address, sent device information, and awaited instructions. When activated, the server instructed the app to target 19 wallet‑related and note‑taking apps. The app then uploaded the contents of Apple Notes, demonstrating the ability to exfiltrate data beyond its own sandbox.

Financial Impact

SlowMist traced the exfiltrated data to a wallet it identified as the attacker’s primary address. Since September 15 the address has received 579,984.34 USDT across multiple blockchain networks. The total reflects all receipts to the address, not a confirmed amount stolen directly via the app.

Affected Versions and Recommendations

  • Version 1.1 released September 9
  • Version 1.2 released September 12
  • Version 1.0 was clean; the malicious code was removed in version 1.3 released September 17

Users who installed the affected versions should assume that any seed phrases, private keys, or other credentials stored on the device may be compromised. The recommended response is to generate new wallets on a secure device that never ran FomoPeek and transfer assets from potentially exposed wallets.

Broader Context

FomoPeek joins other fraudulent iOS apps that have put crypto holdings at risk, such as counterfeit Sparrow and Ledger wallets that tricked users into entering recovery phrases. Unlike those cases, FomoPeek’s hidden code harvested data without the user’s explicit input, expanding the threat surface for crypto users on mobile devices.

Source & attribution

News Source

Publisher
Bitcoin.com News
Original date
September 24, 2026, 12:30 AM
Original headline
iPhone Crypto App Hides Malicious Code as Attacker Wallet Nets $580K
View original report ↗