Crypto news report · source clearly identified

Malicious iPhone app Fomopeek hijacks $580,000 USDT

Fomopeek, a malicious iPhone app distributed through Apple’s App Store, has been linked to nearly $580,000 in stolen USDT.

Security researchers have uncovered a malicious iPhone application, Fomopeek, that escaped Apple’s iOS sandbox and accessed private keys, seed phrases and other sensitive data stored on users’ devices. The exploitation resulted in the theft of almost $580,000 worth of USDT.

How the app operated

Versions 1.1 (released Sep 9) and 1.2 (released Sep 12) of Fomopeek were marketed as a read‑only tool for tracking large crypto transactions on Ethereum, Solana and Tron. Analysis by blockchain security firm SlowMist, in collaboration with researchers at OKX, identified two hidden modules in these versions:

  • A command‑and‑control component that communicated with external servers.
  • A kernel‑exploitation framework containing eight attack methods that could adapt to the victim’s iPhone model and iOS version.

Successful exploitation allowed the app to break out of the iOS sandbox, read the system Keychain, and access files belonging to other applications, exposing private keys, mnemonic phrases, login credentials, chat histories and other user data.

Timeline of the malicious code

  • Version 1.1 released Sep 9 – malicious modules added.
  • Version 1.2 released Sep 12 – modules persisted.
  • Version 1.3 released Sep 17 – malicious code removed.

On‑chain impact

Blockchain analysis firm Salus traced the stolen funds to address 0x6d37f2C5e8F8546b648D317295565dA95975f4BB, estimating proceeds of about 579,900 USDT. The flow included:

  • 401,028 USDT moved through three intermediary addresses to FixedFloat.
  • 20,000 USDT routed through deposit addresses before consolidation into a KuCoin hot wallet.
  • 111,458 USDT passed through an escrow‑platform address.
  • 10,000 USDT processed by the CCE mixing service.

Additional analysis linked the same threat actor to a separate private‑key theft in June.

Industry response

Major crypto platforms—including Binance, OKX, Gate, Bitget Wallet and Rabby—issued warnings, advising users to uninstall Fomopeek, update iOS, and move assets to new wallets on devices that never installed the compromised app. Deleting the app or patching iOS does not invalidate private keys that may have already been exfiltrated.

Implications for mobile crypto security

The incident highlights a risk for users who rely on dedicated smartphones for crypto activities. Even apps distributed through official app stores can contain code capable of compromising the operating system, undermining isolation strategies that separate crypto functions from other device usage.

Source & attribution

News Source

Publisher
CryptoSlate
Original date
September 22, 2026, 10:50 PM
Original headline
Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT
View original report ↗