Security researchers at SlowMist say official App Store versions of the iPhone app FomoPeek included malicious code that could be used to access data from other apps, despite the product being presented as a read-only crypto monitoring tool.

According to the report, versions 1.1 and 1.2 were signed with the same Apple developer identity as the legitimate app and contained modules that could be activated against 19 wallet and note-taking apps. In a controlled test, the code collected and uploaded Apple Notes data.

Malicious modules found in App Store releases

SlowMist said the issue was present in FomoPeek versions 1.1 and 1.2 distributed through Apple’s official App Store. The researchers said the harmful components were not from an impostor build but were embedded in releases tied to the same developer identity as the legitimate application.

The app was marketed as a tool for monitoring crypto activity without transaction capability. SlowMist’s findings indicate that, behind that presentation, the software also included code designed to reach beyond its stated function and interact with sensitive data held by other apps.

What the code was able to target

The researchers said the exploit could be triggered to go after information across 19 wallet and note-taking apps. SlowMist specifically highlighted the risk to seed phrases, private keys, and other sensitive credentials stored or accessible on devices that ran the affected versions.

In testing carried out by the firm, the malicious routine successfully gathered data from Apple Notes and uploaded it. The report also said the app included an exploitation strategy labeled DarkSwordStrategy, a name that matches a known iOS exploit chain.

Attacker-linked wallet received nearly $580,000 in USDT

SlowMist traced blockchain transfers to a wallet it linked to the attacker and said that address had received 579,984.34 USDT across several networks. The researchers added that funds were still moving into the wallet when the report was published.

The firm cautioned that this figure reflects total receipts to the identified wallet, not a verified measure of losses caused by the FomoPeek app itself. That distinction leaves the confirmed financial impact unresolved, even as the onchain activity provides a sense of the scale investigators are examining.

Advice for affected users

SlowMist said anyone who installed and ran the affected FomoPeek versions should treat seed phrases, private keys, and other sensitive credentials on that device as potentially compromised.

The firm’s recommended next step is to move assets to a new wallet created on a secure device that has never run the app. That guidance reflects the central uncertainty in the case: while the code’s capability was demonstrated, the full scope of any theft linked specifically to the app has not been confirmed.

Source: news.bitcoin.com