Tuesday, September 22, 2026

Latest Posts

Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT

Fomopeek, a malicious iPhone app distributed through Apple’s App Store, has been linked to nearly $580,000 in stolen USDT.

Blockchain security firm SlowMist began investigating the app over the weekend after receiving reports of stolen assets linked to exposed private keys.

Some victims had previously installed versions 1.1 or 1.2 of the Fomopeek app, which was marketed as a read-only tool for tracking large cryptocurrency transactions across Ethereum, Solana and Tron.

What is Fomopeek?

Working with security researchers at crypto exchange OKX, SlowMist found two modules embedded in those versions that had no connection to FomoPeek’s advertised monitoring functions.

One communicated with external command-and-control infrastructure, while the other contained a kernel exploitation framework with eight attack methods that could adjust to the victim’s iPhone model and operating-system version.

A successful exploit could escape Apple’s application sandbox and reach Keychain information and files belonging to other apps. That created a route to locally stored private keys, seed phrases, and login credentials without requiring users to connect a wallet or enter those details into FomoPeek.

SlowMist founder Yu Xian said the risk extended to passwords stored in Apple’s Keychain and encrypted files held by other applications. An attacker who obtained both could potentially unlock wallet credentials and other sensitive information stored on the device.

He explained:

“After a successful attack, the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain (Keychain), and access data files from other apps on the device. Private keys, mnemonic phrases, login credentials, chat histories, files, and other user data stored on the device may all face the risk of leakage as a result. Additionally, the app connects to covert servers unrelated to its public business functions to receive remote instructions.”

The malicious components were not present in FomoPeek’s original release. SlowMist found them in version 1.1, released Sept. 9, and version 1.2 on Sept. 12, before removing them in version 1.3 on Sept. 17.

Read More:  Bitcoin faces $450M ETF outflow before Fed decision

Researchers also found that the framework could receive instructions from a remote server, including settings that governed whether exploitation was enabled and how often it would run.

Nearly $580,000 stolen

The technical findings were followed by an on-chain trail showing that attackers had already converted that access into losses.

Blockchain analysis firm Salus identified 0x6d37f2C5e8F8546b648D317295565dA95975f4BB as the attacker address and estimated proceeds from the incident at about 579,900 USDT.

Salus traced 401,028 USDT through three intermediary addresses to FixedFloat. Another 20,000 USDT moved in two transactions through deposit addresses before being consolidated into a KuCoin hot wallet.

A cross-chain funds-flow map traces 15 Ethereum and TRON address pairs connected through leaked transfer evidence. Source: Salus

A further 111,458 USDT was routed through an address Salus associated with an escrow platform, while another 10,000 USDT passed through the CCE mixing service before reaching addresses linked to an escrow service.