AAPLSlowMist links FomoPeek iOS exploit to $580K crypto theftSep 23MACRODiageo names WPP's Joanne Wilson as incoming CFOSep 23MTBM&T Bank refreshes medium-term note program for senior and subordinated issuesSep 23MACRORBA Flags ASX Shortcomings in Key Operational AreasSep 23COINCoinbase Opens IPO Access to U.S. Retail via CCMSep 23PLUNPlutonian Acquisition Corp. II files 8-K for NT1 mergerSep 23$BTCCME Group adds Bitcoin Cash and Uniswap futures to October 19 launchSep 23SDSTStardust Power expands ATM capacity by $6.1 millionSep 23REGULATORYMissouri mother pleads guilty to child endangerment after oven tragedySep 23DEALSBoehly consortium targets Lukoil assets to unseat CarlyleSep 22AAPLSlowMist links FomoPeek iOS exploit to $580K crypto theftSep 23MACRODiageo names WPP's Joanne Wilson as incoming CFOSep 23MTBM&T Bank refreshes medium-term note program for senior and subordinated issuesSep 23MACRORBA Flags ASX Shortcomings in Key Operational AreasSep 23COINCoinbase Opens IPO Access to U.S. Retail via CCMSep 23PLUNPlutonian Acquisition Corp. II files 8-K for NT1 mergerSep 23$BTCCME Group adds Bitcoin Cash and Uniswap futures to October 19 launchSep 23SDSTStardust Power expands ATM capacity by $6.1 millionSep 23REGULATORYMissouri mother pleads guilty to child endangerment after oven tragedySep 23DEALSBoehly consortium targets Lukoil assets to unseat CarlyleSep 22

SlowMist links FomoPeek iOS exploit to $580K crypto theft

SlowMist has identified a malicious version of the FomoPeek app distributed through the Apple App Store as the vector for a $580,000 cryptocurrency theft. The security firm states that the compromised software utilized iOS kernel exploits to breach the device sandbox, granting unauthorized access to sensitive data stored within other applications. This incident highlights a specific failure in the mobile supply chain where a seemingly standard utility app served as the primary entry point for high-value digital asset extraction.

By Miles BroadbentDigital Assets DeskSeptember 23, 20262 min readAAPL
Share

SlowMist has identified a malicious version of the FomoPeek app distributed through the Apple App Store as the vector for a $580,000 cryptocurrency theft. The security firm states that the compromised software utilized iOS kernel exploits to breach the device sandbox, granting unauthorized access to sensitive data stored within other applications. This incident highlights a specific failure in the mobile supply chain where a seemingly standard utility app served as the primary entry point for high-value digital asset extraction.

The Operational Vector

The mechanics of the breach relied on the app’s ability to escape the isolated environment that iOS typically imposes on third-party software. SlowMist notes that the malicious FomoPeek versions leveraged kernel-level vulnerabilities to bypass these restrictions. Once the sandbox was compromised, the malware could read data from neighboring apps without user interaction or visible alerts. This method of attack targets the operational integrity of the device rather than relying on user error, such as phishing or credential stuffing. The distribution channel, the official App Store, adds a layer of complexity to the threat, as it implies the malicious build passed initial review processes or was introduced after approval.

The $580,000 figure represents the confirmed loss attributed to this specific campaign by SlowMist. The theft underscores how mobile security gaps can directly impact crypto holdings, particularly when wallets or exchange applications coexist with third-party tools on the same device. The exploit did not require the victim to input private keys manually; instead, the malware accessed the data programmatically once the kernel barrier was broken. This shift from social engineering to technical exploitation changes the risk profile for mobile crypto users, who must now consider the integrity of every app installed on their devices.

What to Watch

The immediate focus for security teams and users is the availability of patched versions of FomoPeek and the status of the malicious builds within the App Store. SlowMist’s report serves as the primary evidence for the link between the app and the theft, though broader industry confirmation may follow. For market participants, the incident reinforces the persistent risk of mobile-side compromises in the crypto ecosystem. The next confirmable milestone will be Apple’s response to the report and any subsequent removal of the compromised binaries from its platform. Until then, the vulnerability remains a live threat for users who have installed the affected versions.

About this story

Filed by the digital assets desk of MarketPR on September 23, 2026. Source: cointelegraph.com. Indicative figures are not investment advice.

Back to the news index