SlowMist links FomoPeek iOS exploit to $580K crypto theft
SlowMist has identified a malicious version of the FomoPeek app distributed through the Apple App Store as the vector for a $580,000 cryptocurrency theft. The security firm states that the compromised software utilized iOS kernel exploits to breach the device sandbox, granting unauthorized access to sensitive data stored within other applications. This incident highlights a specific failure in the mobile supply chain where a seemingly standard utility app served as the primary entry point for high-value digital asset extraction.
SlowMist has identified a malicious version of the FomoPeek app distributed through the Apple App Store as the vector for a $580,000 cryptocurrency theft. The security firm states that the compromised software utilized iOS kernel exploits to breach the device sandbox, granting unauthorized access to sensitive data stored within other applications. This incident highlights a specific failure in the mobile supply chain where a seemingly standard utility app served as the primary entry point for high-value digital asset extraction.
The Operational Vector
The mechanics of the breach relied on the app’s ability to escape the isolated environment that iOS typically imposes on third-party software. SlowMist notes that the malicious FomoPeek versions leveraged kernel-level vulnerabilities to bypass these restrictions. Once the sandbox was compromised, the malware could read data from neighboring apps without user interaction or visible alerts. This method of attack targets the operational integrity of the device rather than relying on user error, such as phishing or credential stuffing. The distribution channel, the official App Store, adds a layer of complexity to the threat, as it implies the malicious build passed initial review processes or was introduced after approval.
The $580,000 figure represents the confirmed loss attributed to this specific campaign by SlowMist. The theft underscores how mobile security gaps can directly impact crypto holdings, particularly when wallets or exchange applications coexist with third-party tools on the same device. The exploit did not require the victim to input private keys manually; instead, the malware accessed the data programmatically once the kernel barrier was broken. This shift from social engineering to technical exploitation changes the risk profile for mobile crypto users, who must now consider the integrity of every app installed on their devices.
What to Watch
The immediate focus for security teams and users is the availability of patched versions of FomoPeek and the status of the malicious builds within the App Store. SlowMist’s report serves as the primary evidence for the link between the app and the theft, though broader industry confirmation may follow. For market participants, the incident reinforces the persistent risk of mobile-side compromises in the crypto ecosystem. The next confirmable milestone will be Apple’s response to the report and any subsequent removal of the compromised binaries from its platform. Until then, the vulnerability remains a live threat for users who have installed the affected versions.
Filed by the digital assets desk of MarketPR on September 23, 2026. Source: cointelegraph.com. Indicative figures are not investment advice.