Saturday, Sep 19, 2026
1 NEWFomoPeek App v1.1-1.2 Steals Digital Assets via 8 iOS Kernel ExploitsAAPL 🔒 Cybersecurity Sep 19, 3:26 AM EDT 3/3
SlowMist and OKX recently uncovered malicious modules within a crypto asset application that allow attackers to bypass security permissions on Apple devices. The joint investigation confirmed that FomoPeek app versions 1.1–1.2 utilize a kernel exploitation framework to steal private keys and seed phrases. This framework uses 8 different attack methods targeting iOS versions 12.0–18.7 and 26.0–26.1 to escape the device sandbox and decrypt Keychain data, which allows the software to read files from other applications.
The malicious modules connect to hidden servers to receive remote commands and execute attack functions automatically at regular intervals. SlowMist reported multiple cases of asset theft linked to private key exposure for users who installed the affected versions. Affected individuals are advised to create new accounts on trusted devices and move their digital assets to new addresses immediately.