SlowMist issued a security alert after receiving multiple reports of stolen user assets linked to FomoPeek. According to Foresight News, a joint investigation with OKX's security team found that some affected users had previously installed or used FomoPeek versions 1.1-1.2, which contained malicious code.
SlowMist said FomoPeek included modules unrelated to normal business operations, including one with a kernel exploit framework for iOS. The framework supports eight attack methods and can automatically choose an exploit based on device model and iOS version. Affected systems include iOS 12.0 to 18.7 and iOS 26.0 to 26.1. If successful, the app may bypass the iOS sandbox and access and decrypt Keychain data, exposing private keys, seed phrases, login credentials and other sensitive files. SlowMist also said FomoPeek connected to hidden servers unrelated to its public services and could receive remote commands.
SlowMist said plaintext traffic captured in its analysis showed the attack functions are currently enabled and run automatically at regular intervals. It advised users who installed or used FomoPeek versions 1.1-1.2 to check for abnormal asset activity, generate new private keys and seed phrases on a trusted device that has never installed the app, transfer assets to a new account as soon as possible, update to the latest iOS version, and avoid continuing to use or reinstall FomoPeek.