SlowMist Advises Users of FomoPeek 1.1 and 1.2 to Treat Credentials as Exposed After Security Issue
Foresight News posted on X (formerly Twitter). SlowMist advised users who previously used FomoPeek 1.1 or 1.2 to stop running the app, avoid reinstalling it, and treat related seed phrases, private keys, and other sensitive credentials as compromised.
The security firm said that removing the module in version 1.3 only means that version no longer contains the reported code, and it does not recover data that may already have been uploaded. It said asset migration should be done on a device that has never had FomoPeek installed, is fully updated, and comes from a trusted source. New wallets should be created with entirely new seed phrases.
SlowMist said importing an old seed phrase into another wallet restores the same original account, and adding new accounts under the same seed phrase still leaves them controlled by that seed phrase. Tokens on different chains, NFTs, and assets still held in protocols should be checked separately to avoid moving only the most visible balance in the wallet interface.
The wallet unlock password usually only protects local access, and changing it does not replace the on-chain private key. Revoking token approvals can remove a contract’s spending permission, but it cannot stop someone who already has the private key from signing transactions again.
For keys that may have been exposed, the recommended response includes moving assets and stopping use of the old account. If newly added gas fees are immediately transferred out during migration, users should stop repeatedly topping up the wallet, as it may be monitored by automated sweeping tools. SlowMist said users should contact the wallet’s official support team or a trusted security team before taking further action, and should not share seed phrases with strangers for help.
It also advised checking login records and unfamiliar sessions for email, exchange, and other important accounts on the device, then changing passwords on a secure device, logging out of suspicious sessions, and enabling two-factor authentication. If the Apple or Google account linked to the wallet may also be compromised, it should be handled as well, and a suspicious account should not be used as a recovery entry for a new wallet.
Before handling the phone, users should save the app version, installation time, abnormal transaction hashes, and related screenshots. Users who have already suffered theft should confirm evidence-collection requirements with official customer support or a security team before deciding whether to wipe and reinstall the device. The device should be updated to the latest supported security patch, but system updates do not invalidate already exposed keys.
SlowMist said users can separate devices used for claiming rewards or testing new apps from those used to manage major assets. Phones used for asset management should have fewer unrelated apps installed, and seed phrases should not be left in plain text in photo albums, notes, or chat records. Read-only monitoring can use public addresses, while devices that store signing keys should have limited exposure to software that has not been fully reviewed.