FomoPeek, a third-party app built on Fomo, contains malicious code capable of stealing private keys and seed phrases on iOS.
Security & Exploits ·
Security researchers at SlowMist and OKX identified malicious code within FomoPeek, a third-party application built on the Fomo platform, affecting versions 1.1–1.2 on iOS devices. The investigation revealed that multiple users experienced asset theft linked to the app's installation, with private key exposure confirmed in affected cases.
The malicious payload consists of two hidden modules unrelated to FomoPeek's stated functions. One contains an iOS kernel exploitation framework featuring eight distinct exploit methods that automatically select an attack vector based on device model and iOS version. The framework targets iOS versions 12.0–18.7 and 26.0–26.1, enabling the app to escape the iOS sandbox and decrypt Keychain data if successful. This access permits the app to read files from other installed applications, potentially exposing private keys, seed phrases, login credentials, chat history, and stored files.
The app maintains connections to undisclosed servers capable of receiving remote commands independent of its public-facing infrastructure. Traffic analysis showed the attack functionality remains active and executes automatically at regular intervals, with older iOS versions facing heightened risk. Users who installed affected versions are advised to immediately verify account activity, generate new credentials on an uncompromised device, migrate assets to new accounts, update iOS to the latest version, and discontinue use of FomoPeek.