FomoPeek (iOS app) Hack 2026 — $580K Exploit Analysis

SlowMist and the OKX security team found two malicious modules in FomoPeek versions 1.1 and 1.2 distributed through the official Apple App Store, including an iOS kernel exploitation framework covering iOS 12.0-18.7.2 and 26.0-26.1. The attacker's primary address received ~579,984 USDT.

Details

Full Description

On September 15, 2026, SlowMist and the OKX security team disclosed two malicious modules in FomoPeek versions 1.1 (released September 9) and 1.2 (September 12) distributed through the official Apple App Store. One module communicated with command-and-control infrastructure and the other contained an iOS kernel exploitation framework with eight attack methods covering iOS 12.0-18.7.2 and 26.0-26.1. A successful exploit escaped the app sandbox to reach Keychain data and files of other apps, exposing private keys, seed phrases and credentials without the user entering anything. The C2 targeted 19 wallet and notes apps. Version 1.3 (September 17) removed the modules. The attacker's primary address became active September 15 and received 579,984.34 USDT across several networks, with ~401,028 USDT traced to FixedFloat and 20,000 USDT to a KuCoin hot wallet. Binance, OKX, Gate, Bitget Wallet and Rabby issued warnings.

Laundering Analysis

Of the ~579,984 USDT received, ~401,028 USDT was traced to FixedFloat and 20,000 USDT to a KuCoin hot wallet. Binance, OKX, Gate, Bitget Wallet and Rabby issued warnings.

Sources

Related Hacks

Back to Browse