Malicious 'FomoPeek' App on App Store Steals User Assets via iOS Core Vulnerabilities
SlowMist and OKX security teams confirmed that versions 1.1 and 1.2 of the on-chain monitoring app 'FomoPeek' contained a malicious iOS core attack framework. Despite users never sharing seed phrases or signing transactions, the app exploited vulnerabilities to decrypt Keychain data and steal assets. The hackers have reportedly collected over 579,984 USDT since September 15. The app targeted 19 wallet and note-taking applications, including OKX Wallet, MetaMask, and Trust Wallet. SlowMist warns that uninstalling the app or updating to version 1.3 does not guarantee security, as data may have already been compromised. Users are advised to immediately migrate assets to new wallets generated on clean devices.
Summaries are written by AI from the original article. Not investment advice.