Blockchain security firm SlowMist has issued an urgent warning about malicious code hidden inside versions 1.1 and 1.2 of the FomoPeek mobile application, which can secretly steal users' private keys and mnemonic phrases. The alert follows reports from multiple FomoPeek users who lost assets. A joint investigation with the OKX security team found that some victims had previously installed or used the compromised versions of the app.
According to SlowMist, FomoPeek contains modules unrelated to its normal functions, including an exploit framework that targets kernel vulnerabilities in iOS. The framework reportedly supports eight different attack methods and can automatically choose an appropriate vulnerability based on the device model and iOS version. In SlowMist's analysis, the attacks can affect iOS versions from 12.0 through 18.7, as well as iOS 26.0 and 26.1. If exploited, the app can bypass iOS sandbox protection and access and decrypt Keychain data, allowing attackers to capture private keys, seeds or mnemonics, login credentials, and other sensitive files.
SlowMist also found that FomoPeek communicates with hidden remote servers and receives commands, with unencrypted network traffic suggesting the attack functions remain active and run automatically at regular intervals. The firm's Chief Information Security Officer, 23pds, separately stressed the need for immediate device updates, warning that a full-chain exploit framework on iOS could affect versions 13 to 26.5 through social engineering and memory corruption techniques. Users who installed or used FomoPeek version 1.1 or 1.2 are advised to check asset movements, generate a new private key and mnemonic phrase on a trusted device where the app was never installed, transfer assets to the new wallet as soon as possible, update iOS, and remove FomoPeek without continuing to use it.