FomoPeek iPhone App Carried Malicious Code as Wallet Received $580K
Versions 1.1 and 1.2 included modules that could target data from other apps, while version 1.3 removed them.

FomoPeek, an iPhone app marketed as a read-only crypto wallet monitor, carried code capable of reaching data held by other applications, while an attacker-linked wallet received nearly $580,000 in Tether (USDT).
Versions 1.1 and 1.2 included modules named apptrace and libapptracecore, along with an exploit framework containing eight methods. The code was designed to select an approach based on the device model and iOS version, potentially escaping the app sandbox and accessing Keychain data and files belonging to other apps.
In an isolated test, the code produced a collection list targeting 19 wallet and note-taking apps. The test also captured an upload of an Apple Notes data container, where users may store recovery phrases, private keys or other sensitive information.
A wallet identified as attacker-linked became active Sept. 15 and received 579,984.34 USDT across multiple networks by Sept. 20. That total reflects the wallet’s receipts and has not been confirmed as the amount stolen through FomoPeek.
The app’s first affected version was released Sept. 9, followed by version 1.2 on Sept. 12. Version 1.3 arrived Sept. 17 with the malicious modules removed. The number of affected users and successfully exploited devices has not been disclosed.

