SlowMist and OKX security teams confirmed on September 19, 2026 that FomoPeek versions 1.1 and 1.2 contained malicious code capable of stealing private keys, mnemonic phrases, and other sensitive credentials stored on iOS devices. Marketed as a whale tracking tool for Solana, Ethereum, and TRON, the app hid an iOS kernel exploit framework using eight distinct attack methods targeting iOS versions 12.0 through 26.1. Researchers found the malicious functions already active and communicating with remote servers to execute unauthorized commands in real time. Financial losses and specific compromised wallet addresses had not been publicly disclosed at the time of the alert. SlowMist and OKX advised affected users to immediately transfer assets to wallets generated on devices that never installed FomoPeek.
Source: Read the original article

