FomoPeek iOS Malware Threatens Crypto Wallet Credentials
SlowMist and OKX security researchers have warned that FomoPeek iOS versions 1.1 and 1.2 contained malicious code allegedly linked to several crypto asset-theft reports. The app was marketed as a read-only whale-tracking tool for Solana, Ethereum and TRON, but investigators identified two modules unrelated to its stated functions.
One module reportedly included an eight-method iOS kernel exploit framework. It could select exploits based on the device and iOS version, bypass the app sandbox, access protected files and decrypt Keychain data. The alleged malware could expose private keys, seed phrases, login credentials, chat histories and personal files. Hidden servers and unencrypted network traffic reportedly enabled recurring activity and remote commands.
The reported exposure includes iOS 12.0–18.7 and iOS 26.0–26.1, although the version references require independent verification. Users who installed FomoPeek 1.1 or 1.2 should treat wallet keys stored or cached on the device as compromised. SlowMist and OKX advised uninstalling the app, updating devices, moving funds to wallets created with fresh keys on a clean device, revoking approvals and reviewing transaction histories.
The FomoPeek iOS malware poses a serious security risk, but its direct impact on crypto prices is likely limited unless further thefts or wider distribution are confirmed. Traders should monitor affected wallets and avoid relying on third-party mobile apps for key custody.
Neutral
The incident is primarily a wallet-security and custody issue rather than a fundamental development affecting Solana, Ethereum or TRON. In the short term, affected users may sell assets to cover losses, while broader traders could reduce activity on mobile and third-party platforms. That could create limited, temporary volatility if additional thefts are confirmed.
However, no evidence in the reports indicates a protocol failure, network disruption or market-wide compromise. The direct price impact on SOL, ETH and TRX is therefore expected to remain limited. Longer term, the incident may increase demand for hardware wallets, fresh-key migration and stronger app security, but it is unlikely by itself to establish a sustained bearish trend.