• About
  • FAQ
  • Earn Bitcoin while Surfing the net
  • Buy & Sell Crypto on Paxful
Newsletter
Approx Foundation
  • Home
    • Home – Layout 1
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
  • Home
    • Home – Layout 1
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Business
  • Guide
  • Contact Us
No Result
View All Result
Approx Foundation
No Result
View All Result
Home Bitcoin

iPhone Crypto App Hides Malicious Code as Attacker Wallet Nets $580K

Moussa by Moussa
September 24, 2026
in Bitcoin
0
iPhone Crypto App Hides Malicious Code as Attacker Wallet Nets $580K
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

Senate Map Drives Polymarket’s 65.5% Democratic Odds

Senate Map Drives Polymarket’s 65.5% Democratic Odds

September 23, 2026
SpaceX Tokenization Scramble Shows The Difference Between Tokens And Real Shares

Binance Extends Tokenized Stock Utility With Soxl Dividend Support

September 23, 2026


Key Takeaways

  • Malicious code appeared in two official App Store versions of FomoPeek.
  • In a controlled test, the code collected and uploaded Apple Notes data.
  • A wallet linked to the attacker received 579,984.34 USDT.

How FomoPeek Reached the App Store With Malicious Code

People who installed FomoPeek to monitor crypto wallets may have exposed data stored in other iPhone apps. In a threat intelligence analysis published on Sept. 20, blockchain security firm SlowMist reported finding malicious modules in versions 1.1 and 1.2 distributed through the Apple App Store.

FomoPeek presented itself as a “read-only on-chain monitoring and alerting tool” that did not require users to connect a wallet or provide a seed phrase. That description concealed code capable of bypassing iPhone security protections, collecting information from other apps and sending it to a remote server, according to SlowMist. The firm and OKX’s security team investigated after receiving reports of stolen assets and exposed private keys.

To establish which downloads carried the code, investigators compared copies of FomoPeek’s App Store releases. The app and the two malicious modules had been signed by the same Apple developer identity, and the downloaded files retained App Store encryption records. That evidence placed the modules inside the officially distributed app, rather than in a copy altered after download.

SlowMist also traced funds to a wallet it identified as the attacker’s primary address. The address became active Sept. 15 and received 579,984.34 USDT across several blockchain networks, with funds still flowing in when SlowMist published its report. Investigators followed transfers through swaps and other addresses. The amount is the wallet’s total receipts, not a confirmed tally of crypto stolen through FomoPeek.

What Investigators Saw When They Tested the App

SlowMist then examined how the hidden modules operated. One retrieved an encrypted server address from Bitbucket, sent information about the iPhone, and requested instructions. The server could select data to collect and control whether the app attempted to exploit the device.

During the observed test, the server had exploitation switched off. Researchers enabled it in an isolated environment to examine the remaining steps. The app then received a list targeting 19 wallet and note-taking apps. Investigators captured an upload of the Apple Notes data container, decrypted the network traffic, and reconstructed the archive sent from the test device. Those findings show what the code could do when activated; they do not establish which data it collected from other users’ phones.

The app’s code included an exploitation strategy named DarkSwordStrategy, which shares its name with DarkSword, an iOS exploit chain documented by Google Threat Intelligence Group in March.

The threat to crypto wallets is direct: An attacker who obtains a private key or recovery phrase can access assets controlled by it. Earlier reporting on DarkSword described SlowMist’s warning that attackers could use iOS exploits to reach private keys. FomoPeek added another concern by carrying its malicious modules in official App Store releases.

Affected Versions and the Risk to Existing Wallets

SlowMist found the modules in FomoPeek version 1.1, released Sept. 9, and version 1.2, released Sept. 12. They were absent from version 1.0 and removed in version 1.3 on Sept. 17. Anyone who used either affected version may still face exposure after deleting or updating the app, as information already transmitted cannot be retrieved by removing the app.

Other fraudulent App Store downloads have put crypto holdings at risk through different methods. In July, three investors alleged losses from a counterfeit Sparrow Wallet app after entering their recovery phrases. In that case, users supplied the information directly; FomoPeek’s hidden code was designed to collect data beyond its own app.

An investigator also linked a fake Ledger app to reported crypto thefts in April. Both the Ledger and Sparrow cases involved counterfeit wallet apps. FomoPeek appeared to be a monitoring tool, so its users had no stated reason to expect it to access private information held elsewhere on their phones.

SlowMist advised users of FomoPeek versions 1.1 and 1.2 to treat seed phrases, private keys, and sensitive credentials stored on those devices as potentially compromised. While cold storage keeps keys offline, the firm’s immediate recommendation was to create a new wallet on a secure device that never ran the affected app and transfer assets from wallets whose keys may have been exposed.



Source link

Share76Tweet47

Related Posts

Senate Map Drives Polymarket’s 65.5% Democratic Odds

Senate Map Drives Polymarket’s 65.5% Democratic Odds

by Moussa
September 23, 2026
0

US Midterms Betting Odds: Polymarket’s market for Which party will win the Senate in 2026? showed Democrats at 66% and...

SpaceX Tokenization Scramble Shows The Difference Between Tokens And Real Shares

Binance Extends Tokenized Stock Utility With Soxl Dividend Support

by Moussa
September 23, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure TL;DR Binance will process cash dividends for...

Bybit Adds Support For Avalanche v1.15.0 Network Upgrade

by Moussa
September 23, 2026
0

TL;DR Bybit has confirmed support for Avalanche’s v1.15.0 network upgrade. The exchange is updating its Avalanche node infrastructure while keeping...

NYSE And Blockchain.com To List Tokenized Stocks

NYSE And Blockchain.com To List Tokenized Stocks

by Moussa
September 23, 2026
0

The New York Stock Exchange and crypto exchange Blockchain.com have signed a memorandum of understanding to debut tokenized stocks.  According...

Bitcoin Price Plunges Below $84K as Rally Snaps

Bitcoin Price Plunges Below $84K as Rally Snaps

by Moussa
September 23, 2026
0

Key TakeawaysBitcoin dropped below $84,000 after failing to breach resistance at $87,000 on Wednesday.Coinglass data shows the crash triggered $423M...

Load More

youssufi.com

sephina.com

[vc_row full_width="stretch_row" parallax="content-moving" vc_row_background="" background_repeat="no-repeat" background_position="center center" footer_scheme="dark" css=".vc_custom_1517813231908{padding-top: 60px !important;padding-bottom: 30px !important;background-color: #191818 !important;background-position: center;background-repeat: no-repeat !important;background-size: cover !important;}" footer_widget_title_color="#fcbf46" footer_button_bg="#fcb11e"][vc_column width="1/4"]

We bring you the latest in Crypto News

[/vc_column][vc_column width="1/4"][vc_wp_categories]
[/vc_column][vc_column width="1/4"][vc_wp_tagcloud taxonomy="post_tag"][/vc_column][vc_column width="1/4"]

Newsletter

[vc_raw_html]JTNDcCUzRSUzQ2RpdiUyMGNsYXNzJTNEJTIydG5wJTIwdG5wLXN1YnNjcmlwdGlvbiUyMiUzRSUwQSUzQ2Zvcm0lMjBtZXRob2QlM0QlMjJwb3N0JTIyJTIwYWN0aW9uJTNEJTIyaHR0cHMlM0ElMkYlMkZhcHByb3gub3JnJTJGJTNGbmElM0RzJTIyJTNFJTBBJTBBJTNDaW5wdXQlMjB0eXBlJTNEJTIyaGlkZGVuJTIyJTIwbmFtZSUzRCUyMm5sYW5nJTIyJTIwdmFsdWUlM0QlMjIlMjIlM0UlM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1maXJzdG5hbWUlMjIlM0UlM0NsYWJlbCUyMGZvciUzRCUyMnRucC0xJTIyJTNFRmlyc3QlMjBuYW1lJTIwb3IlMjBmdWxsJTIwbmFtZSUzQyUyRmxhYmVsJTNFJTBBJTNDaW5wdXQlMjBjbGFzcyUzRCUyMnRucC1uYW1lJTIyJTIwdHlwZSUzRCUyMnRleHQlMjIlMjBuYW1lJTNEJTIybm4lMjIlMjBpZCUzRCUyMnRucC0xJTIyJTIwdmFsdWUlM0QlMjIlMjIlM0UlM0MlMkZkaXYlM0UlMEElM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1lbWFpbCUyMiUzRSUzQ2xhYmVsJTIwZm9yJTNEJTIydG5wLTIlMjIlM0VFbWFpbCUzQyUyRmxhYmVsJTNFJTBBJTNDaW5wdXQlMjBjbGFzcyUzRCUyMnRucC1lbWFpbCUyMiUyMHR5cGUlM0QlMjJlbWFpbCUyMiUyMG5hbWUlM0QlMjJuZSUyMiUyMGlkJTNEJTIydG5wLTIlMjIlMjB2YWx1ZSUzRCUyMiUyMiUyMHJlcXVpcmVkJTNFJTNDJTJGZGl2JTNFJTBBJTNDZGl2JTIwY2xhc3MlM0QlMjJ0bnAtZmllbGQlMjB0bnAtcHJpdmFjeS1maWVsZCUyMiUzRSUzQ2xhYmVsJTNFJTNDaW5wdXQlMjB0eXBlJTNEJTIyY2hlY2tib3glMjIlMjBuYW1lJTNEJTIybnklMjIlMjByZXF1aXJlZCUyMGNsYXNzJTNEJTIydG5wLXByaXZhY3klMjIlM0UlQzIlQTBCeSUyMGNvbnRpbnVpbmclMkMlMjB5b3UlMjBhY2NlcHQlMjB0aGUlMjBwcml2YWN5JTIwcG9saWN5JTNDJTJGbGFiZWwlM0UlM0MlMkZkaXYlM0UlM0NkaXYlMjBjbGFzcyUzRCUyMnRucC1maWVsZCUyMHRucC1maWVsZC1idXR0b24lMjIlM0UlM0NpbnB1dCUyMGNsYXNzJTNEJTIydG5wLXN1Ym1pdCUyMiUyMHR5cGUlM0QlMjJzdWJtaXQlMjIlMjB2YWx1ZSUzRCUyMlN1YnNjcmliZSUyMiUyMCUzRSUwQSUzQyUyRmRpdiUzRSUwQSUzQyUyRmZvcm0lM0UlMEElM0MlMkZkaXYlM0UlM0NiciUyRiUzRSUzQyUyRnAlM0U=[/vc_raw_html][/vc_column][/vc_row]
No Result
View All Result
  • Contact Us
  • Homepages
  • Business
  • Guide

© 2024 APPROX FOUNDATION - The Crypto Currency News