Blockchain security company SlowMist announced that malicious code capable of stealing users’ private keys and seed phrases has been detected in versions 1.1 and 1.2 of the FomoPeek application. The company stated that it recently received reports from multiple FomoPeek users about their assets being stolen, and a joint investigation with the OKX security team revealed that some affected users had previously installed or used versions 1.1 or 1.2 of FomoPeek.
According to SlowMist’s analysis, the application contains various modules not related to its normal functions. One of these is identified as an exploit framework targeting kernel vulnerabilities in iOS systems. This framework reportedly supports eight different attack methods and can automatically select the appropriate vulnerability based on the device model and iOS version.
The company stated that the attacks can affect iOS versions 12.0 through 18.7, as well as iOS 26.0 and 26.1. If the vulnerability is exploited, the application can bypass iOS sandbox protection and access and decrypt Keychain data. In such a scenario, private keys, seeds or mnemonics, login credentials, and other sensitive files on the device could fall into the hands of attackers.
SlowMist also found that FomoPeek communicates with and receives remote commands from hidden servers that are not connected to public services. Analysis of the intercepted unencrypted network traffic suggests that the attack functions are still active and run automatically at regular intervals.
The security company urged those who have installed or previously used FomoPeek version 1.1 or 1.2 to immediately check their asset movements. Users were advised to generate a new private key and mnemonic phrase via a trusted device where the app was never installed, transfer their assets to the new wallet as soon as possible, and upgrade their devices to the latest iOS version.
SlowMist also added that users should not continue using FomoPeek and should reinstall the application.
*This is not investment advice.


