Meet the Top 101 in Crypto
News
4 min read

iPhone Crypto Users Urged to Move Funds After FomoPeek Malware Exposes Wallet Keys

Published 21 September 2026
Dr. Guneet Kaur
Authors

Key Takeaways

  • SlowMist says FomoPeek versions 1.1–1.2 contained malicious code capable of stealing private keys, seed phrases, and credentials from iPhones.
  • Researchers found an iOS kernel exploitation framework with eight attack methods, potentially affecting iOS versions from 12.0 through 18.7 and iOS 26.0–26.1.
  • Binance has urged affected self-custody users to generate entirely new wallet credentials on a clean device and move their remaining crypto.

Crypto users who installed the iPhone app FomoPeek are being urged to move their funds after security researchers discovered malware that can bypass Apple’s app protections and extract cryptocurrency wallet credentials.

Blockchain security firm SlowMist issued the warning on Sept. 19 after receiving multiple reports of stolen crypto involving users who had previously installed FomoPeek versions 1.1 or 1.2.

A subsequent investigation conducted with OKX’s security team uncovered two suspicious modules unrelated to the app’s advertised functions.

FomoPeek markets itself as a read-only tool for monitoring whale wallets across Ethereum, Solana and TRON, promising users onchain alerts without taking custody of their assets.

Researchers say the malicious versions were doing considerably more.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
Opened in 2011
Promotions
Get $10 in Bitcoin when you register through a referral link from an existing member.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +81
Promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether USD Coin Solana +76
Opened in 2017
Promotions
Unlock 1,500+ cryptocurrencies and seamless instant swaps in the all-in-one crypto super app ChangeNOW
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +217
 

Eight Exploits Could Break Out of Apple’s Sandbox

SlowMist found one hidden module containing an iOS kernel exploitation framework with eight separate attack methods.

The malware could select an exploit based on the iPhone model and operating-system version. SlowMist’s analysis covered devices running iOS 12.0–18.7 and iOS 26.0–26.1.

If exploitation succeeded, FomoPeek could escape Apple’s application sandbox — the security boundary normally designed to prevent one app from accessing another app’s private information.

From there, researchers said the malware could decrypt Keychain data and access private keys, recovery phrases, login credentials, chat histories, and files from other applications.

That makes the incident particularly dangerous for crypto holders. An attacker obtaining a wallet’s private key or recovery phrase does not need continued access to the victim’s iPhone. The credentials can be imported elsewhere to control the same blockchain assets.

Researchers also detected connections to hidden servers unrelated to FomoPeek’s advertised service. SlowMist said captured network traffic indicated that the malicious functionality was active and configured to execute automatically at regular intervals.

Binance Says Move Crypto to New Wallets

Binance has now issued its own warning to iPhone and iPad users who installed FomoPeek.

Affected users are advised to delete the app, avoid reinstalling it, and update their devices to the latest iOS release.

More importantly, Binance recommends that self-custody users create an entirely new wallet on a device that never had FomoPeek installed and transfer their assets to the new address.

Simply deleting FomoPeek may not be enough.

Once a private key or seed phrase has been copied, the credential itself must be considered compromised.

Reinstalling the same wallet on another phone using the old recovery phrase would therefore recreate the same vulnerable wallet.

Gate issued similar guidance, saying its risk-control systems had detected no losses among its own users, while warning that FomoPeek could put other wallet applications on an infected device at risk.

SlowMist has not disclosed the total amount stolen or the number of successfully compromised devices.

For users who installed versions 1.1 or 1.2, however, the security response goes beyond removing a malicious app: the wallet keys themselves may need to be replaced.

[fo

 

Disclaimer: The information provided in this article is for informational purposes only. It is not intended to be, nor should it be construed as, financial advice. We do not make any warranties regarding the completeness, reliability, or accuracy of this information. All investments involve risk, and past performance does not guarantee future results. We recommend consulting a financial advisor before making any investment decisions.
Dr. Guneet Kaur

Dr. Guneet Kaur is a senior editor at CCN.com and a Science Fellow at Exponential Science. She is a fintech and blockchain expert with extensive experience in digital finance education, blockchain ecosystems, and cryptocurrency markets. She has worked with global media such as Cointelegraph, as well as education and blockchain platforms, to design and lead strategic content and learning initiatives. As an educator and assessor for top-tier executive programs, she bridges real-world fintech trends with academic insight.

Dr. Kaur is also a published researcher and peer reviewer across fintech and data science journals, including Financial Innovation Journal and International Journal of Big Data Intelligence and Applications. Her work spans data-driven analysis, Web3 innovation, and technical content development. With a strong foundation in both industry and academia, she translates complex financial technologies into practical applications, empowering learners, professionals, and institutions across the rapidly evolving digital finance landscape.

Related

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status