mt logoMyToken
ETH Gas
한국어

SlowMist: FomoPeek versions 1.1–1.2 contain malicious code that could lead to the leakage of private keys and mnemonic phrases.

2026-09-19 07:35:17
공유하다share

According to BlockBeats, on September 19, SlowMist issued a security alert stating that it had recently received multiple reports of FomoPeek users' assets being stolen. A joint investigation with the OKX security team revealed that some affected users had previously installed or used FomoPeek versions 1.1–1.2, and the application contained malicious code.


SlowMist reports that FomoPeek contains modules unrelated to normal business operations, one of which includes a kernel vulnerability exploit framework for iOS systems. This framework supports eight different attack methods and can automatically select the appropriate exploit based on the device model and iOS version. Affected systems include iOS 12.0 to 18.7 and iOS 26.0 to 26.1. If successfully exploited, applications could breach the iOS sandbox and access and decrypt Keychain data, potentially leading to the leakage of private keys, mnemonic phrases, login credentials, and other sensitive files.


In addition, FomoPeek connects to hidden servers unrelated to its public services and can receive remote commands. SlowMist stated that its analysis of captured plaintext traffic shows that the attack functionality is currently enabled and runs automatically on a regular schedule.


SlowMist recommends that users who have installed or used FomoPeek versions 1.1–1.2 immediately check their assets for any anomalies, generate a new private key and mnemonic phrase on a trusted device that has never had the app installed, transfer their assets to a new account as soon as possible, upgrade to the latest iOS version, and not continue to use or reinstall FomoPeek.

면책 조항: 이 기사의 저작권은 원저자에게 있으며 MyToken을 대표하지 않습니다.(www.mytokencap.com)의견 및 입장 콘텐츠에 대한 질문이 있는 경우 저희에게 연락하십시오
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
https://t.me/mytokenGroup