mt logoMyToken
ETH Gas
简体中文

SlowMist: FomoPeek versions 1.1–1.2 contain malicious code that could lead to the leakage of private keys and mnemonic phrases.

2026-09-19 07:35:17
分享share

According to BlockBeats, on September 19, SlowMist issued a security alert stating that it had recently received multiple reports of FomoPeek users' assets being stolen. A joint investigation with the OKX security team revealed that some affected users had previously installed or used FomoPeek versions 1.1–1.2, and the application contained malicious code.


SlowMist reports that FomoPeek contains modules unrelated to normal business operations, one of which includes a kernel vulnerability exploit framework for iOS systems. This framework supports eight different attack methods and can automatically select the appropriate exploit based on the device model and iOS version. Affected systems include iOS 12.0 to 18.7 and iOS 26.0 to 26.1. If successfully exploited, applications could breach the iOS sandbox and access and decrypt Keychain data, potentially leading to the leakage of private keys, mnemonic phrases, login credentials, and other sensitive files.


In addition, FomoPeek connects to hidden servers unrelated to its public services and can receive remote commands. SlowMist stated that its analysis of captured plaintext traffic shows that the attack functionality is currently enabled and runs automatically on a regular schedule.


SlowMist recommends that users who have installed or used FomoPeek versions 1.1–1.2 immediately check their assets for any anomalies, generate a new private key and mnemonic phrase on a trusted device that has never had the app installed, transfer their assets to a new account as soon as possible, upgrade to the latest iOS version, and not continue to use or reinstall FomoPeek.

免责声明:本文版权归原作者所有,不代表MyToken(www.mytokencap.com)观点和立场;如有关于内容、版权等问题,请与我们联系。
更多精彩内容请查阅
X(https://x.com/MyTokencap)
或加入社区了解更多MyToken-官方华文电报群
https://t.me/mytoken_cn