Cryptocurrency Theft Worth $580K Traced to Harmful iOS Application FomoPeek, SlowMist Reports

Cryptocurrency Theft Worth $580K Traced to Harmful iOS Application FomoPeek, SlowMist Reports

According to SlowMist, compromised versions of FomoPeek made available via Apple's App Store leveraged kernel vulnerabilities in iOS to break free from sandbox restrictions and extract confidential information from additional applications.

A harmful application for iOS devices that was made available through Apple's official App Store has been connected to cryptocurrency thefts totaling close to $580,000, following the discovery by security researchers that it harbored numerous kernel vulnerabilities designed to break out of Apple's protective sandbox environment and gain unauthorized access to sensitive cryptocurrency wallet information.

Based on findings from an investigation released by SlowMist, a blockchain security company, the application known as FomoPeek incorporated a pair of harmful modules with the capability to take advantage of weaknesses in iOS, obtain heightened system permissions and retrieve Keychain information and file data that belonged to separate applications on the device.

According to SlowMist's report, the compromised versions of the application were made public on Sept. 9 and Sept. 12, whereas version 1.3, which was released to the public on Sept. 17, had the harmful elements eliminated from its code.

The company stated that its investigative efforts, which were carried out in collaboration with OKX's security division, were initiated following the receipt of multiple complaints from users who had experienced the loss of digital assets and who were discovered to have previously downloaded and installed the compromised FomoPeek application versions on their devices.

The exploitation framework that was discovered contained eight distinct attack methodologies and explicitly indicated compatibility with iOS versions spanning from 12.0 through 18.7.2 and from 26.0 through 26.1.

Through onchain analytical procedures conducted by SlowMist, investigators were able to identify a principal hacker wallet address linked to the security incident that had received approximately 579,984 USDT in stolen digital assets. According to the firm's findings, this particular address first showed activity on Sept. 15, and the misappropriated funds moved across numerous blockchain networks before ultimately being combined and routed through multiple wallet addresses and cryptocurrency services.

SlowMist indicated that certain portions of the misappropriated funds were channeled toward various services including FixedFloat, KuCoin and cce.cash, whereas other portions of the stolen assets were distributed among additional wallet addresses that the security firm remained actively working to monitor and trace.

Cointelegraph made attempts to contact Apple, SlowMist and OKX to obtain official statements regarding the incident but had not received any responses from these organizations at the time this article was published.

← Back to Blog