SlowMist Links App Store Malware FomoPeek to Nearly 580,000 USDT Theft
Key Facts
SlowMist said its joint analysis with the OKX security team confirmed two malicious modules in FomoPeek versions 1.1 and 1.2, which were distributed through the official App Store. Its MistTrack service traced 579,984.34 USDT to the primary attacker address associated with the incident, which became active on September 15, 2026.
FomoPeek was marketed as a read-only wallet-monitoring tool, but the apptrace and libapptracecore modules provided capabilities for remote control, iOS kernel exploitation, sandbox escape, Keychain decryption and cross-app data collection. In an isolated test, researchers received a target list covering 19 wallet and note-taking apps and verified the packaging and upload of an Apple Notes container to the command server.
The version history shows that version 1.0, released on August 29, 2026, did not contain the malicious modules. They appeared in version 1.1 on September 9, remained in version 1.2 on September 12 and were removed from version 1.3 on September 17, leaving a confirmed risk window of September 9 to September 17, 2026.
The financial mechanism is direct: a private key can authorize transfers, so extracting it from the Keychain or wallet files may allow assets to be moved without connecting a wallet to FomoPeek or approving a transaction inside the app. SlowMist said activity involving the primary address spanned Ethereum, BNB Chain and Arbitrum, with most funds consolidated on Ethereum.
SlowMist advised users of versions 1.1 and 1.2 not to rely on deleting or upgrading the app because successfully collected data would already have left the device. Its recommended steps include creating a wallet with a new seed phrase on a trusted device that never ran FomoPeek, transferring assets, treating old keys as exposed and checking for abnormal transfers and authorizations.