CryptoMediumUpdatedOriginally published 22 September 2026Updated 22 September 2026
2 min read

SlowMist Links App Store Malware FomoPeek to Nearly 580,000 USDT Theft

Key Facts

1FomoPeek versions 1.1 and 1.2 contained two malicious modules distributed through the official App Store.
2MistTrack traced 579,984.34 USDT to the primary attacker address, active since September 15, 2026.
3Testing identified a target list covering 19 wallet and note-taking apps.
4SlowMist advises users of versions 1.1 and 1.2 to create new keys on a trusted device and move their assets.

SlowMist said its joint analysis with the OKX security team confirmed two malicious modules in FomoPeek versions 1.1 and 1.2, which were distributed through the official App Store. Its MistTrack service traced 579,984.34 USDT to the primary attacker address associated with the incident, which became active on September 15, 2026.

FomoPeek was marketed as a read-only wallet-monitoring tool, but the apptrace and libapptracecore modules provided capabilities for remote control, iOS kernel exploitation, sandbox escape, Keychain decryption and cross-app data collection. In an isolated test, researchers received a target list covering 19 wallet and note-taking apps and verified the packaging and upload of an Apple Notes container to the command server.

The version history shows that version 1.0, released on August 29, 2026, did not contain the malicious modules. They appeared in version 1.1 on September 9, remained in version 1.2 on September 12 and were removed from version 1.3 on September 17, leaving a confirmed risk window of September 9 to September 17, 2026.

The financial mechanism is direct: a private key can authorize transfers, so extracting it from the Keychain or wallet files may allow assets to be moved without connecting a wallet to FomoPeek or approving a transaction inside the app. SlowMist said activity involving the primary address spanned Ethereum, BNB Chain and Arbitrum, with most funds consolidated on Ethereum.

SlowMist advised users of versions 1.1 and 1.2 not to rely on deleting or upgrading the app because successfully collected data would already have left the device. Its recommended steps include creating a wallet with a new seed phrase on a trusted device that never ran FomoPeek, transferring assets, treating old keys as exposed and checking for abnormal transfers and authorizations.