{"id":78579,"date":"2026-09-24T00:32:18","date_gmt":"2026-09-24T00:32:18","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/iphone-crypto-app-hides-malicious-code-as-attacker-wallet-nets-580k\/"},"modified":"2026-09-24T00:32:18","modified_gmt":"2026-09-24T00:32:18","slug":"iphone-crypto-app-hides-malicious-code-as-attacker-wallet-nets-580k","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/iphone-crypto-app-hides-malicious-code-as-attacker-wallet-nets-580k\/","title":{"rendered":"iPhone Crypto App Hides Malicious Code as Attacker Wallet Nets $580K"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Malicious code appeared in two official App Store versions of FomoPeek.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">In a controlled test, the code collected and uploaded Apple Notes data.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">A wallet linked to the attacker received 579,984.34 USDT.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2>How FomoPeek Reached the App Store With Malicious Code<\/h2>\n<p>People who installed FomoPeek to monitor crypto wallets may have exposed data stored in other iPhone apps. In a <a href=\"https:\/\/slowmist.medium.com\/threat-intelligence-analysis-of-fomopeek-app-store-poisoning-and-ios-kernel-exploitation-e568762d11ca\" target=\"_blank\" rel=\"noopener noreferrer\">threat intelligence analysis<\/a> published on Sept. 20, blockchain security firm SlowMist reported finding malicious modules in versions 1.1 and 1.2 distributed through the Apple App Store.<\/p>\n<p>FomoPeek presented itself as a \u201cread-only on-chain monitoring and alerting tool\u201d that did not require users to connect a wallet or provide a seed phrase. That description concealed code capable of bypassing iPhone security protections, collecting information from other apps and sending it to a remote server, according to SlowMist. The firm and OKX\u2019s security team investigated after receiving reports of stolen assets and exposed private keys.<\/p>\n<p>To establish which downloads carried the code, investigators compared copies of FomoPeek\u2019s App Store releases. The app and the two malicious modules had been signed by the same Apple developer identity, and the downloaded files retained App Store encryption records. That evidence placed the modules inside the officially distributed app, rather than in a copy altered after download.<\/p>\n<p>SlowMist also traced funds to a wallet it identified as the attacker\u2019s primary address. The address became active Sept. 15 and received 579,984.34 USDT across several blockchain networks, with funds still flowing in when SlowMist published its report. Investigators followed transfers through swaps and other addresses. The amount is the wallet\u2019s total receipts, not a confirmed tally of crypto stolen through FomoPeek.<\/p>\n<h2>What Investigators Saw When They Tested the App<\/h2>\n<p>SlowMist then examined how the hidden modules operated. One retrieved an encrypted server address from Bitbucket, sent information about the iPhone, and requested instructions. The server could select data to collect and control whether the app attempted to exploit the device.<\/p>\n<p>During the observed test, the server had exploitation switched off. Researchers enabled it in an isolated environment to examine the remaining steps. The app then received a list targeting 19 wallet and note-taking apps. Investigators captured an upload of the Apple Notes data container, decrypted the network traffic, and reconstructed the archive sent from the test device. Those findings show what the code could do when activated; they do not establish which data it collected from other users\u2019 phones.<\/p>\n<p>The app\u2019s code included an exploitation strategy named DarkSwordStrategy, which shares its name with DarkSword, an iOS exploit chain documented by <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/darksword-ios-exploit-chain\" target=\"_blank\" rel=\"noopener noreferrer\">Google Threat Intelligence Group<\/a> in March.<\/p>\n<p>The threat to crypto wallets is direct: An attacker who obtains a private key or recovery phrase can access assets controlled by it. <a href=\"https:\/\/news.bitcoin.com\/security\/slowmist-warns-darksword-ios-exploit-targets-crypto-wallet-keys\/\">Earlier reporting on DarkSword<\/a> described SlowMist\u2019s warning that attackers could use iOS exploits to reach private keys. FomoPeek added another concern by carrying its malicious modules in official App Store releases.<\/p>\n<h2>Affected Versions and the Risk to Existing Wallets<\/h2>\n<p>SlowMist found the modules in FomoPeek version 1.1, released Sept. 9, and version 1.2, released Sept. 12. They were absent from version 1.0 and removed in version 1.3 on Sept. 17. Anyone who used either affected version may still face exposure after deleting or updating the app, as information already transmitted cannot be retrieved by removing the app.<\/p>\n<p>Other fraudulent App Store downloads have put crypto holdings at risk through different methods. In July, three investors <a href=\"https:\/\/news.bitcoin.com\/regulation-and-legal\/a-fake-crypto-wallet-reached-apples-app-store-three-users-say-it-cost-them-1-8-million\/\">alleged losses from a counterfeit Sparrow Wallet app<\/a> after entering their recovery phrases. In that case, users supplied the information directly; FomoPeek\u2019s hidden code was designed to collect data beyond its own app.<\/p>\n<p>An investigator also <a href=\"https:\/\/news.bitcoin.com\/zachxbt-says-apple-app-store-fake-ledger-app-stole-9-5m-from-50-victims-in-one-week\/\">linked a fake Ledger app to reported crypto thefts<\/a> in April. Both the Ledger and Sparrow cases involved counterfeit wallet apps. FomoPeek appeared to be a monitoring tool, so its users had no stated reason to expect it to access private information held elsewhere on their phones.<\/p>\n<p>SlowMist advised users of FomoPeek versions 1.1 and 1.2 to treat seed phrases, private keys, and sensitive credentials stored on those devices as potentially compromised. While<a href=\"https:\/\/www.bitcoin.com\/get-started\/wallet-security\/wallets-custody\/setting-up-your-own-cold-storage-bitcoin-wallet\/\" target=\"_blank\" rel=\"noopener noreferrer\"> cold storage keeps keys offline<\/a>, the firm\u2019s immediate recommendation was to create a new wallet on a secure device that never ran the affected app and transfer assets from wallets whose keys may have been exposed.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/iphone-crypto-app-hides-malicious-code-attacker-wallet-580k\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways Malicious code appeared in two official App Store versions of FomoPeek. In a controlled test, the code collected and uploaded Apple Notes data. A wallet linked to the attacker received 579,984.34 USDT. How FomoPeek Reached the App Store With Malicious Code People who installed FomoPeek to [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":78580,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78579"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=78579"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78579\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/78580"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=78579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=78579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=78579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}