security · Security · iOS · Wallet Theft

Malicious FomoPeek iOS Releases Linked to About $580K in Crypto Theft

SlowMist linked malicious FomoPeek releases to iOS kernel exploits, sandbox escape and an address that received approximately 579,984 USDT.

Observed September 23, 2026 at 9:38 AMBlue Rogues Newsroom
Malicious FomoPeek iOS Releases Linked to About $580K in Crypto Theft — Blue Rogues Crypto editorial artwork
Blue Rogues editorial artwork · BRC-20260923-006

What happened

SlowMist said malicious App Store versions released on September 9 and 12 exploited iOS kernel flaws, escaped the application sandbox and accessed Keychain data and files belonging to other apps. An associated address received about 579,984 USDT.

Blue Rogues read

The incident illustrates that official-store distribution reduces but does not eliminate application risk. A compromised device can expose secrets beyond the malicious app's own storage boundary.

What this confirms

The security analysis connects specific releases, exploit behavior and an associated receiving address. Version 1.3, released September 17, removed the reported malicious modules.

What it does not confirm

The report does not prove that every transfer to the address came from the app, nor does it independently attribute the operator. Affected users should follow verified remediation guidance and treat exposed credentials cautiously.

Sources and disclosures

Source: Cointelegraph citing SlowMist. The report is used within its stated scope, and attributed claims remain attributed. Blue Rogues has not converted a reported or conditional fact into independent certainty.

Update note

Observed September 23, 2026 at approximately 09:38 BRT. Any time-sensitive figure or developing status must be refreshed immediately before publication.