Researchers at SlowMist have reported multiple incidents where FomoPeek’s iOS app was used to steal user assets. Their investigation uncovered malicious code inside the app that intercepts seed phrases from crypto wallets. In every confirmed case, private key leaks were also detected, according to the team.

Which Versions and Devices Are at Risk?

Some victims had previously installed and used FomoPeek versions 1.1 and 1.2. Devices running iOS firmware 12.0–18.7 and 26.0–26.1 are at risk.

What Did the Investigation Find?

Researchers found two suspicious modules in the compromised builds that had nothing to do with the app’s advertised features. They believe these modules were added to intercept sensitive data.

How Did the Attack Work?

SlowMist says the compromise happened through interception of seed phrases, which then led to private key leaks and asset theft. The full scale of the incident and a complete list of affected configurations haven’t been disclosed.