FomoPeek crypto app in App Store hid iOS kernel exploits to steal wallet keys
SlowMist and OKX Security found hidden modules apptrace and libapptracecore in versions 1.1 and 1.2 of the FomoPeek crypto tracker on the App Store. The malware escaped the iOS sandbox and could read Keychain data, including passwords, seed phrases and private keys, affecting iOS 12.0–18.7 and 26.0–26.1.
- Hidden apptrace and libapptracecore modules shipped in official App Store builds
- Kernel exploit framework supported eight attack methods per device and iOS version
- Malicious code was live September 9–17, 2026, removed in version 1.3
- Deleting the app is not enough: move funds to a new wallet on a clean device
Read next
Security