An iOS whale-watching app that never asked users for a seed phrase has been tied to nearly $580,000 in stolen cryptocurrency after researchers found it could reach secrets stored by other apps on the same iPhone.
Blockchain security firm SlowMist, working with OKX’s security team, says versions 1.1 and 1.2 of FomoPeek contained two hidden modules with no relation to the app’s advertised job of tracking large transfers on Ethereum, Solana, and Tron.
Those builds reached users through Apple’s App Store on September 9 and September 12.
Version 1.0, published August 29, did not include the extra code. Version 1.3, released September 17, stripped it out and shrank the package from about 10.5 MB to 1.8 MB.
FomoPeek looked ordinary.
It was listed under a developer account, had a website and social channels, and marketed itself as a read-only monitor.
Users did not connect a wallet or type a recovery phrase. Some promotions even paid a few dollars in USDT after people installed the app with a referral code and kept it open on a real device for several minutes.
That last detail later looked less like a growth tactic and more like a technical requirement: at least one of the exploit paths needed minutes of continuous runtime on physical hardware.
SlowMist says the extra frameworks loaded as soon as the app launched. One handled command-and-control traffic.
The other packed a kernel-exploitation toolkit with eight methods that picked a path based on device model and iOS version.
Declared coverage ran from iOS 12.0 through 18.7.2 and also listed 26.0 through 26.1.
If a method succeeded, the implant could leave Apple’s sandbox, read and decrypt Keychain items, and pull files belonging to other apps.
Isolated tests produced a collection list aimed at 19 wallet and notes apps, including well-known mobile wallets and Apple Notes.
A phrase stored only in Notes was therefore as exposed as one sitting in a wallet app.
On-chain tracing put the main attacker address in motion around September 15.
That address collected about 579,984 USDT. Funds later moved across Ethereum, BNB Chain, and Arbitrum, with some routed toward mixers and platforms including FixedFloat, KuCoin, and cce.cash.
Researchers stress that upgrading or deleting the app does not undo data that may already have left the phone.
Anyone who ran 1.1 or 1.2 is being told to treat keys and phrases that lived on that device as burned, generate new credentials on a clean phone that never had FomoPeek, move remaining assets, update iOS, and review related account logins.
The case is less about a fake store listing than about a signed App Store update that briefly carried a full iOS attack stack. It shows how a tool that never touches a wallet can still empty one if it can read the rest of the device.