Malicious iOS app FomoPeek linked to $580K crypto theft, SlowMist says
SlowMist said malicious FomoPeek versions distributed through Apple’s App Store used iOS kernel exploits to escape the sandbox and access sensitive data from other apps.
Asanat Analysis — Why it matters
FomoPeek's sandbox escape via iOS kernel exploits represents a critical infrastructure failure in Apple's app review process. The $580K theft demonstrates that even curated app stores remain viable attack vectors for sophisticated social engineering—malicious actors simply repackaged a legitimate-sounding FOMO-trading tool. This mirrors 2023-2024 patterns where apps like MetaMask phishing variants bypassed initial reviews, then relied on user trust to execute theft.
The incident signals broader iOS security assumptions in crypto UX are broken. Mobile wallets and DeFi interfaces increasingly compete on convenience, but kernel-level privilege escalation means traditional iOS sandboxing provides little protection against determined attackers who can access keychain data, seed phrases stored in memory, or intercept signing requests. SlowMist's attribution may accelerate pressure on Apple to harden its review process specifically for crypto-adjacent apps and tighten kernel exploit disclosure practices.
For the ecosystem: this validates security auditing and multi-signature schemes as non-negotiable infrastructure rather than convenience features. Projects will likely face renewed user scrutiny around native iOS app distributions versus browser-based alternatives, and institutional onboarding teams may deprioritize iOS-native solutions pending enhanced isolation architectures.