Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT
Fomopeek, a malicious iPhone app distributed by way of Apple’s App Store, has been linked to practically $580,000 in stolen USDT.
Blockchain safety agency SlowMist started investigating the app over the weekend after receiving reviews of stolen belongings linked to uncovered non-public keys.
Some victims had beforehand put in variations 1.1 or 1.2 of the Fomopeek app, which was marketed as a read-only software for monitoring giant cryptocurrency transactions throughout Ethereum, Solana and Tron.
What is Fomopeek?
Working with safety researchers at crypto exchange OKX, SlowMist found two modules embedded in these variations that had no connection to FomoPeek’s marketed monitoring features.
One communicated with exterior command-and-control infrastructure, whereas the opposite contained a kernel exploitation framework with eight assault strategies that would alter to the sufferer’s iPhone mannequin and operating-system model.
A profitable exploit may escape Apple’s software sandbox and attain Keychain data and information belonging to different apps. That created a route to regionally saved non-public keys, seed phrases, and login credentials with out requiring customers to join a pockets or enter these particulars into FomoPeek.
SlowMist founder Yu Xian mentioned the danger prolonged to passwords saved in Apple’s Keychain and encrypted information held by different purposes. An attacker who obtained each may probably unlock pockets credentials and different delicate data saved on the machine.
He explained:
“After a profitable assault, the app can break by way of the iOS sandbox isolation mechanism, then learn and decrypt the system keychain (Keychain), and entry knowledge information from different apps on the machine. Private keys, mnemonic phrases, login credentials, chat histories, information, and different consumer knowledge saved on the machine could all face the danger of leakage in consequence. Additionally, the app connects to covert servers unrelated to its public enterprise features to obtain distant directions.”
The malicious parts weren’t current in FomoPeek’s authentic launch. SlowMist discovered them in model 1.1, launched Sept. 9, and model 1.2 on Sept. 12, earlier than eradicating them in model 1.3 on Sept. 17.
Researchers additionally discovered that the framework may obtain directions from a distant server, together with settings that ruled whether or not exploitation was enabled and the way typically it could run.
Nearly $580,000 stolen
The technical findings had been adopted by an on-chain path displaying that attackers had already transformed that entry into losses.
Blockchain evaluation agency Salus identified 0x6d37f2C5e8F8546b648D317295565dA95975f4BB because the attacker handle and estimated proceeds from the incident at about 579,900 USDT.
Salus traced 401,028 USDT by way of three middleman addresses to FixedFloat. Another 20,000 USDT moved in two transactions by way of deposit addresses earlier than being consolidated right into a KuCoin sizzling pockets.

An extra 111,458 USDT was routed by way of an handle Salus related to an escrow platform, whereas one other 10,000 USDT handed by way of the CCE mixing service earlier than reaching addresses linked to an escrow service.
Salus mentioned its evaluation additionally indicated that the group behind the FomoPeek incident had been concerned in a separate private-key theft in June. Investigators are nonetheless figuring out whether or not the identical method was used in that assault.
Crypto platforms warn customers as custody debate returns
The losses and the potential attain of the exploit have prompted warnings from a number of crypto platforms, together with Binance, OKX, Gate, Bitget Wallet and Rabby.
Binance warned:
“The third-party app FomoPeek (variations 1.1–1.2) accommodates malicious code that may exploit iOS system vulnerabilities to achieve the best stage of machine privileges, probably accessing delicate knowledge saved on the machine, together with non-public keys, seed phrases, login credentials, chat historical past, information, and extra. Please observe that one of these malware targets the machine itself. If an assault succeeds, knowledge from all apps on the affected machine could also be accessed.”
In gentle of this, the crypto companies have broadly issued the identical steering, urging crypto customers to take away FomoPeek, replace iOS, and transfer belongings to newly created wallets on units the place the compromised app was by no means put in.
These recent credentials are essential as a result of deleting the app or patching the working system can’t invalidate a personal key that will have already got been copied.
Meanwhile, the incident additionally comes two months after on-chain investigator ZachXBT argued that a separate iPhone dedicated to crypto could possibly be preferable to current {hardware} wallets for storing funds and signing transactions.
His advice relied on conserving the machine remoted from on a regular basis looking, messaging, and different exercise that would develop the assault floor.
FomoPeek exposes a distinct weak point in that mannequin. The app was itself constructed for crypto customers and distributed by way of Apple’s official marketplace, but researchers say it contained tooling able to breaching the boundaries separating purposes on the machine.
That doesn’t set up that devoted crypto iPhones are inherently much less safe than {hardware} wallets. However, it reveals that isolation presents restricted safety if software program put in on the machine can compromise the working system itself.
For affected customers, the quick focus is now on containing additional losses and tracing the stolen funds.
Salus continues to observe addresses linked to the remaining proceeds, whereas Binance and different platforms monitor for deposits that would give investigators one other alternative to monitor or prohibit the motion of the stolen USDT.
The put up Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT appeared first on CryptoSlate.
