Security researchers at SlowMist and OKX confirmed on September 19, 2026, that FomoPeek, an iOS application marketed as a tracker of large cryptocurrency holders' movements, contained hidden code capable of stealing private keys from other apps on the same device. The app had passed Apple's review process, which makes the finding relevant to any European user who downloaded it through the official App Store.
According to the two firms, versions 1.1 and 1.2 of FomoPeek carried two hidden modules unrelated to the app's declared function of monitoring so-called whale wallets. One of these modules exploited the iOS Keychain, the system's encrypted store for passwords and credentials belonging to other installed apps, using eight distinct attack methods. The specific method deployed against a given device was selected automatically based on the phone model and the version of iOS running on it.
The app was also found to receive instructions from a hidden remote server, reached through an encrypted address hosted on Bitbucket. This channel allowed operators to switch the malicious module on or off remotely without any visible change appearing on the user's device, meaning the app could behave normally for extended periods before activating the exploit.
What affected users should do
SlowMist has issued a set of recommendations for anyone who installed FomoPeek. Users are advised to check their accounts and assets for unusual activity, create a new wallet on a device that has never had the app installed, and migrate funds to that wallet as soon as possible. The firm also recommends updating iOS to its latest version and warns that FomoPeek should not be reinstalled under any circumstances.
Neither SlowMist nor OKX has disclosed a total figure for funds stolen or the number of users affected by the exploit.
A wider question about where keys live
The incident has drawn comment from hardware wallet maker Keystone, which framed the case as a reminder of the risks inherent to storing keys on general-purpose smartphones. "A key stored on a smartphone is exposed to any OS vulnerability, even if the wallet app itself has no flaws," the company said. Keystone recommends generating a seed phrase offline, on a device that never connects to the internet, as a way to avoid this category of attack entirely.
Even under that model, risk is not eliminated. The hardware device itself, its screen, and the software used to construct a transaction before it is signed all remain potential points of attack, though the overall surface is considerably smaller than on a phone carrying many third-party apps.
The FomoPeek case joins a series of recent incidents in which applications approved by official app stores were later found to carry malicious code, underscoring that store vetting does not guarantee the absence of hidden exploits targeting crypto holders.




