Binance Wallet issued an urgent security advisory on September 19 telling iPhone and iPad users to check whether they have ever installed FomoPeek, after an investigation by SlowMist — working with the OKX security team — found that versions 1.1 and 1.2 of the app contained malicious code capable of escaping the iOS sandbox and harvesting private keys, seed phrases and credentials stored by other applications.

The affected versions were distributed through Apple's official App Store, not third-party or re-signed channels, according to the analysis. crypto.news, ChainCatcher and CoinsPress all corroborate the advisory and the underlying findings.

A Whale Tracker That Attacked the Device

FomoPeek was marketed as a read-only whale-tracking app covering Solana, Ethereum and TRON — a category with no obvious reason to request sensitive privileges. That disguise matters: the malware targeted the device itself rather than a specific crypto application, so a successful attack exposed everything on the phone, including login credentials, chat records and files held by unrelated apps.

SlowMist opened the investigation after receiving multiple reports of stolen assets involving private-key exposure. Researchers found two modules inside the affected versions that were unrelated to the app's advertised functions — including an iOS kernel exploitation framework equipped with eight distinct exploit methods, allowing the operator to select an approach based on the device model and operating system version.

The framework's declared coverage spanned iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1, with older iOS versions facing generally higher risk, the researchers said. Once an exploit succeeded, the malicious code could escape the sandbox, decrypt Keychain data and access files belonging to other applications — the mechanism by which wallet key material became reachable.

The Timeline: Eight Days in the Store

The version history reconstructed by SlowMist narrows the exposure window with unusual precision:

  • Version 1.0 — did not contain the malicious frameworks.
  • Version 1.1 (build 105) — introduced both modules on September 9.
  • Version 1.2 (build 110) — retained the code after its September 12 release.
  • Version 1.3 (build 111) — removed both frameworks on September 17.

The malicious code communicated with infrastructure unrelated to FomoPeek's public services and could receive remote instructions; analysis of its communications showed operators could control exploit execution and how frequently the process ran, according to the analysis.

What Affected Users Are Told to Do

Binance's advisory and SlowMist's recommendations converge on the same guidance: users who installed FomoPeek and run iOS 26.x or earlier should remove the app, avoid reinstalling it, and update to the latest available iOS version.

For self-custody users the advice goes further, and the reasoning is cold arithmetic: deleting the app cannot revoke a private key or seed phrase that may already have been extracted. Anyone who ran versions 1.1 or 1.2 is advised to generate a new wallet on a separate device that never had the app installed, and transfer assets to the new addresses. Binance asked users who detect unusual asset activity to preserve the affected device and evidence before contacting support.

What Remains Unverified

The investigation establishes the code, its capabilities and its distribution channel. It does not establish the operators: no attribution for the malware has been confirmed, no total of stolen assets has been published, and it is not yet clear how many users ran the affected builds during the eight-day window. Apple has not publicly commented on how the builds passed App Store review.

The incident is at least the third this year in which malicious code reached iOS users through official distribution — after the SparkKitty image-scavenging spyware detailed by Kaspersky and a string of fake wallet clone apps. FomoPeek differs in degree, not kind: it is the first publicly documented case of a full kernel-exploitation framework shipping through the App Store inside a crypto-adjacent utility.

TrustGrade covers the security and trust ecosystem around digital assets. For verified trust data on the platforms and firms shaping it, see trustgrade.ai.