Crypto World
Binance warns iPhone users of FomoPeek malware targeting crypto wallets
Binance has warned iPhone and iPad users to check whether they have installed FomoPeek after security researchers linked versions 1.1 and 1.2 of the app to malicious code capable of exposing private keys, seed phrases and other data stored across affected devices.
Summary
- Binance has warned iPhone and iPad users after malicious code was discovered in FomoPeek versions 1.1 and 1.2.
- The malware could exploit iOS vulnerabilities to access private keys, seed phrases, login credentials and data stored by other apps.
- Affected self custody users were advised to create new wallets on clean devices and transfer their assets to the new addresses.
According to Binance, the warning follows a security incident disclosed by the community and findings from blockchain security firms including SlowMist, which found that the affected FomoPeek versions could exploit vulnerabilities in Apple’s iOS operating system and obtain high level privileges on a device.
The malware targets the device itself instead of a specific crypto application, Binance said. A successful attack could therefore expose information held by other apps, including login credentials, chat records and files alongside cryptocurrency wallet data.
Users who have installed FomoPeek and run iOS 26.x or an earlier version should remove the application, avoid reinstalling it and update their operating system to the latest available version, according to Binance.
Self custody wallet users were advised to use a separate device that has never had FomoPeek installed to create a new wallet and transfer their assets to the new address. Binance asked anyone who detects unusual asset activity to preserve the affected device and relevant evidence before contacting customer support.
FomoPeek malware could escape the iOS sandbox
SlowMist’s investigation provided more detail on how the malicious versions operated after the security firm received multiple reports of stolen assets involving private key exposure.
Working with the OKX security team, researchers found two modules inside FomoPeek versions 1.1 and 1.2 that were unrelated to the application’s advertised functions. One contained an iOS kernel exploitation framework equipped with eight exploit methods, allowing it to select an attack method based on the device model and operating system version.
The framework’s declared coverage included iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1, according to the researchers. SlowMist said older versions of iOS generally faced a higher level of risk.
Once an exploit succeeded, the malicious code could escape the iOS sandbox, decrypt Keychain data and access files belonging to other applications. Such access could expose private keys, wallet recovery phrases, account credentials, conversations and locally stored files.
Researchers found that the malicious code communicated with infrastructure unrelated to FomoPeek’s public services and could receive remote instructions. Analysis of its communications showed that operators could control exploit execution and how frequently the process ran.
Historical versions obtained through the official App Store showed that FomoPeek 1.0 did not contain the two malicious frameworks. Version 1.1, build 105, introduced them on Sept. 9, while version 1.2, build 110, retained the code after its Sept. 12 release.
Version 1.3, build 111, removed both frameworks on Sept. 17, according to the security analysis. The affected 1.1 and 1.2 versions had been distributed through Apple’s official App Store instead of third party or re-signed installations.
Crypto wallet malware has repeatedly targeted mobile devices
Mobile devices have remained a target for malware designed to obtain crypto wallet credentials. In July, crypto.news previously reported on the SparkKitty mobile spyware, which could collect images from infected iOS and Android devices and send them to servers controlled by attackers.
Kaspersky had initially detailed the malware in June 2025 after finding infected applications distributed through Apple’s App Store, Google Play and unofficial channels. SparkKitty sought wallet recovery phrases, passwords and other sensitive information that users had stored as images on their phones.
An earlier malware family called SparkCat used optical character recognition to scan images for cryptocurrency recovery phrases. Some infected applications carrying the malicious software had reached official app stores, while Kaspersky said the campaign had been active since March 2024.
Researchers have found other methods for compromising iPhones without relying on users storing seed phrase screenshots. In March, Google’s Threat Intelligence Group identified an iPhone exploit kit known as Coruna that contained five complete exploit chains and 23 vulnerabilities.
The framework targeted devices running versions between iOS 13 and iOS 17.2.1 and could search compromised phones for cryptocurrency wallet recovery phrases and financial information. Google researchers said the toolkit had moved through different groups over time, including financially motivated cybercriminals.
Malicious apps have reached Apple’s App Store
Crypto users have faced separate threats from applications that impersonate legitimate wallet software.
In August, a fake Wasabi Wallet app appeared on Apple’s App Store and was linked by security monitoring reports to the theft of roughly 6 BTC from one victim.
The fraudulent listing was identified as the 27th reported crypto wallet clone found on the App Store during 2026 at the time. A fake Ledger application represented the largest reported case among the clones, with roughly $9.3 million stolen.
Another fake Ledger Live app had previously been linked to the loss of 5.9 BTC worth roughly $420,000 from American musician Garrett Dutton, known professionally as G. Love.
Dutton downloaded software posing as the Ledger Live manager onto a new MacBook Neo and entered his recovery phrase into the fraudulent application. Blockchain records showed the stolen Bitcoin subsequently moving to several deposit addresses associated with the KuCoin exchange.
Unlike wallet impersonation schemes that depend on convincing a user to manually surrender a recovery phrase, SlowMist’s FomoPeek findings describe malicious code capable of obtaining elevated system access and collecting information from other applications after exploiting the operating system.
Earlier mobile malware drained thousands of crypto wallets
SlowMist has previously investigated malicious applications that obtained wallet information directly from users’ devices.
In February 2025, the security firm reported that a fake application called BOM had compromised more than 13,000 wallets across Android and iOS, with estimated losses exceeding $1.82 million.
The application requested access to files, photos and media before scanning device storage for private keys and mnemonic phrases and transmitting the information to a remote server, according to the investigation.
Onchain analysis linked the main attacker address to stolen assets that moved across BNB Chain, Ethereum, Polygon, Arbitrum and Base. The affected cryptocurrencies included USDT, Ethereum, Wrapped Bitcoin and Dogecoin.
For FomoPeek users, SlowMist recommended checking accounts for unauthorized activity and generating a new private key and seed phrase on a trusted device where the affected application had never been installed. Assets held in wallets potentially exposed through versions 1.1 or 1.2 should then be moved to the newly generated wallet.
Binance gave similar instructions in its security notice, while advising users to keep their device software updated and avoid applications obtained from untrusted sources.
You must be logged in to post a comment Login