On September 19, 2026, blockchain security firm SlowMist published a theft-risk warning about an iOS app called FomoPeek. The warning read differently from the usual “malicious dApp” advisory. SlowMist said it had received multiple reports from users whose crypto assets had been stolen, that every case it traced involved leaked private keys, and that a joint investigation with OKX’s security team had confirmed why: some of those victims had installed FomoPeek versions 1.1–1.2, and those builds contained a professional iOS kernel exploitation framework (Lookonchain carries the full alert, TechFlow’s English version).

This article covers what the app claimed to be, what was actually inside it, and — the part no other coverage did — the infrastructure forensics we ran ourselves: App Store records, domain registration data, and DNS telemetry that show exactly how short-lived this operation was.

What FomoPeek promised

FomoPeek marketed itself as a monitoring tool for crypto investors. The App Store description, preserved by the Japanese app tracker APPLION after Apple delisted the app, pitched it like this:

“FomoPeek is a read-only whale-tracking and smart-alert app for crypto investors. Monitor high-value wallets across Solana, Ethereum, and TRON, and get notified the moment meaningful on-chain activity happens.”

The feature list was exactly what a retail trader wants: add any public wallet address to a watchlist, customize thresholds, receive push alerts on large moves, browse a curated feed of smart-money activity. And the description closed with the sentence that did the most work:

“Important: FomoPeek is a monitoring and alerting tool only. We do NOT execute trades, custody funds, or collect deposits.”

Every word of that pitch is about not touching your money. That is the point — and the trap. If you want to understand whale tracking done the safe way, with a block explorer and public data only, see our guide to tracking whale wallets.

What was actually inside versions 1.1–1.2

According to the SlowMist alert, joint analysis with OKX’s security team found the app carrying clear evidence of planted malicious code. Besides its normal features, the app bundled two modules unrelated to its stated business, one of which contained an iOS kernel exploitation framework integrating eight distinct exploit methods that automatically choose an attack path based on the device model and iOS version. Affected versions: iOS 12.0–18.7 and 26.0–26.1 — which, taken together, spans essentially every iPhone still in circulation that is not on the very latest patch.

If the exploit succeeds, the app can:

  • Break out of the iOS sandbox isolation mechanism
  • Read and decrypt the system Keychain
  • Access data files belonging to other apps on the device
  • Expose private keys, seed phrases, login credentials, chat history, and files
  • Connect to hidden servers unrelated to its public-facing services and receive remote commands

One detail from the alert deserves emphasis: SlowMist captured plaintext traffic showing the attack functionality was currently enabled and executing automatically at regular intervals. This was not dormant code waiting for a trigger. During the analysis window, the malware was running its attack routine on infected devices on a schedule.

Binance Wallet amplified the advisory the same day, urging iPhone users to check whether they had ever installed FomoPeek and framing the mechanism correctly: this malware attacks the device itself, so if the attack succeeds, data from all apps on the device may be accessed — not just crypto apps (BlockBeats, AInvest summary).

Our forensics: a 23-day operation

We ran our own checks on September 20, 2026. Nothing below relies on rumor; every row is reproducible with public tools.

The App Store record

FieldValueSource
App nameFomoPeekAPPLION cache
Apple app ID6806199011IPA library listing
Bundle IDcom.fomopeek.appIPA library structured data
Developer accountWhaleScanvAPPLION cache
First releasedSeptember 7, 2026APPLION cache
Version 1.2 shippedSeptember 13, 2026 (“Fixed some issues. Optimized UI adaptation.”)APPLION cache
Size / minimum OS11.8 MB, iOS 16.0+APPLION cache
Price / IAPFree, no in-app purchasesAPPLION cache
Status on Sep 20Removed from every storefront we queriedOur lookup checks

The APPLION page is the cleanest surviving snapshot: it cached the full store listing and flags the app as “currently unavailable.” A third-party IPA library had mirrored the version 1.2 binary, extracted from the China storefront — meaning the malicious build circulated both through Apple’s official update channel and through sideloading sites.

We searched the developer name “WhaleScanv” across app stores and the web and could find no other app ever published under this account. It was a burner identity created to pass review once.

Two more observations from these numbers. First, the changelog for the payload version — “Fixed some issues. Optimized UI adaptation” — is the generic text you ship when you do not want a reviewer to look closely. Second, the app weighed 11.8 MB. A framework packing eight kernel exploit methods is dense code; the small footprint, combined with SlowMist’s finding that the app fetched instructions from hidden servers, suggests at least part of the attack machinery was staged or reconfigured remotely rather than shipped whole. That last sentence is our inference, not SlowMist’s finding.

The domain and DNS

The operation’s web presence died even faster than the app:

  • fomopeek.com was registered on August 28, 2026 — eleven days before the app reached the store — through registrar Hello Internet Corp, with an expiry in August 2027 (WHOIS record)
  • Its nameservers pointed at ns1/ns2.jtdnsv1.com — a DNS service hosted on AS140227 (Hong Kong Communications International Co., with an announced LACNIC-space address), infrastructure typical of gray-market hosting resellers. We confirmed the ASN and routing with public IP intelligence
  • By September 20, the domain’s delegation was dead: our DNS-over-HTTPS queries return SERVFAIL with an extended-error code meaning the authoritative servers are unreachable. Not “website down” — the name server itself stopped answering for the zone
  • No snapshot of fomopeek.com exists in the Wayback Machine or archive.today. The site lived and died between two crawler visits

The timeline

DateEvent
Aug 28, 2026fomopeek.com domain registered
Sep 7, 2026FomoPeek v1.0 clears App Store review, goes live
By Sep 13, 2026v1.1 and v1.2 — the malicious builds — ship through the official update channel
~Sep 15, 2026v1.2 IPA mirrored on a third-party sideload library
Sep 19, 2026SlowMist + OKX joint warning; Binance Wallet advisory; victim reports confirmed
Sep 20, 2026App gone from all six storefronts we queried; domain DNS delegation dead

Twenty-three days from domain registration to total burn-down. Roughly twelve days of storefront availability. The malicious versions were live for at most six days before the alert. That compression is the signature of a hit-and-run operation that expected to be caught and planned around it: pass review with a clean-looking build, push the payload fast, harvest, vanish.

The distribution funnel: KOL invite codes and 5-USDT red packets

Getting the app into the store was only half the plan. The other half was a paid distribution campaign that ran through crypto influencer channels in the days before the exposure.

Promo posts from mid-September — still visible in search caches after the app died — show the mechanics. Influencers published personal invite codes, and anyone who registered with a code could collect a small USDT red packet; one post offered followers 5 USDT cash for signing up through the poster’s code. Another pitch positioned the app as the missing companion to a popular memecoin copy-trading platform: on that platform you can watch a wallet buy in, but the app never shows you the address — FomoPeek was sold as the tool that catches exactly that, hooking the tracker onto an existing product’s user base and borrowed trust.

Run the economics and the giveaway stops looking like generosity. A campaign that pays intermediaries per install, and pays users 5 USDT each to activate, only makes sense when every install is worth more to the operator than the payout. For a keychain-draining implant, it is: the bounty on each new device is measured in whatever that device’s wallets hold. The pattern is the same bait as the fake giveaway distribution channels we have documented before — the innovation here was bolting it onto an App Store product instead of a phishing page.

The fallout split into two groups. On the victim side, a Chinese-language Telegram channel summarized it bluntly: the hardest-hit users were the airdrop farmers, who “worked hard farming small amounts and lost everything for a few USDT — you wanted their interest, they wanted your principal” (channel post). On the distribution side, the KOLs who took the promo deal — many of them, by all indications, without knowing what was inside the build — watched their invite codes turn into infection ledgers the day the alert dropped: every install traced through a KOL’s code now ties that KOL’s audience directly to the theft wave.

Gate’s security team, which analyzed the app independently after the SlowMist alert, added a detail that makes the whole funnel more hostile than it already looked: the malware could also read the device clipboard — where copied wallet addresses and two-factor codes live. Gate reported no confirmed losses among its own app’s users at the time of writing (ChainCatcher).

Why “read-only” was the perfect disguise

The cruelest part of this case is that the app’s honesty pitch was technically true. FomoPeek really did not touch your funds. It did not need to.

Most crypto users have internalized a permission model: wallet connects are risky, seed-phrase prompts are hostile, transaction buttons are danger zones. That model assumes the attack happens at the app level. A kernel exploit does not. It escalates to the highest device privileges, escapes the sandbox that keeps apps isolated from each other, and then decrypts the Keychain — iOS’s shared credential vault, the place apps keep passwords, session tokens, and cryptographic keys.

Read that against the fake wallet app playbook, where malware must trick you into entering a seed phrase on its screen. FomoPeek skipped the trick entirely. Your wallet app stores its (encrypted) key material in the Keychain; the malware sits below it, decrypts the vault, and takes what every app deposited. Your exchange app’s session token, your authenticator data, your saved passwords — all of it is in scope, which is exactly what Binance’s advisory stressed. This is the same class of threat as infostealer malware on desktop, moved to mobile and armed with kernel exploits: the target is the device, and every app on it is loot.

The uncomfortable takeaway: on a compromised device, there is no safe wallet. Hardware wallets survive this scenario better than anything else because the private key never exists on the phone in any form — transactions are signed inside the device. A hot wallet on an infected iPhone, no matter how reputable the wallet app is, is standing in the same burning building.

Not an isolated incident

FomoPeek’s framework did not come from nowhere. The iOS-attack-adjacent black market has been industrializing all year:

  • In April 2026, Tencent Cloud security published a teardown of a toolkit it attributed to the “Plasma” gang — at that point the most complex publicly analyzed iOS attack framework, containing 23 vulnerabilities and 5 complete exploit chains covering iOS 13.0 through 17.2.1, a four-year version span (Tencent Cloud analysis)
  • In early September 2026, SlowMist disclosed “DarkSword,” a six-vulnerability chain that attacked iPhone Safari browsers on iOS 18.4–18.6.2 through pages disguised as a free VPS service — no app install required (Binance Square summary)
  • FomoPeek’s framework — eight methods, model-and-version-aware selection — fits this supply chain’s product catalog: prebuilt exploit packs that a criminal buyer wraps in any wrapper app they like

The through-line for crypto users: the delivery vector is now anything you tap. A trading app, a “free server,” a phishing page, a social-engineering pitch on Telegram. The social engineering layer finds you; the exploit layer does the rest. This is functionally a supply-chain attack against the App Store distribution channel itself — the attacker’s code reached victims through Apple’s own update mechanism, which is why “I only install apps from the App Store” stopped being a complete answer sometime this year.

What to do if you installed it

The checklist from SlowMist’s alert, echoed by Binance:

  1. Delete FomoPeek and never reinstall it.
  2. Check every account — exchange logins, email, wallets — for activity you did not authorize.
  3. Create a new wallet on a clean device that never had FomoPeek installed. Not the same phone after a delete; a different device.
  4. Generate fresh keys there and move your assets to the new wallet. Treat every key that ever lived on the exposed phone as compromised.
  5. Update iOS to the latest version — the framework’s listed range stops at 18.7 and 26.1, and older builds were described as higher-risk.
  6. Preserve the device and evidence if you see unauthorized transactions, then contact the platform’s official support. For what happens next, read what to do in the first 24 hours after a theft.

If you used FomoPeek only to watch addresses and never connected anything, do steps 1, 2, and 5 anyway — and understand from the section above why “I never entered my seed phrase” is not an exemption.

How to spot the next one

FomoPeek will not be the last burner-app operation. The pattern is now legible:

  • Developer account with exactly one app, registered shortly before release. WhaleScanv had no history and no other titles.
  • A fresh domain registered days to weeks before launch. fomopeek.com was eleven days older than the app.
  • A trust pitch aimed at your fear of scams — “read-only,” “we never touch your funds,” “no custody.” Legitimate tools say this too, which is exactly why the phrase carries no security signal.
  • Generic changelogs on rapid updates (“Fixed some issues. Optimized UI adaptation”) within days of a clean-looking launch.
  • Cash-for-signup invites through influencer channels. Invite codes bundled with red-packet rewards are paid acquisition. When the product is three weeks old, the reward is the risk.
  • Category mismatch: a “Finance + Utilities” whale tracker asking for nothing is a monitoring app; a monitoring app pushing multiple updates in week one is testing its payload delivery.

None of these alone is proof. Together, in the first two weeks of an app’s life, they are a reason to wait — because in this case the app’s entire storefront existence lasted twelve days. An app that is still alive and unremarkable in month three has at least survived one burn cycle that FomoPeek did not.

And when the next incident lands, the response playbook is now standard: assume device-level compromise, migrate keys to a clean device first, patch second, investigate third. The order matters. Patching stops tomorrow’s attack; it does nothing about the keys that left the building yesterday.

Frequently Asked Questions

Was FomoPeek available in the official App Store?

Yes. Apple's app ID 6806199011 shows FomoPeek was published on App Store storefronts (including China and Japan) by the developer account WhaleScanv on September 7, 2026, and passed review again for version updates as late as September 13. After the September 19 SlowMist and OKX warning, Apple removed it. On September 20 we queried the iTunes lookup API across six storefronts (CN, JP, US, TW, HK, SG) and the app returned zero results everywhere. Third-party IPA sites had also mirrored the version 1.2 binary for sideloading.

I never typed a seed phrase into FomoPeek. Is my wallet still at risk?

Yes. FomoPeek did not need your seed phrase because it did not attack wallets at the app level. According to SlowMist, its kernel exploit framework escapes the iOS sandbox and decrypts the system Keychain — the shared vault where apps store passwords, tokens, and cryptographic keys. That means keys generated or stored by other apps on the same device, including genuine wallet apps, exchange app sessions, and 2FA tokens, were exposed. SlowMist's intercepted traffic showed the attack functions were live and running automatically.

What should I do if I installed FomoPeek at any point?

Follow the checklist issued by SlowMist and repeated in Binance Wallet's advisory: delete the app and never reinstall it; check all accounts for unusual activity; create a brand-new wallet on a device that never had FomoPeek installed; generate new keys there and transfer your assets to it; update iOS to the latest version; and preserve the device and evidence if you see unauthorized transactions. Treat every key that ever lived on the infected phone as compromised, not just at risk.

Is the app called 'fomo' the same thing as FomoPeek?

No. A separate cross-chain trading app branded 'fomo' (family.fomo.app) from a different developer is an unrelated product and should not be confused with FomoPeek, whose developer account was WhaleScanv and whose app ID was 6806199011. Confusion between the two names spread in social chatter after the alert.

Did FomoPeek run a giveaway campaign with KOL promoters?

Yes. Mid-September promo posts show influencers publishing personal invite codes, with followers offered a 5-USDT red packet for registering through them — paid per-install acquisition dressed up as a reward. Many KOLs took the deal without knowing the build was weaponized, and after the September 19 alert their invite codes became records of which audiences were exposed. The pattern matches the fake-giveaway bait used by airdrop scam distribution channels, except here the payload was an App Store app rather than a phishing page. A cash reward for signing up through someone's code is a promotion, not a gift.

Does updating iOS make an infected device safe again?

Updating closes the known holes the framework exploits — affected versions were iOS 12.0 through 18.7 and 26.0 through 26.1 — and lowers risk substantially, since older builds were more exposed. But the malware received remote commands from hidden servers, so the correct response after exposure is migration: new keys on a clean device, assets moved first, OS update second. Patching the OS does not un-leak keys that were already stolen.