Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT

1 hour ago 2



Fomopeek, a malicious iPhone app distributed through Apple’s App Store, has been linked to nearly $580,000 in stolen USDT.Blockchain security firm SlowMist began investigating the app over the weekend after receiving reports of stolen assets linked to exposed private keys.Some victims had previously installed versions 1.1 or 1.2 of the Fomopeek app, which was marketed as a read-only tool for tracking large cryptocurrency transactions across Ethereum, Solana and Tron.What is Fomopeek?Working with security researchers at crypto exchange OKX, SlowMist found two modules embedded in those versions that had no connection to FomoPeek’s advertised monitoring functions.One communicated with external command-and-control infrastructure, while the other contained a kernel exploitation framework with eight attack methods that could adjust to the victim’s iPhone model and operating-system version.A successful exploit could escape Apple’s application sandbox and reach Keychain information and files belonging to other apps. That created a route to locally stored private keys, seed phrases, and login credentials without requiring users to connect a wallet or enter those details into FomoPeek.SlowMi...

Read Entire Article