Security· ★★★· bearish·

SlowMist finds seed-phrase stealer in iOS app FomoPeek

  • —FomoPeek versions 1.1 and 1.2 contained two third-party modules unrelated to the app's features
  • —One module includes DarkSword frameworks for iOS kernel exploits with eight attack methods
  • —If deployed, the app could read Keychain data and files from other apps
  • —iOS 12.0–18.7 and 26.0–26.1 are affected; the malicious code ran automatically
Why it matters: Seed-phrase theft via an official iOS app highlights mobile wallet risks and calls for urgent asset migration.
Source: CoinSpot