
SlowMist and OKX: App Store app FomoPeek stole crypto wallet keys
- —Malicious modules apptrace and libapptracecore appeared in version 1.1 on September 9 and persisted in 1.2
- —The framework packs eight exploit strategies and claims coverage of iOS 12.0–18.7.2 and 26.0–26.1
- —The C2 server targeted 19 apps, including Gate Web3, SafePal, OKX Wallet, MetaMask, Trust Wallet, imToken, TokenPocket and TronLink
- —The attacker address has received 579,984.34 USDT since September 15, with funds still flowing in
Why it matters: The app shipped through the official App Store, so deleting it or upgrading to 1.3 does not undo the compromise — affected seed phrases should be treated as leaked.
Source: 動區 BlockTempo