Security· ★★★★· bearish·

SlowMist and OKX: App Store app FomoPeek stole crypto wallet keys

  • Malicious modules apptrace and libapptracecore appeared in version 1.1 on September 9 and persisted in 1.2
  • The framework packs eight exploit strategies and claims coverage of iOS 12.0–18.7.2 and 26.0–26.1
  • The C2 server targeted 19 apps, including Gate Web3, SafePal, OKX Wallet, MetaMask, Trust Wallet, imToken, TokenPocket and TronLink
  • The attacker address has received 579,984.34 USDT since September 15, with funds still flowing in
Why it matters: The app shipped through the official App Store, so deleting it or upgrading to 1.3 does not undo the compromise — affected seed phrases should be treated as leaked.
Source: 動區 BlockTempo