BTCBTC$85,355-0.92%|
ETHETH$2,714.99-1.67%|
USDTUSDT$0.99973+0.00%|
BNBBNB$777.8500-1.69%|
XRPXRP$1.5600+0.99%|
USDCUSDC$0.99980+0.00%|
SOLSOL$116.5900-0.89%|
TRXTRX$0.34155-1.17%|
ZECZEC$1,626.08+6.90%|
FIGR_HELOCFIGR_HELOC$1.0310+1.66%|
HYPEHYPE$94.6400-1.24%|
DOGEDOGE$0.09892-1.37%|
XMRXMR$562.6600-3.30%|
WBTWBT$85.7400-1.17%|
USDSUSDS$0.99989-0.00%|
LINKLINK$12.6500-3.52%|
ADAADA$0.24843-1.31%|
RAINRAIN$0.01272-5.93%|
LEOLEO$8.9800-0.07%|
XLMXLM$0.21215-0.70%|
BCHBCH$355.0700+12.00%|
NEARNEAR$4.6800+2.18%|
UNIUNI$9.6000+0.36%|
USDEUSDE$0.99970+0.01%|
LTCLTC$61.8400+0.19%|
AVAXAVAX$10.6600-2.55%|
DAIDAI$0.99994+0.01%|
CCCC$0.11215-5.24%|
USD1USD1$0.99918+0.00%|
HBARHBAR$0.09422-1.24%|
BTCBTC$85,355-0.92%|
ETHETH$2,714.99-1.67%|
USDTUSDT$0.99973+0.00%|
BNBBNB$777.8500-1.69%|
XRPXRP$1.5600+0.99%|
USDCUSDC$0.99980+0.00%|
SOLSOL$116.5900-0.89%|
TRXTRX$0.34155-1.17%|
ZECZEC$1,626.08+6.90%|
FIGR_HELOCFIGR_HELOC$1.0310+1.66%|
HYPEHYPE$94.6400-1.24%|
DOGEDOGE$0.09892-1.37%|
XMRXMR$562.6600-3.30%|
WBTWBT$85.7400-1.17%|
USDSUSDS$0.99989-0.00%|
LINKLINK$12.6500-3.52%|
ADAADA$0.24843-1.31%|
RAINRAIN$0.01272-5.93%|
LEOLEO$8.9800-0.07%|
XLMXLM$0.21215-0.70%|
BCHBCH$355.0700+12.00%|
NEARNEAR$4.6800+2.18%|
UNIUNI$9.6000+0.36%|
USDEUSDE$0.99970+0.01%|
LTCLTC$61.8400+0.19%|
AVAXAVAX$10.6600-2.55%|
DAIDAI$0.99994+0.01%|
CCCC$0.11215-5.24%|
USD1USD1$0.99918+0.00%|
HBARHBAR$0.09422-1.24%|
News/Security
Security

Binance Warns iPhone Users After FomoPeek Malware Targets Crypto Wallets

Binance Warns iPhone Users After FomoPeek Malware Targets Crypto Wallets — Security crypto news

Summary:

  • Binance warned iPhone and iPad users about malicious code discovered in FomoPeek versions 1.1 and 1.2.

  • Researchers said the malware could exploit iOS vulnerabilities, escape the sandbox and potentially access private keys, seed phrases and data from other apps.

  • The malicious frameworks appeared in FomoPeek 1.1 and 1.2 and were removed from version 1.3.

  • Affected self-custody users were advised to create a fresh wallet on a separate clean device and transfer their assets.

  • The incident is notable because the affected versions were distributed through Apple's official App Store.

  • Similar mobile threats including SparkCat, SparkKitty and Coruna show growing attempts to steal crypto credentials directly from phones.

Binance has issued a security warning to iPhone and iPad users after researchers discovered malicious code inside certain versions of FomoPeek, an app that had been distributed through Apple's official App Store.

The alert focuses on FomoPeek versions 1.1 and 1.2, which security researchers said contained components capable of exploiting iOS vulnerabilities, escaping normal application restrictions and reaching sensitive information stored elsewhere on an affected device.

That could include crypto wallet private keys and recovery phrases, but the risk was not limited to wallets. Login credentials, chat history, locally stored files and information belonging to other applications could potentially become accessible after a successful compromise.

The distinction matters. This was not simply another fake wallet asking users to type their seed phrase into a fraudulent interface. Researchers described a threat aimed at compromising the device itself.

For anyone who installed one of the affected FomoPeek versions, Binance's security advisory recommends removing the app, updating iOS and, for self-custody users, moving funds to a newly created wallet generated on a separate trusted device.

What happened with FomoPeek?

The warning followed reports of stolen crypto assets investigated by blockchain security firm SlowMist together with the OKX security team.

Researchers examining FomoPeek found two components that they said were unrelated to the app's advertised functionality.

One of those components contained an iOS kernel exploitation framework with eight different attack methods. Rather than relying on one vulnerability for every target, the framework could choose an exploit according to the device model and version of iOS it detected.

SlowMist's analysis described exploit coverage spanning iOS 12.0 through 18.7-series systems and iOS 26.0 through 26.1, with older software generally considered more exposed.

Binance later simplified the warning for users, asking anyone who had used FomoPeek on an iPhone or iPad running iOS 26.x or earlier to check whether they could have been affected.

These descriptions should not be read as meaning that every device in those software ranges was successfully compromised. They describe the versions that the exploit framework was designed to target. An actual compromise would still depend on factors including the exact device, system version and whether exploitation succeeded.

How the FomoPeek malware worked

The mechanics are important because they change the usual assumption that an app remains isolated inside its own iOS sandbox.

Normally, iOS applications operate inside restricted environments designed to prevent one app from freely reading another app's data.

According to the security investigation, FomoPeek's malicious components attempted to break through those restrictions by exploiting vulnerabilities at a deeper system level.

If exploitation succeeded, the malicious code could escape the iOS sandbox, access and decrypt Keychain information and read files belonging to other applications.

That potentially exposed private keys, wallet recovery phrases, usernames, passwords, conversations and locally stored files.

Researchers also found that the suspicious code communicated with infrastructure that was separate from FomoPeek's normal public services. That infrastructure could reportedly issue remote instructions and influence when the exploit functionality executed.

Captured network activity indicated that the malicious functionality could run automatically at repeated intervals instead of requiring the victim to manually trigger it each time.

This is what makes the incident substantially more serious than ordinary credential phishing.

The malicious code appeared in specific FomoPeek versions

The version timeline provides an important way to understand who may have been exposed.

Security analysis of historical FomoPeek packages obtained through the official App Store found no evidence of the two malicious frameworks in version 1.0.

Version 1.1, build 105, introduced them on September 9.

Version 1.2, build 110, was released on September 12 and continued to contain the suspicious code.

Version 1.3, build 111, released on September 17, removed both frameworks from the application.

That means versions 1.1 and 1.2 are the versions explicitly identified in the investigation.

However, upgrading from an affected version does not retroactively protect secrets that may already have been exposed while the malicious code was present.

If a private key or recovery phrase was copied from a device during a previous compromise, deleting the app later cannot make that information secret again.

That is why the response recommended by security teams goes further than simply uninstalling FomoPeek.

Why users are being told to create an entirely new wallet

For users holding crypto in self-custody wallets, Binance and security researchers recommended creating a new wallet on a separate trusted device where FomoPeek had never been installed.

Assets from a potentially exposed wallet should then be transferred to addresses generated by that new wallet.

There is an important reason for using another device.

If the original device was successfully compromised at a system level, generating another wallet or another recovery phrase on that same device could expose the new credentials to the same environment.

Likewise, changing an exchange password does not solve the problem if the private key controlling an on-chain wallet has already been copied.

A recovery phrase is effectively the master credential for many self-custody wallets. Anyone who obtains it can usually recreate the wallet elsewhere without needing the original phone.

For that reason, users should treat a potentially exposed seed phrase as permanently compromised rather than simply changing an app password and continuing to use the same wallet.

The same principle explains the hard separation hardware wallet makers draw when they design around mobile exposure.

What affected FomoPeek users should do now

Anyone who installed FomoPeek versions 1.1 or 1.2 should first remove the application and avoid reinstalling it.

The device should then be updated to the latest compatible version of iOS.

Apple released iOS 27 and iOS 26.7 on September 14, several days before the FomoPeek alert became widely public. Keeping a device on a current security release reduces exposure to known vulnerabilities that older exploit frameworks may depend on.

Self-custody users should create a fresh wallet on a different trusted device and transfer assets from wallets whose private keys or recovery phrases may have been accessible on the affected phone.

Users should also review recent wallet transactions and exchange account activity for withdrawals, transfers or login events they do not recognize.

If suspicious asset movements are found, preserving the affected device and other evidence may help security teams or an exchange investigate what happened.

Users should avoid wiping or resetting a device before preserving evidence if they already know that funds were stolen and expect to seek technical assistance.

The App Store distribution makes the case unusual

One of the most concerning details is how the affected versions were distributed.

Researchers said versions 1.1 and 1.2 came through Apple's official App Store rather than through a third-party download, modified installation package or sideloaded copy.

That does not mean every App Store application is unsafe. Apple's review, signing and sandboxing systems still remove many categories of risk compared with installing random software from unknown websites.

But the FomoPeek incident illustrates that official distribution alone cannot serve as the only security check when significant crypto assets are involved.

Users can follow the standard advice to download software only from a trusted app store and still encounter an application that later proves malicious.

It is the same broader lesson seen in fake-security-tool campaigns Bitnxt has covered: trusted-looking delivery is increasingly part of the attack rather than proof that an application is harmless.

FomoPeek is different from a normal fake wallet app

Crypto users have become familiar with wallet impersonation scams.

A fake application copies the name and branding of a legitimate wallet and then asks the victim to enter a recovery phrase. The attacker does not necessarily need a sophisticated device exploit because the user voluntarily provides the secret.

FomoPeek represents a different category of risk.

According to the investigation, successful exploitation could allow the malware to reach information belonging to other applications after escaping the normal sandbox.

That reduces the amount of cooperation required from the victim.

A user does not necessarily have to type a recovery phrase into a fake form if malware can locate sensitive information directly on the phone.

Unlike phishing-class attacks that rely on the victim's cooperation, this generation of mobile threats increasingly focuses on harvesting information directly from the device.

Crypto malware has already been moving in this direction

FomoPeek did not appear in isolation.

Kaspersky previously documented the SparkCat malware campaign, which placed malicious applications in official app stores and used optical character recognition to search images for cryptocurrency wallet recovery phrases.

Instead of exploiting the operating system to read another app's Keychain information, SparkCat targeted a common user habit: storing screenshots of seed phrases and other sensitive information in the phone's photo gallery.

Kaspersky later uncovered SparkKitty, another mobile stealer affecting iOS and Android devices. It was designed to collect images from infected phones and send them to infrastructure controlled by attackers.

The two campaigns demonstrated why saving a seed phrase as a screenshot can turn a normal photo permission into a crypto security problem.

FomoPeek takes the risk a step further because researchers described an exploit framework designed to break outside normal application boundaries.

Google's Coruna research shows how powerful iPhone exploits can spread

Research published by Google's Threat Intelligence Group earlier in 2026 provides another useful comparison.

Google analyzed an iPhone exploit framework called Coruna containing five complete exploit chains and 23 individual exploits.

It targeted versions from iOS 13 through iOS 17.2.1 and was observed moving between different groups over time.

Researchers found financially motivated campaigns using the toolkit on fake financial and crypto-related websites.

Its payload was capable of searching compromised phones for financial information and cryptocurrency wallet material, including text associated with BIP39 recovery phrases.

The significance is broader than any one malware family.

Advanced mobile exploits do not necessarily remain exclusively in the hands of the group that developed them. Exploit techniques can spread, be resold, reused or incorporated into new criminal operations.

For crypto holders, that makes timely operating-system updates part of wallet security rather than simply routine phone maintenance.

Why seed phrases should never be stored on a phone

The FomoPeek case also reinforces an old self-custody rule that is becoming more important as malware improves.

A wallet recovery phrase should not be stored in screenshots, cloud photo backups, messaging apps, notes applications or ordinary text files on a daily-use phone.

The seed phrase is not a password that can simply be reset.

It is the cryptographic backup from which wallet keys can be recreated.

Once another person obtains it, the original owner cannot reliably take that knowledge back.

The safest response is normally to create a completely new wallet with a new recovery phrase and move funds before an attacker can do the same.

For users protecting significant amounts of crypto, isolating signing keys from general-purpose phones and computers can substantially reduce the number of ways ordinary malware can reach them.

App-store trust should be one layer, not the entire security model

The FomoPeek incident does not mean crypto users should start installing apps from random websites instead of official stores.

Official stores remain an important security layer.

The lesson is that they should not be the only layer.

Users should still verify the publisher, examine what permissions an application requests, keep operating systems patched and avoid storing wallet recovery material on internet-connected devices.

Applications that appear unrelated to wallet management should also be treated carefully if they request unusually broad access to photos, files or other sensitive device resources.

For users with substantial self-custody holdings, a separate hardware wallet or isolated signing device can limit the damage if a phone used for browsing, social media or everyday applications becomes compromised.

FomoPeek shows why that separation matters.

A crypto holder does not have to install a fake wallet for wallet security to fail. If attackers can compromise the device underneath the wallet, every application running on that device can become part of the threat model.

#FomoPeekMalware#BinanceWallet#iPhoneSecurity#CryptoWalletSecurity#iOSMalware#SlowMist#CryptoSecurity#SeedPhrase#PrivateKeys#AppleAppStore
Aaron Bailey

Author

Aaron Bailey

Blockchain Tech Analyst

Aaron Bailey has covered blockchain technology and decentralized systems for 2 years, focusing on protocol upgrades, Layer 2 developments, and emerging DeFi infrastructure. He breaks down complex technical shifts into clear, actionable insights for Bitnxt readers.

Share: