A security report published Sept. 20 alleged that FomoPeek, an iOS crypto monitoring application distributed through Apple’s App Store, contained malicious components in versions 1.1 and 1.2 that could attempt device exploitation and collect sensitive data from targeted wallet and note-taking apps.
The report linked the operation to roughly 579,984 USDT in on-chain inflows as of publication. Its findings place the suspected theft campaign inside a seemingly ordinary finance-category app marketed as “FomoPeek – Whale Tracker & Smart Alerts,” rather than a package installed through an unofficial iOS distribution channel.
Users who installed versions 1.1 or 1.2 should regard seed phrases, private keys and credentials stored or entered on the affected phone as potentially exposed, the researchers said. Moving assets requires generating a new wallet on a separate, trusted device; changing an app password or revoking token approvals would not protect funds if a private key or recovery phrase had already been copied.
Malicious modules appeared in two releases
Public App Store information identifies FomoPeek under App Store ID 6806199011. The application was first released on Aug. 29, 2026, under the developer display name WhaleScanv, with Porter Manufacturing, L.L.C. listed as its seller and legal entity. The app was offered free in Apple’s finance category and required iOS 16.0 or later.
According to the Sept. 20 report, version 1.0 did not include the modules named apptrace and libapptracecore. Those components appeared in version 1.1, released Sept. 9, and remained in version 1.2, released Sept. 12.
Version 1.3, published on Sept. 18, removed both modules, the report said. The application package also fell sharply in size, from 10.47MB in the affected versions to 1.81MB in version 1.3, consistent with the removal of substantial embedded code.
Researchers said the app’s main binary and the two suspect modules carried the same Apple developer signing identity. The installation package also retained encrypted metadata associated with App Store distribution. On that basis, the report concluded that the code was included in an officially submitted version of the application rather than added after installation through sideloading.
The alleged components listed compatibility targets spanning iOS 12.0 through iOS 18.7.2, as well as iOS 26.0 through iOS 26.1. Their stated capabilities included remote control functions, attempts to exploit the kernel, sandbox-bypass behavior, Keychain decryption and cross-application data collection.
Servers could select apps and control collection activity
The investigation began after several users reported stolen crypto assets and suspected that private information had been exposed. Some cases involved phones on which the affected FomoPeek builds had been installed, according to the report.
In testing, researchers observed the application collecting device reconnaissance information, including a list of 135 application identifiers. Such a list could tell an operator which wallet, messaging, note-taking or financial apps were present on a device before sending tailored commands back to it.
The report said the app’s remote server could define whether exploitation attempts should run, whether tasks should repeat and how long the software should wait between attempts. Server addresses could also be changed remotely, while the embedded framework included eight exploitation strategies.
One configuration retrieved during isolated testing named 19 wallet and note-taking applications as collection targets. The list included MetaMask, Trust Wallet, imToken, TokenPocket, TronLink and Apple Notes.
Researchers captured an upload package of about 46KB in compressed form. Once unpacked, it reportedly contained an Apple Notes database and associated files. The finding illustrates the practical risk for wallet users who keep recovery phrases or private keys in phone notes: a copied phrase can be used to recreate a wallet elsewhere, without requiring a transaction confirmation from the victim’s original device.
Collected material was first staged in FomoPeek’s own app directory before being transmitted to a remote server, the report said. That approach would make the app a collection point for data drawn from outside its apparent whale-tracking function.
Privacy disclosures raised additional questions
The report also pointed to a discrepancy between FomoPeek’s App Store privacy label and its published privacy policy. Apple’s store listing indicated that the app collected no data, according to the researchers. The privacy policy, by contrast, listed device identifiers, push-notification tokens, email addresses, password hashes and wallet addresses added by users.
A privacy-policy disclosure alone would not establish malicious activity, but the mismatch becomes more consequential alongside the reported device inventory collection and remote tasking capabilities. Users evaluating financial applications often rely on App Store labels as a quick signal of what an app accesses, particularly when a service has no obvious need to interact with wallet secrets or personal notes.
On-chain flows concentrated on ethereum
The report’s blockchain tracing identified a primary address active from Sept. 15 that had received cumulative inflows of 579,984.34 USDT at the time of publication. The movement spanned ethereum, BNB Chain and Arbitrum, with the largest aggregation activity occurring on ethereum.
One downstream address received 159,000 USDT before sending funds to FixedFloat, the report said. Another address handled 47,028 USDT that was routed to KuCoin and FixedFloat. These transfers do not independently prove the origin of every deposit, but they provide an on-chain trail associated by the researchers with the suspected campaign.
Users who installed the affected builds should preserve practical evidence before resetting a device, including the app version, installation time, relevant transaction hashes and screenshots. The report also advised reviewing email and other account login histories, changing passwords from a known-safe device and enabling two-factor authentication.
An operating-system update may remove a vulnerable app or close a software flaw, but it cannot invalidate a wallet key that has already been exported. For users with potentially exposed recovery phrases, the urgent task is to move assets to a new wallet controlled by a newly generated seed phrase on a clean device.
For practical steps to protect your wallets after incidents like FomoPeek, read this security guide next.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
