← FomoPeek1 decision on this page
Audit log
Every state-changing event for FomoPeek: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-09-23 12:09:27ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 449,699,146
- sig
5ipSnBuY11iq…CUt7geUSexplorer ↗- hash
9TT6LEkiFL5u…AeBmnmZvsha256 → base58
verifying row…full verify ↗canonical bytes (13378 B) ▸
{"actor":"system:backfill","investigation_id":"1bcea4b0-2bac-4ad5-9a78-34d75126ee07","kind":"publish","page_slug":"fomopeek","published_at":"2026-09-23T12:09:27.391Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"FomoPeek","sections":[{"content":"FomoPeek presented itself as a read-only on-chain whale-tracking tool for Ethereum, Solana, and TRON networks, alerting users when large wallets moved funds. According to security reporting by SecurityOnline and Cointelegraph, distribution relied on a referral-code system: prospective users required an invitation code to download and register the app, and were offered 5–7 USDT upon completing registration and running the app on a physical device for several minutes. Key opinion leaders (KOLs) in crypto communities on Telegram and Discord were paid higher commissions to distribute referral codes, according to SecurityOnline's analysis. The app passed Apple's App Review process without detection of its malicious payload.","heading":"Background and Marketing","severity":"high","sources":[{"credibility":2,"name":"FomoPeek App Hides an iOS Kernel Exploit to Steal Crypto — SecurityOnline","type":"news_article","url":"https://securityonline.info/fomopeek-ios-crypto-theft/"},{"credibility":2,"name":"Malicious iOS App FomoPeek Linked to $580K Crypto Theft — Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/fomopeek-ios-app-580k-crypto-theft"}]},{"content":"Security firms SlowMist and OKX identified two malicious modules embedded in FomoPeek versions 1.1 and 1.2. The first was a command-and-control communicator that connected to external infrastructure unrelated to the app's public services, operating automatically at regular intervals and capable of receiving remote instructions. The second was an iOS kernel exploitation framework containing eight distinct attack methods. According to SlowMist's published analysis, the framework automatically selected its exploitation technique based on device model and iOS version, covering iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1. Upon successful exploitation, the framework escaped the iOS application sandbox, decrypted Keychain contents, and exfiltrated data from 19 other installed applications including MetaMask, Trust Wallet, SafePal, OKX Wallet, and Apple Notes. SecurityOnline's reporting noted the framework likely relied on the 'DarkSword series of exploit frameworks,' referencing vulnerabilities Google disclosed in March 2026 that Apple had subsequently patched — meaning devices running current iOS versions were reported to be unaffected by this specific exploit chain. Stolen data including private keys, seed phrases, login credentials, chat records, and files was uploaded to attacker-controlled servers.","heading":"Malicious Payload: iOS Kernel Exploit Framework","severity":"critical","sources":[{"credibility":2,"name":"Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/threat-intelligence-analysis-of-fomopeek-app-store-poisoning-and-ios-kernel-exploitation-e568762d11ca"},{"credibility":2,"name":"SlowMist Warns FomoPeek iOS Versions May Expose Crypto Wallet Keys — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/19/slowmist-warns-fomopeek-ios-versions-may-expose-crypto-wallet-keys/"},{"credibility":2,"name":"FomoPeek App Hides an iOS Kernel Exploit to Steal Crypto — SecurityOnline","type":"news_article","url":"https://securityonline.info/fomopeek-ios-crypto-theft/"}]},{"content":"SlowMist and OKX security teams traced approximately $579,984 in stolen USDT to a single attacker-controlled address: 0x6d37f2C5e8F8546b648D317295565dA95975f4BB, which became active on September 15, 2026. According to Cointelegraph and CryptoSlate reporting, fund movement from that address included approximately $401,028 USDT routed through three intermediary addresses to FixedFloat, $20,000 USDT sent to a KuCoin hot wallet, $111,458 USDT directed to an escrow platform address, and $10,000 USDT sent to the CCE mixing service. The $580,000 figure is an approximation based on on-chain tracing by SlowMist and OKX; no court judgment or regulatory finding has been issued as of the date of this investigation. No individual or organization has been formally charged in connection with this attacker address.","heading":"Financial Impact and On-Chain Attribution","severity":"critical","sources":[{"credibility":2,"name":"Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT — CryptoSlate","type":"on_chain","url":"https://cryptoslate.com/rogue-iphone-app-escapes-ios-sandbox-to-hijack-580000-in-usdt/"},{"credibility":2,"name":"Malicious iOS App FomoPeek Linked to $580K Crypto Theft — Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/fomopeek-ios-app-580k-crypto-theft"},{"credibility":2,"name":"Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/threat-intelligence-analysis-of-fomopeek-app-store-poisoning-and-ios-kernel-exploitation-e568762d11ca"}]},{"content":"Version 1.0 of FomoPeek contained no malicious code. Version 1.1 (build 105), released September 9, 2026, introduced both malicious modules. Version 1.2 (build 110), released September 12, 2026, retained both modules. Version 1.3 (build 111), released September 17, 2026, removed both malicious frameworks. SlowMist and OKX published their joint findings on September 19, 2026. According to search-aggregated reporting, Apple subsequently removed the application from the App Store, though Apple did not respond to Cointelegraph's request for comment before that outlet's publication. The developer's identity has not been publicly confirmed in available sources. SlowMist noted that if an attacker had already successfully exploited a device and copied sensitive data, enabling Lockdown Mode or uninstalling the app would not recover that data.","heading":"Affected Versions and Timeline of Removal","severity":"high","sources":[{"credibility":2,"name":"Binance warns iPhone users of FomoPeek malware targeting crypto wallets — crypto.news","type":"news_article","url":"https://crypto.news/binance-warns-iphone-users-of-fomopeek-malware-targeting-crypto-wallets/"},{"credibility":2,"name":"Malicious iOS App FomoPeek Linked to $580K Crypto Theft — Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/fomopeek-ios-app-580k-crypto-theft"}]},{"content":"Binance issued a public warning advising iPhone and iPad users to remove FomoPeek, avoid reinstalling it, and update iOS to the latest available version. Binance further recommended that self-custody wallet holders create entirely new wallets on a separate, clean device that had never had FomoPeek installed, and transfer all assets to newly generated addresses. SlowMist's analysis stated that the underlying iOS vulnerabilities exploited by FomoPeek had been patched by Apple, and that users running the latest iOS version were not at risk from this specific exploit chain. The incident was widely covered by CryptoSlate, Cointelegraph, CryptoTimes, and SecurityOnline, and flagged by Binance as a novel App Store supply-chain vector for iOS wallet theft.","heading":"Industry Response and User Advisories","severity":"high","sources":[{"credibility":2,"name":"Binance warns iPhone users of FomoPeek malware targeting crypto wallets — crypto.news","type":"news_article","url":"https://crypto.news/binance-warns-iphone-users-of-fomopeek-malware-targeting-crypto-wallets/"},{"credibility":2,"name":"SlowMist Warns FomoPeek iOS Versions May Expose Crypto Wallet Keys — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/19/slowmist-warns-fomopeek-ios-versions-may-expose-crypto-wallet-keys/"},{"credibility":2,"name":"Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/rogue-iphone-app-escapes-ios-sandbox-to-hijack-580000-in-usdt/"}]},{"content":"No available public source has identified or named the developer or developers behind FomoPeek. No formal charges, indictments, or regulatory actions had been reported as of September 23, 2026. The attacker-controlled address (0x6d37f2C5e8F8546b648D317295565dA95975f4BB) identified by SlowMist and OKX represents the extent of on-chain attribution available in published reporting. The developer's App Store account identity and any corporate structure behind the application remain publicly unknown.","heading":"Developer Identity and Attribution","severity":"medium","sources":[{"credibility":2,"name":"Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/threat-intelligence-analysis-of-fomopeek-app-store-poisoning-and-ios-kernel-exploitation-e568762d11ca"}]}],"sources_used":[{"credibility":2,"name":"Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation — SlowMist on Medium","type":"research","url":"https://slowmist.medium.com/threat-intelligence-analysis-of-fomopeek-app-store-poisoning-and-ios-kernel-exploitation-e568762d11ca"},{"credibility":2,"name":"Malicious iOS App FomoPeek Linked to $580K Crypto Theft — Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/fomopeek-ios-app-580k-crypto-theft"},{"credibility":2,"name":"SlowMist Warns FomoPeek iOS Versions May Expose Crypto Wallet Keys — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/19/slowmist-warns-fomopeek-ios-versions-may-expose-crypto-wallet-keys/"},{"credibility":2,"name":"Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/rogue-iphone-app-escapes-ios-sandbox-to-hijack-580000-in-usdt/"},{"credibility":2,"name":"Binance warns iPhone users of FomoPeek malware targeting crypto wallets — crypto.news","type":"news_article","url":"https://crypto.news/binance-warns-iphone-users-of-fomopeek-malware-targeting-crypto-wallets/"},{"credibility":2,"name":"FomoPeek App Hides an iOS Kernel Exploit to Steal Crypto — SecurityOnline","type":"news_article","url":"https://securityonline.info/fomopeek-ios-crypto-theft/"},{"credibility":2,"name":"SlowMist: FomoPeek iOS Malware Tied to $580K Crypto Theft — CryptoBreaking","type":"news_article","url":"https://www.cryptobreaking.com/slowmist-fomopeek-ios-malware-tied/"}],"summary":"FomoPeek was an iOS App Store application marketed as a read-only cryptocurrency whale-wallet monitor. Versions 1.1 and 1.2, distributed September 9–12, 2026, were found by SlowMist and OKX security researchers to contain a hidden iOS kernel-exploit framework capable of sandbox escape, Keychain decryption, and data extraction from 19 other installed apps. Approximately $579,984 in USDT was traced to a single attacker-controlled address before the developer released a clean version 1.3 on September 17, 2026.","timeline":[{"date":"2026-09-09","event":"FomoPeek version 1.1 (build 105) released on Apple App Store, introducing two malicious modules including an iOS kernel exploit framework.","source":"Binance warning via crypto.news; Cointelegraph","source_url":"https://crypto.news/binance-warns-iphone-users-of-fomopeek-malware-targeting-crypto-wallets/"},{"date":"2026-09-12","event":"FomoPeek version 1.2 (build 110) released, retaining both malicious modules.","source":"Binance warning via crypto.news","source_url":"https://crypto.news/binance-warns-iphone-users-of-fomopeek-malware-targeting-crypto-wallets/"},{"date":"2026-09-15","event":"Attacker-controlled address 0x6d37f2C5e8F8546b648D317295565dA95975f4BB became active, according to SlowMist and OKX on-chain tracing.","source":"Cointelegraph","source_url":"https://cointelegraph.com/news/fomopeek-ios-app-580k-crypto-theft"},{"date":"2026-09-17","event":"FomoPeek version 1.3 (build 111) released, removing both malicious frameworks. Malicious code was active for approximately eight days.","source":"Cointelegraph; Binance warning via crypto.news","source_url":"https://cointelegraph.com/news/fomopeek-ios-app-580k-crypto-theft"},{"date":"2026-09-19","event":"SlowMist and OKX security teams published joint findings identifying the malicious modules, tracing approximately $579,984 USDT to the attacker address, and issuing user advisories.","source":"CryptoTimes; SlowMist on Medium","source_url":"https://www.cryptotimes.io/2026/09/19/slowmist-warns-fomopeek-ios-versions-may-expose-crypto-wallet-keys/"},{"date":"2026-09-19","event":"Binance issued a public advisory warning iPhone and iPad users to delete FomoPeek, update iOS, and migrate wallets to clean devices.","source":"crypto.news","source_url":"https://crypto.news/binance-warns-iphone-users-of-fomopeek-malware-targeting-crypto-wallets/"},{"date":"2026-09-22","event":"Apple removed FomoPeek from the App Store following emergency threat disclosure. Apple had not responded to press requests for comment as of Cointelegraph's publication.","source":"Cointelegraph; search-aggregated reporting","source_url":"https://cointelegraph.com/news/fomopeek-ios-app-580k-crypto-theft"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 19f0c723-deeb-48fd-bc2c-d2b6e8bd15eb
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.