FomoPeek Slips Past Apple's Sandbox, Drains $580K From Crypto Users
SlowMist says malicious versions of an iOS app called FomoPeek made it into Apple's App Store and used kernel exploits to break out of the sandbox. The campaign is tied to $580,000 in stolen crypto, and it didn't require a jailbreak or a sideload.
$580,000 gone. That's the tally SlowMist is attaching to FomoPeek, a malicious iOS app that got into Apple's App Store and used kernel exploits to climb out of the sandbox.
The sandbox is the whole security model on iOS. Apps live in their own box. They can't read each other's files, can't scan your messages, can't touch another app's keychain. FomoPeek broke that wall. Once an app escapes, it reaches into whatever else sits on the device. For crypto holders, that means wallet data, seed phrases, clipboard contents, session tokens. Anything left in reach.
Here's what matters: this didn't need a jailbreak. No sideloaded profile. No sketchy TestFlight link. Users installed it the normal way, from the store everyone treats as the safe option. That's what makes it sting.
SlowMist points to kernel level exploits, which is a different class of problem than the usual app that just asks for too many permissions. Kernel access means the app isn't asking. It's taking. And App Store review isn't built to catch a working exploit buried inside a functioning app. Reviewers watch behavior. They don't fuzz memory corruption primitives.
The dollar figure is small next to exchange breaches, but the target profile isn't. This is retail. People with a few thousand bucks in a hot wallet, a seed phrase in Notes, and a habit of copying addresses to the clipboard. They didn't do anything careless. They still got cleaned out.
From a risk perspective, the exposure isn't FomoPeek itself. It's the signal. If a kernel exploit can ride through iOS review undetected, the trust premium Apple charges developers and users just took a hit. Hardware wallet makers win from that. Cold storage is the one thing an escaped app on your phone still can't reach.
Watch how fast Apple patches the underlying flaw. That timeline will say more about the next six months than anything else coming out of this.