Investigation Unveils Security Breach
A recent investigation by SlowMist, a blockchain security firm, has unveiled a significant security breach connected to the FomoPeek app, which was made available through Apple’s App Store. This malicious application has been implicated in the theft of cryptocurrency totaling approximately $580,000.
Exploitation of iOS Vulnerabilities
Researchers discovered that FomoPeek utilized multiple kernel exploits, allowing it to bypass the protective sandbox environment of iOS and access sensitive information from other applications, including cryptocurrency wallets. The compromised versions of the app were released on September 9 and 12, with later versions, specifically version 1.3 released on September 17, removing these harmful features.
Investigation Findings
The investigation, conducted alongside the OKX security team, was prompted by user reports detailing unauthorized access and theft of their assets. It was revealed that many victims had previously installed the compromised versions of FomoPeek. The app leveraged an extensive exploit framework that employed eight distinct attack vectors, supporting a host of iOS versions from 12.0 up to 18.7.2, as well as newer versions 26.0 and 26.1.
Tracing the Stolen Cryptocurrency
Further analysis by SlowMist pinpointed a primary hacking address responsible for the theft, which received nearly 579,984 USDT. This address became active on September 15, and subsequent tracing revealed that the stolen cryptocurrency traversed multiple blockchain networks, being consolidated and distributed across various addresses and services. Transfers from this address pointed to platforms like FixedFloat, KuCoin, and cce.cash, among others.
Ongoing Concerns and Future Implications
As the research into this alarming case continues, Cointelegraph has sought comments from Apple, SlowMist, and OKX but has yet to receive a reply ahead of publication. This incident highlights ongoing vulnerabilities within app ecosystems and the potential risks that come with third-party applications.
In the broader scope, this event raises critical questions regarding app security in the rapidly evolving landscape of cryptocurrency management, and further emphasizes the importance of vigilance among users.