S&P 5007,764.70▲1.5% Nasdaq27,122.09▲2.3% Dow52,048.83▲0.7% Russell 2K2,875.36▲0.5% 10-Yr4.96%−3bp VIX14.31−0.56 WTI$90.73▼4.1% Gold$4,348.00▼0.7% EUR/USD1.141▼0.4% BTC$85,554▼0.7% Nikkei65,019▲1.4%
At close · Wed, Sep 23, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureMalicious iPhone app linked to nearly $580,000 in stol…

Malicious iPhone app linked to nearly $580,000 in stolen USDT

Security firm SlowMist said the app’s later versions added iOS sandbox escape code that could reach other apps’ Keychain items, private keys, and seed phrases.

Fomopeek, a malicious iPhone app distributed through Apple’s App Store, has been linked to nearly $580,000 in stolen USDT, according to an investigation by blockchain security firm SlowMist. SlowMist began looking into reports that assets were being stolen after private keys were exposed.

SlowMist said the app had been marketed as a read-only tool for tracking large cryptocurrency transactions across Ethereum, Solana and Tron. But researchers working with security teams at crypto exchange OKX found two hidden modules embedded in versions 1.1 and 1.2 that were not tied to the app’s advertised monitoring functions, including one component that communicated with command-and-control infrastructure and another that included a kernel exploitation framework with eight attack methods.

The firm said a successful exploit could escape Apple’s application sandbox and access data from other apps on the device, creating a path to locally stored private keys, seed phrases, and login credentials without requiring users to connect a wallet or manually enter sensitive details into Fomopeek. SlowMist also said the risk extended to passwords stored in Apple’s Keychain and encrypted files held by other applications, with attackers potentially unlocking wallet credentials and other data if they obtained both.

SlowMist found the malicious components were introduced in version 1.1, released Sept. 9, and version 1.2 on Sept. 12, and then removed in version 1.3 on Sept. 17. The technical findings were followed by an on-chain trail showing the attackers had already converted the access into losses, with Salus identifying activity tied to address 0x6d37f2.

Latest closeEthereum $2,725.65 ▼1.0%|Solana $117.06 ▼1.2%

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.