
FomoPeek Crypto Monitoring App Allegedly Exposed Users to Wallet Data
An iPhone application marketed as a read-only cryptocurrency monitoring tool contained code capable of accessing other apps and sensitive wallet information, according to a new analysis. A cryptocurrency wallet linked to the suspected attacker reportedly received nearly $580,000 in digital assets.
App Presented as Wallet Monitoring Tool
The application, identified as FomoPeek, was promoted as a tool for tracking cryptocurrency wallets without requiring users to make transactions. However, an analysis of the app’s code found capabilities that allegedly extended beyond passive monitoring.
Researchers said the application could access data from other apps and obtain sensitive information associated with cryptocurrency wallets. Such access could expose users to the theft of private wallet data and digital assets.
Malicious Code Reached Apple’s App Store
The discovery has raised questions about how the application passed Apple’s App Store review process while allegedly carrying code with the ability to access sensitive information. Apps distributed through official marketplaces are generally subject to security and privacy checks, although those controls do not guarantee that every malicious application will be detected before release.
Users who installed FomoPeek to monitor cryptocurrency activity may have unknowingly granted the application access to information stored on their devices, according to the analysis.
Nearly $580,000 Sent to Suspected Attacker Wallet
A wallet identified by researchers as being controlled by the suspected attacker reportedly received nearly $580,000 in cryptocurrency. The transfers indicate that the application’s alleged data-access capabilities may have been used in a broader asset-theft operation.
The incident highlights the risks associated with installing cryptocurrency applications that request access to device data or other applications. Users should verify an app’s developer, review permission requests carefully and avoid entering private keys or recovery phrases into third-party software.