FomoPeek 应用被曝植入恶意代码,导致用户加密货币钱包凭证泄露
一款名为 FomoPeek 的 iPhone 应用程序,其宣传功能为追踪 Solana、Ethereum 和 TRON 网络上的“巨鲸”钱包动态,但实际上却包含了能够突破 iOS 安全限制并从受影响设备中提取加密货币钱包凭证的恶意代码。
SlowMist(慢雾)在与 OKX 安全团队合作调查多起加密货币被盗案件后,于 9 月 19 日发布了资产盗窃警告。受影响的用户在资产被盗前曾安装或使用过 FomoPeek 的 1.1 或 1.2 版本。
此次披露正值本周末发生数起无关的加密安全事件之际。此前,Blink 因攻击者清空托管账户而暂时暂停了服务;Fetch.ai 和 NuNet 则遭受了一起独立的价值 200 万美元的攻击漏洞利用事件。
恶意软件包含八种 iOS 攻击方法
研究人员在 FomoPeek 内部发现了两个与其宣传的钱包追踪功能无关的恶意模块。其中一个模块包含一个 iOS 内核利用框架,具备八种攻击方法,能够适应不同的设备型号和操作系统版本。
The impact areas determined by the researchers cover iOS 12.0 to 18.7 and iOS 26.0 to 26.1. Once successfully executed, malicious code can break through normal sandbox limits, access and decrypt Keychain information, and read data belonging to other applications. Information that may be exposed includes private keys, mnemonics, login credentials, chat logs, and other files stored on the device.
SlowMist also detected a connection to a server outside of FomoPeek's normal infrastructure. Captured network traffic indicates that the malicious feature is active and configured to execute automatically at fixed intervals rather than exist as dormant code.
Leaked wallet credentials must be replaced
Binance Wallet warns affected users to remove FomoPeek, update their devices to the latest available iOS version, and avoid reinstalling the app.
For users who have stored or accessed cryptocurrency wallets on affected devices, it is recommended to generate new wallet credentials on a clean device that has never run FomoPeek, and then transfer the remaining funds to the new address. Simply deleting an application will not protect extracted private keys or mnemonics. Anyone holding these credentials can rebuild their wallet and authorize transactions elsewhere without having to regain access to the damaged iPhone.
In addition, users who discover unauthorized transactions are also advised to retain affected equipment and transaction records for investigation rather than immediately clearing the evidence.
SlowMist has not disclosed the total amount of money stolen through FomoPeek or the total number of infected devices. Its September 19 investigation linked versions 1.1 and 1.2 to reported asset theft and confirmed that these versions contained features that could break through the application's normal sandbox to reach sensitive data.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH
SOL
TRX