币安警告iPhone与iPad用户检查是否安装FomoPeek应用
币安(Binance)已发出安全警告,提醒iPhone和iPad用户检查设备上是否安装了FomoPeek应用。此前,安全研究人员发现该应用的1.1版和1.2版包含恶意代码,能够窃取私钥、助记词以及其他存储在受影响设备上的敏感数据。
核心摘要
- 币安在发现FomoPeek 1.1和1.2版本中存在恶意代码后,向iPhone及iPad用户发出警示。
- 该恶意软件可能利用iOS系统的漏洞,访问用户的私钥、助记词、登录凭证以及其他应用程序存储的数据。
- 建议进行自我托管(Self-custody)的用户在清洁设备上创建新钱包,并将资产转移至新地址。
据币安表示,此次警告基于社区披露的安全事件以及包括SlowMist在内的区块链安全公司的调查结果。这些机构发现,受影响的FomoPeek版本能够利用Apple iOS操作系统的漏洞,从而在设备上获取高级权限。
⚠️ 安全公告 | iPhone用户:请检查您是否曾安装过FomoPeek应用
币安已知悉近期由社区披露的一起安全事件。据SlowMist等安全公司指出,第三方应用FomoPeek(1.1-1.2版本)包含……
币安指出,该恶意软件针对的是设备本身,而非特定的加密货币应用程序。因此,一旦攻击成功,不仅会泄露加密货币钱包数据,还可能暴露其他应用程序持有的信息,包括登录凭证、聊天记录和文件。
币安建议,已安装FomoPeek且运行iOS 26.x或更早版本的用户应立即卸载该应用,避免重新安装,并将操作系统更新至最新版本。对于使用自我托管钱包的用户,建议使用从未安装过FomoPeek的独立设备创建新钱包,并将资产转移至新地址。币安还呼吁任何检测到异常资产活动的用户,在联系客户支持之前,保留受影响的设备及相关证据。
FomoPeek恶意代码如何突破iOS沙盒限制
SlowMist的调查提供了更多关于恶意版本运作机制的细节。在收到多起涉及私钥泄露导致资产被盗的报告后,研究人员与OKX安全团队合作,在FomoPeek 1.1和1.2版本中发现了两个与该应用宣传功能无关的模块。
其中一个模块包含了iOS内核利用框架,配备了八种利用方法,使其能够根据设备型号和操作系统版本选择攻击方式。研究人员指出,该框架宣称覆盖的范围包括iOS 12.0至18.7.2,以及iOS 26.0至26.1。SlowMist强调,较旧版本的iOS通常面临更高的风险。
一旦利用成功,恶意代码便能突破iOS的沙盒限制,解密Keychain数据并访问属于其他应用程序的文件。这种访问权限可能导致私钥、钱包恢复短语、账户凭证、对话内容和本地存储的文件被泄露。
研究人员发现,恶意代码与不属于FomoPeek公开服务的基础设施进行通信,并能接收远程指令。对其通信内容的分析显示,操作者可以控制利用程序的执行及其运行频率。
通过官方App Store获取的历史版本显示,FomoPeek 1.0不包含这两个恶意框架。版本1.1(构建版105)于9月9日引入了它们,而版本1.2(构建版110)在9月12日发布后仍保留了这些代码。安全分析表明,版本1.3(构建版111)于9月17日移除了这两个框架。受影响的1.1和1.2版本是通过Apple官方App Store分发的,而非第三方或重新签名的安装渠道。
加密钱包恶意软件持续瞄准移动设备
移动设备一直是旨在获取加密钱包凭据的恶意软件的目标。今年七月,媒体曾报道过名为SparkKitty的移动间谍软件,它能够从受感染的iOS和Android设备中收集图像并将其发送至攻击者控制的服务器。
Kaspersky originally described the malware in detail in June 2025, when it was discovered that infected apps were distributed through the Apple App Store, Google Play and unofficial channels. SparkKitty aims to steal wallet recovery phrases, passwords and other sensitive information that users store on their phones in the form of pictures.
Previously, another malware family called SparkCat used optical character recognition technology to scan cryptocurrency recovery phrases in images. Some infected apps carrying malware have entered the official app store, and Kaspersky said the activity has been active since March 2024.
Researchers have also discovered other ways to hack into the iPhone without relying on users to store screenshots of mnemonic words. In March, Google's Threat Intelligence Team identified an iPhone exploitation suite called Coruna, which contained five complete exploitation chains and 23 vulnerabilities. The framework is targeted at devices running between iOS 13 and iOS 17.2.1 and is able to search for cryptocurrency wallet recovery phrases and financial information on infected phones. Google researchers said the toolkit has been used by different groups at different times, including profit-seeking cybercriminals.
Malicious apps penetrate Apple's App Store
Encrypted users also face separate threats from apps that pose as legitimate wallet software. In August this year, a fake Wasabi Wallet app was launched on the Apple App Store, and security monitoring reports linked it to a case in which approximately 6 BTC was stolen.
截至2026年,该欺诈性列表被列为在App Store上发现的第27起报告的加密钱包克隆案例。其中,假冒Ledger应用程序是最大的报告案例,被盗金额约为930万美元。此前,另一个假冒的Ledger Live应用与美国音乐家Garrett Dutton(艺名G. Love)损失价值约42万美元的5.9 BTC有关。
Dutton在新MacBook Neo上下载了伪装成Ledger Live管理器的软件,并在欺诈应用中输入了他的恢复短语。区块链记录显示,被盗的比特币随后转移到了与KuCoin交易所相关的几个存款地址。
与依赖于说服用户手动交出恢复短语的钱包冒充方案不同,SlowMist对FomoPeek的发现描述了恶意代码在利用操作系统后,能够获得提升的系统访问权限并从其他应用程序收集信息的能力。
早期移动恶意软件曾清空数千个加密钱包
SlowMist此前曾调查过直接从用户设备获取钱包信息的恶意应用程序。2025年2月,该安全公司报告称,一个名为BOM的虚假应用程序在Android和iOS平台上感染了超过13,000个钱包,估计损失超过182万美元。
Investigation showed that after requesting access to files, photos and media, the app scans device storage for private keys and mnemonics, and transfers the information to a remote server. On-chain analysis connects the primary attacker addresses to stolen assets flowing between BNB Chain, Ethereum, Polygon, Arbitrum and Base. The affected cryptocurrencies include USDT, Ethereum, Wrapped Bitcoin and Dogecoin.
For FomoPeek users, SlowMist recommends checking the account for unauthorized activity and generating new private keys and mnemonics on trusted devices where the affected app has never been installed. Assets stored in wallets that may have been exposed through version 1.1 or 1.2 should then be transferred to a newly generated wallet.
Binance gave similar instructions in its security notices, while advising users to keep device software updated and avoid obtaining applications from untrusted sources.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BNB
BTC
ETH