EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

iPhone应用窃取了加密货币密钥,超过一周才被发现

2026-09-22 00:45:13
Bookmark

币安发布紧急安全警告:iPhone与iPad用户需排查FomoPeek应用

币安(Binance)发布了一项紧急安全建议,警告iPhone和iPad用户检查是否曾安装过一款名为“FomoPeek”的应用。该警告基于安全研究人员的发现:版本1.1和1.2中包含恶意代码,能够窃取受影响设备中的私钥、助记词及其他敏感数据。

私钥是控制加密货币钱包的密钥;助记词则是用于恢复钱包的备份。一旦这些信息泄露,攻击者即可清空钱包中的所有资产。

攻击原理揭秘

FomoPeek伪装成一款加密货币市场追踪应用,并通过苹果官方App Store分发,而非第三方来源。安全公司SlowMist联合OKX安全团队发现,在版本1.1和1.2中隐藏了两个与该应用宣传功能无关的模块。

其中一个模块包含一个iOS内核利用框架,具备八种不同的攻击方法,可根据设备型号和操作系统版本选择最合适的漏洞利用方式。研究人员指出,该框架覆盖iOS 12.0至26.1版本,其中较旧版本的系统面临最高风险。

一旦漏洞利用成功,恶意软件便可突破iOS的沙盒机制——即通常用于防止应用间相互访问数据的隔离屏障——从而读取设备上其他应用的私钥、钱包恢复短语、登录凭证、聊天消息及文件等内容。

不仅是钱包的问题

币安强调,该恶意软件针对的是设备本身,而非特定的加密应用程序。一旦攻击成功,手机上的所有应用数据都可能暴露,而不仅仅是加密货币钱包。

此外,恶意代码还可接收来自操作者的远程指令,由后者控制漏洞利用的执行频率。

根据SlowMist的分析,FomoPeek版本1.0是干净的;恶意代码于9月9日在版本1.1中引入,并在9月12日的版本1.2中延续,最终于9月17日的版本1.3中被移除。

如果已安装,该如何处理?

币安建议立即删除该应用,并将iOS系统更新至最新版本。对于使用自托管钱包的用户,应在从未安装过FomoPeek的设备上创建新钱包,然后将所有资产转移至新地址。

任何注意到异常活动的人士应保留受影响的设备,并联系币安客服寻求帮助。

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP