Built-in Framework in Crypto-Circle App FomoPeek Steals Private Keys, Resulting in Massive User Fund Theft
1 hour ago / Read about 0 minute
Author:小编   

SlowMist Technology reports that it has recently received numerous complaints regarding the theft of user assets. All these cases involve the leakage of private keys and are linked to users who have either installed or previously installed the FomoPeek app. Marketed as an on-chain fund movement tracking tool, the app was discovered to contain two built-in modules that are unrelated to its core business functions. One of these modules is an iOS kernel-level exploit framework. This framework is capable of automatically selecting an attack path based on the device model and iOS version. Upon a successful attack, it can bypass the iOS sandbox, access and decrypt keychain data, obtain the permission to read files from other apps on the device, steal sensitive data such as private keys and mnemonic phrases from encrypted wallets, and upload this information to the attacker's server. Moreover, FomoPeek can remotely receive instructions from attackers, allowing for the adjustment of attack methods at any given time. The targets of this kernel-level exploit framework include iOS versions ranging from 12.0 to 18.7 and 26.0 to 26.1, exploiting security vulnerabilities that Apple has already addressed with patches. SlowMist Technology strongly advises users to refrain from downloading apps from unverified sources, regularly update their iOS systems, and, if they have installed the FomoPeek app, uninstall it immediately and transfer their assets to a secure location.