• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Binance Vip program

Binance says App Store app FomoPeek could steal seed phrases from iPhones

09/21/2026
Four men tie up French family to force €40,000 crypto transfer

Four men tie up French family to force €40,000 crypto transfer

09/21/2026
Saudi Arabia leaves mBridge after saying its digital currency trial was complete

Saudi Arabia leaves mBridge after saying its digital currency trial was complete

09/21/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Binance Vip program

Binance says App Store app FomoPeek could steal seed phrases from iPhones

09/21/2026
Four men tie up French family to force €40,000 crypto transfer

Four men tie up French family to force €40,000 crypto transfer

09/21/2026
Saudi Arabia leaves mBridge after saying its digital currency trial was complete

Saudi Arabia leaves mBridge after saying its digital currency trial was complete

09/21/2026
Monday, September 21, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

Binance says App Store app FomoPeek could steal seed phrases from iPhones

A Binance security warning has urged iPhone and iPad users to check for FomoPeek after researchers linked versions of the app to code capable of exposing wallet credentials and other sensitive device data.

by Joseph Samuel
21 minutes ago
in Crypto News
Reading Time: 3 mins read
0
Binance Vip program
Share on FacebookShare on Twitter

Binance warned iPhone and iPad users on Sept. 19, 2026, that FomoPeek, an app distributed through Apple’s App Store, contained code researchers say could break out of iOS protections and reach wallet seed phrases, private keys and login data.

The FomoPeek malware presents a particular concern for crypto investors because the reported attack is not limited to a single wallet application. Binance said the incident should be treated as a device-level security issue rather than a conventional phishing attempt.

The exchange specifically urged users running iOS 26.x or earlier to determine whether they had ever installed FomoPeek. Users who meet both conditions were advised to remove the application, update their operating system and avoid reinstalling the software.

How the FomoPeek malware could access sensitive data

SlowMist’s investigation found that versions 1.1 and 1.2 contained components that were unrelated to the application’s advertised functions. Researchers working with the OKX security team identified an iOS kernel exploitation framework containing eight different exploit methods.

The framework was reportedly designed to select an exploitation method based on the affected device model and its iOS version. SlowMist said the framework covered a range of operating systems, including iOS 12.0 through 18.7.2 and iOS 26.0 through 26.1.

If the exploit succeeds, the FomoPeek malware could reportedly break through Apple’s application sandbox and gain access to protected information. Researchers said this could include Keychain data, private keys, wallet recovery phrases, login credentials, conversations and files belonging to other applications.

The investigation also identified communications between the malicious components and infrastructure unrelated to FomoPeek’s legitimate public services. According to the security analysis, those connections could allow remote instructions to be delivered to the compromised software.

SlowMist further reported that FomoPeek version 1.0 did not contain the two malicious frameworks. The components appeared in version 1.1, released on September 9, and remained in version 1.2, released on September 12. Security researchers said version 1.3, released on September 17, removed the identified frameworks.

The discovery is particularly notable because the affected versions were distributed through Apple’s official App Store, rather than being limited to unofficial or modified installations.

FomoPeek malware raises wider mobile security concerns

The FomoPeek malware is part of a broader pattern of attacks targeting cryptocurrency users through mobile devices. Security researchers have previously documented malware capable of searching smartphones for wallet recovery phrases, passwords and other information that can be used to access digital assets.

Earlier campaigns have included malware that searched photographs for recovery phrases. Other threats have relied on fake wallet applications designed to persuade users to enter their seed phrases directly into fraudulent software.

Rather than depending solely on a user voluntarily entering a recovery phrase, the malicious components identified by SlowMist were reportedly designed to exploit the operating system and access information belonging to other applications.

A compromised device can potentially expose information from multiple applications, increasing the consequences of a successful attack. Binance has therefore advised users to avoid applications from untrusted sources and keep device software updated.

What crypto investors should do after FomoPeek exposure

Investors who previously installed versions 1.1 or 1.2 of FomoPeek should treat the potential exposure seriously. Binance and SlowMist recommend removing the application and updating iOS to the latest available version.

For self-custody wallet holders, simply deleting the application may not be sufficient if sensitive credentials were already exposed. Binance recommends creating a new wallet on a separate device that has never had FomoPeek installed and transferring assets to the newly generated wallet address.

The FomoPeek malware warning also highlights why recovery phrases and private keys should not be stored casually on internet-connected devices. If a seed phrase has potentially been exposed, creating a replacement wallet with fresh credentials can limit the risk associated with the compromised information.

Users who discover unusual transactions or other unexplained asset movements have also been advised to preserve the affected device and relevant evidence before contacting Binance support.

The FomoPeek malware incident underscores a wider security challenge for crypto investors: protecting digital assets requires securing not only the blockchain wallet itself but also the devices used to access it.

As mobile applications become increasingly integrated with financial services, security researchers are likely to continue examining how vulnerabilities in smartphones can be exploited to reach cryptocurrency credentials.

For investors, the immediate lesson from the FomoPeek malware case is to verify installed applications, maintain current operating-system security updates and avoid relying on a compromised device for long-term custody of digital assets.

The FomoPeek malware investigation also demonstrates that an application appearing through an official software marketplace is not, by itself, an absolute guarantee against security risks.

Investors holding significant digital assets may therefore need to consider additional safeguards, including dedicated devices and carefully protected recovery credentials.

Tags: . crypto newsApple App StorebinanceBlockchain Securitycrypto scamcrypto SecurityCrypto wallet securityCryptocurrency NewsFomoPeekiPhone securityseed phrase theft
Share197Tweet123
Joseph Samuel

Joseph Samuel

Samuel Joseph is a professional writer with experience creating clear, engaging, and well-researched crypto contents. He specializes in Crypto contents, educational articles, debate pieces, and informative reviews, with a strong ability to adapt tone to suit different audiences. With a passion for simplifying complex ideas and presenting them in a compelling way, he delivers content that informs, persuades, and connects with readers. Samuel is committed to accuracy, originality, and continuous improvement in his craft, making him a reliable voice in digital publishing.

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
Binance Vip program

Binance says App Store app FomoPeek could steal seed phrases from iPhones

09/21/2026
Four men tie up French family to force €40,000 crypto transfer

Four men tie up French family to force €40,000 crypto transfer

09/21/2026
Saudi Arabia leaves mBridge after saying its digital currency trial was complete

Saudi Arabia leaves mBridge after saying its digital currency trial was complete

09/21/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.