On 19 September 2026, the blockchain security firm SlowMist and OKX's security team published a warning about an iOS app that had been sitting in Apple's App Store like any other download. FomoPeek marketed itself as a read-only tracker for watching large wallets move money across Ethereum, Solana and Tron, and it asked for no keys, no signatures and no permissions that would make a careful person hesitate. Two of its releases carried a hidden exploit chain that could break out of Apple's sandbox, decrypt the device Keychain and read files belonging to other apps. Cointelegraph reported that roughly 579,984 USDT was traced to the attacker's main address.
A fake crypto app is usually described as a clumsy clone with a misspelt name and a five-star review from an account made yesterday. This one was a working product with a plausible purpose, and the lesson it leaves behind is about which parts of your setup depend on the phone staying trustworthy.
How a fake crypto app gets through review
The timeline matters more than the marketing. Versions 1.1 and 1.2 shipped on 9 and 12 September and carried the malicious modules; version 1.3, released on 17 September, removed them. For roughly a week, the download you got from an official store was the compromised one.
App review checks what software does while somebody is looking at it. Because a remote server decided when the exploitation routines ran and what they collected, the app could behave impeccably during review and turn hostile later, on a schedule nobody at Apple controlled. That is the gap worth internalising: the store is a filter on presentation and observed behaviour rather than a guarantee about every future execution of the code.
What the exploit could reach
SlowMist's analysis described two malicious modules carrying an iOS kernel exploitation framework with eight separate attack methods, covering iOS 12.0 through 18.7.2 and 26.0 through 26.1. That range takes in most iPhones in circulation.
Once the sandbox boundary went, the chain could decrypt Keychain data and open files stored by unrelated applications. The server configuration named nineteen wallet and notes apps as targets, among them MetaMask, Trust Wallet, SafePal, OKX Wallet and Apple Notes. Read that list again and notice what the last entry means. An attacker who reaches your notes does not need to defeat a wallet's cryptography, because plenty of people have typed their recovery words into a note and left them there.
Why a phone can only protect a key so far
Every software wallet on a handset makes the same trade, and for small balances it's a sensible one. The private key has to be readable by software so the app can sign a transaction, which means the key's safety rests on the operating system rather than on anything the wallet author built. iOS does this job well against ordinary attacks.
The arrangement comes apart when the operating system itself is the thing that falls. Code running with kernel privileges sits underneath the boundary the wallet was relying on, so no hot wallet on that device can hold a secret back from it, however carefully the app was written. Choosing between mobile wallets has a ceiling for exactly this reason, since all of them stand behind the same door.
What changes when the key was never on the phone
Here is the boundary the FomoPeek chain could not cross. A key generated inside a certified secure element on a separate device, which has never been exported, is not in the Keychain and not in any app's storage. Kernel access on the handset does not produce it, because the handset never held it. The chip receives a request, signs, and returns a signature; no interface exists that hands the key back out.
On Ryder One the key is generated inside an EAL6+ certified Infineon SLC38 and stays there, with the firmware audited by Halborn and the report published in full. Communication is NFC only, so there's no wired data path and no Bluetooth or Wi-Fi radio for a compromised phone to reach through, and the device is addressable only while you hold it against the phone.
We should be even-handed about the limit of that protection. A compromised phone can still present you with a convincing request and hope you approve it without looking. What changes is that the details you're approving appear on a screen the attacker has no access to, which turns a silent theft into something you can decline by reading the 1.6-inch display before you tap.
If your recovery words ever touched that device
This is the part that outlasts the incident, and it's where the damage tends to settle. A kernel-level compromise can read photo libraries, notes and synced folders, so a seed phrase kept in a screenshot or a note is exposed even when the wallet app gave up nothing at all. Moving to a new wallet afterwards doesn't undo that exposure, because those words stay valid for every account they created.
SlowMist's guidance for anyone who installed version 1.1 or 1.2 is to treat exposed credentials as compromised, generate a new wallet on a device that was never affected, and move the assets across. Do that before anything else here. Where the fresh backup then lives is the decision you'll still be living with in ten years. Paper escapes every digital exposure and introduces fire, water and the recycling bin, which makes it fragile in a different way. A steel plate answers those and leaves your entire balance resting on one object staying unfound for decades, so it improves on paper without changing the shape of the problem. TapSafe Recovery was built to break that single point of failure apart: half of what a restore needs lives on the Recovery Tag, the other half travels with your paired phone and is held encrypted in your own iCloud or Google Drive rather than on the handset itself. Either half alone reveals nothing usable. Recovery Contacts are optional, hold a quarter share each, and can see no balances or addresses at any point.
What to do this week
Check which apps you installed in early September, and if FomoPeek was among them at version 1.1 or 1.2, follow SlowMist's advice rather than hoping you were missed. Then search your own phone the way an attacker would, looking through the photo library, the notes app and any synced folder for your recovery words, and delete what you find. Anything of size that sat in a software wallet on that device belongs behind keys generated somewhere clean.
Ryder One is 149 USD for the Starter Combo and 179 USD for the Super Safe Combo, with a Recovery Tag, wireless charger and pouch in the box. Setup runs about 60 seconds across three NFC taps, every transaction is shown in readable detail on the device before you approve it, and the keys are generated in the secure element and never leave it.
Meta description: A fake crypto app called FomoPeek cleared Apple's App Store review. What its exploit chain reached inside an iPhone, and the one boundary it could not cross.




Share: