Coin Brief ENDE

An App Store crypto tracker broke the iOS sandbox to reach other wallets

Roughly $580,000 of USDT was taken from people who had installed FomoPeek, an iPhone application that reached them through Apple's own store. CryptoSlate set out the case on 22 September 2026.

Blockchain security firm SlowMist began investigating over the weekend after reports of stolen assets tied to exposed private keys. Affected users had version 1.1 or 1.2 installed. The app presented itself as a passive viewer for watching large transfers on Ethereum, Solana and Tron — nothing it did required write access to anything. Inside those two builds, SlowMist and researchers from OKX turned up a pair of components that had nothing to do with watching transfers.

According to the report, the exploit could break iOS sandbox protections and reach private keys, seed phrases and Keychain data stored by other apps, with eight iOS exploit methods found inside the versions examined. Binance, OKX, Gate, Bitget Wallet and Rabby are warning users while investigators trace the funds and assess wider exposure.

An App Store crypto tracker broke the iOS sandbox to reach other wallets
An App Store crypto tracker broke the iOS sandbox to reach other wallets — Coin Brief

What it means

The detail that matters is not the theft total but the boundary that failed. A read-only tracker is, by its stated function, an app with no reason to hold or see a key — and users install that class of app precisely because it appears to carry no custody risk. The threat model most people apply is "does this app ask for my seed phrase", and this one did not have to.

Sandbox isolation is the assumption underneath that reasoning. If one App Store app can read another's Keychain items, then the security of a hardware-backed wallet on the same device depends on every other app installed beside it, which is not a property users can evaluate.

Two limits on what is established here. The figure, the module count and the capability description come from the cited security firms through a trade publication; we have not seen the technical write-up or independently verified the exploit chain. And the practical instruction for anyone affected is to treat keys that ever existed on a device running those versions as exposed — moving funds to keys generated elsewhere, rather than relying on the app's removal.

⚠️ Nothing here is a recommendation about any asset, exchange or wallet product.