Search the site
Press ESC to close
LIVE
Loading...
Updating...

Apple App Store FOMO Malware Alert: Crypto Wallet Private Keys at Risk

Fact-checked
3 min read
421 words
Share

Security experts have identified a significant security breach affecting the Apple ecosystem, where a malicious application titled FOMO bypassed App Store security protocols. The application, which remained available for public download for over a week, is designed to exfiltrate cryptocurrency wallet private keys and mnemonic phrases from unsuspecting users. This incident highlights a growing trend of sophisticated malware targeting mobile devices to drain digital asset holdings.

Exploitation of WebKit and JavaScriptCore Vulnerabilities

According to reports from Protos, SlowMist Chief Information Security Officer Zhang Shanshan has issued a warning regarding a specific malware strain known as DarkSword. This malicious software targets iPhone users by exploiting memory corruption vulnerabilities within WebKit and JavaScriptCore in the Safari browser. The technical exploit allows attackers to bypass standard sandbox protections to access sensitive data stored on the device.

  • Affected Versions: The vulnerability impacts a wide range of operating systems, specifically iOS 13 through iOS 26.5.
  • Targeted Data: The primary objective is the theft of private keys, mnemonic seeds, and other sensitive authentication credentials.
  • Infection Vector: Primarily executed through malicious scripts that trigger memory corruption during web browsing sessions.

The FOMO App Breach on the Official App Store

The threat escalated between September 9 and September 17, 2026, when the official FOMO application was hosted on the Apple App Store. During this eight-day window, the app was available for legitimate download, despite containing a hidden malicious module. The presence of such software on a moderated platform raises concerns regarding the current effectiveness of automated app screening processes for crypto-related threats.

SlowMist discovered that the FOMO app contained a malicious module capable of stealing mnemonic phrases and private keys. Even after updating or deleting the app, users should consider their related credentials as compromised.

Security researchers emphasize that the removal of the application does not reverse the potential theft of data. Once a mnemonic phrase has been transmitted to an attacker's server, the associated funds on any blockchain—whether Ethereum, Bitcoin, or Solana—remain at risk until they are moved to a newly generated, secure wallet.

Users who downloaded the FOMO application or visited suspicious links during the affected period are urged to migrate their assets to new hardware wallets immediately. As the landscape for mobile security evolves, experts recommend utilizing multi-signature (Multi-sig) solutions and avoiding the storage of unencrypted seed phrases in mobile clipboards or cloud-synced note applications. The incident serves as a critical reminder that official app stores are not immune to supply chain attacks and sophisticated malware injections.

Frequently Asked Questions

Quick answers to the most common questions about this topic.