Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT
SlowMist, working with OKX security researchers, found that versions 1.1 (released Sept. 9) and 1.2 (Sept. 12) of the App Store app FomoPeek contained two modules unrelated to its advertised transaction-tracking function: one communicating with command-and-control servers and one containing a kernel exploitation framework with eight attack methods. Blockchain analysis firm Salus attributed roughly 579,900 USDT in stolen funds to the incident and identified an attacker address, 0x6d37f2C5e8F8546b648D317295565dA95975f4BB.
According to SlowMist founder Yu Xian, a successful exploit could break through the iOS sandbox isolation mechanism, read and decrypt the system Keychain, and access data files from other apps — potentially exposing private keys, mnemonic phrases and login credentials stored on the device. Binance, OKX, Gate, Bitget Wallet and Rabby have issued user warnings.
The malicious components were absent from FomoPeek's original release and were removed again in version 1.3 on Sept. 17; the framework was also able to receive remote instructions governing whether exploitation was enabled and how often it ran. Salus traced 401,028 USDT through three intermediary addresses to FixedFloat, 20,000 USDT through deposit addresses into a KuCoin hot wallet, 111,458 USDT via an address it associated with an escrow platform, and 10,000 USDT through the CCE mixing service before reaching escrow-linked addresses.
rss · CryptoSlate · · 2 sources
Background, discussion, and references
Tags
#FomoPeek#SlowMist#iOS sandbox escape#USDT theft#Apple App Store#Keychain