FomoPeek: the App Store app that read wallet keys off the phone
PublicAML · On-chain investigation · 23 September 2026
FomoPeek was sold as a whale-watching app. Two of its versions carried a hidden iOS exploit that escaped Apple’s sandbox and read the Keychain and other wallet apps’ files, so people lost their coins without typing a seed phrase or signing anything. One address collected 580,129 USDT from those phones between 15 and 23 September 2026, and emptied itself as fast as it filled.
580,129
USDT into the collection address, 15–23 Sep 2026
413
token transfers into it in nine days
38
victim wallets we can see on Ethereum, now labelled
0
of the stolen USDT frozen by Tether
If you installed FomoPeek, do this first
- Treat every key and seed phrase that was on that phone as known to someone else. That includes wallets you never opened in the app.
- Create new wallets on a different device and move what is left. Do not import the old seed phrase anywhere.
- Change the passwords and revoke the sessions of anything else that phone held: exchanges, email, messengers.
- Then check your address below, and tell us what happened — it is how the rest of this trace gets built.
What the app did
FomoPeek was published on the App Store as a read-only tracker for Solana, Ethereum and Tron whale wallets. Versions 1.1 and 1.2, released 9 and 12 September 2026, carried a module that picked one of several iOS kernel exploits depending on the device and OS version, escaped the app sandbox, decrypted the Keychain and read the stored data of other apps — wallets and notes apps among them. Version 1.3 removed it.
This is why the usual advice does not cover it. The victim never entered a seed phrase into the app and never approved a transaction: the keys were taken off the device, and the theft happened later, from the attacker’s own machine. SlowMist published the analysis on 19 September 2026.
How we know which address it is
The reports named a figure but not an address, and a widely repeated "attacker address" turned out not to appear in the article it was credited to. So we checked the candidate against the chain instead: 0x6d37f2C5e8F8546b648D317295565dA95975f4BB received 580,129.46 USDT in 413 token transfers between 15 and 23 September 2026. MistTrack's published figure, a day earlier, is 579,984.34 USDT. The arithmetic is what identifies the address; nothing here rests on a quote.
It did not only take stablecoins. The same wallets lost whatever else they held:
| Token | Amount taken |
|---|---|
| USDT | 580,129 |
| ELON | 342,741,556 |
| SHIB | 50,115,856 |
| PEPE | 15,145,283 |
| WHITE | 3,240,283 |
| TEL | 834,476 |
| BONE | 350,322 |
| KEY | 149,677 |
Where the money went
The collection address does not hold the money: 22 USDT remain. It paid out to a layer of addresses whose first and last characters copy each other — the same look-alike trick used in address-poisoning — and from there the money splits into round amounts of 40,000 to 240,000 USDT across dozens of fresh contracts.
| Address | USDT received |
|---|---|
| 0x0A5769…34BbAE | 1,225,512 |
| 0x0DF8D0…ea3E68 | 477,000 |
| 0x111fAe…BF541c | 432,478 |
| 0x0DF6aC…eA3e68 | 318,000 |
| 0x0df695…A63E68 | 159,000 |
| 0x11183E…Bf541c | 152,810 |
| 0x0A571f…34BbAe | 146,676 |
| 0x0a5725…dcBbaE | 62,174 |
What cannot be done
None of it is frozen. We checked every address above against Tether’s own blacklist on 23 September 2026: not one is blocked, and each holds nothing. The money moved before the story was published, which is the usual ending when a theft is discovered from the victim’s side rather than from the chain.
What is left is attribution. Every address on this page is now labelled in PublicAML, so an exchange or an exchanger that screens an address will see where the money came from, and a victim can at least document the route.
Was your wallet one of them?
We labelled 38 wallets that the FomoPeek drainer emptied on Ethereum. Paste an address and you will land on its page, which says whether it is one of them. We do not store what you type here.
Did FomoPeek take your coins?
We can see the Ethereum side of this theft. The app also watched Solana and Tron wallets, and those victims are invisible to us until somebody tells us. If your coins went, tell us which address they went FROM and where they landed, and we will trace it and add what we find here.
Sources: Ethereum chain data via Blockscout and public nodes, read on 23 September 2026, and the PublicAML graph; the app’s behaviour as described in SlowMist’s published analysis of 19 September 2026. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.