SlowMist: FOMO's official iOS app exposed for containing crypto-stealing malware, was live on the App Store for a week.
September 23: Blockchain security firm SlowMist warned that the official FOMO iOS app was once found to contain malware capable of stealing crypto assets, and the affected versions of the app were available on the App Store from September 9 to September 17.
SlowMist said the malicious module possesses attack capabilities similar to DarkSword malware, which could lead to the theft of users' seed phrases and private keys. Because the FOMO app was promoted through crypto KOLs, some users may have downloaded the affected versions as a result.
SlowMist also reminded users that simply updating or deleting the FOMO app may not be enough to eliminate the risk, and users who have used the affected versions should treat the related seed phrases, private keys, and sensitive credentials as already compromised and take corresponding security measures.
In addition, SlowMist Chief Information Security Officer Shān Zhang previously warned that iOS versions 13 to 26.5 may be affected by malicious Safari link attacks exploiting WebKit and JavaScriptCore memory corruption vulnerabilities. Attackers can use this to gain JavaScript-layer read and write permissions, and further bypass pointer authentication, escape the WebContent sandbox, and elevate kernel privileges, ultimately obtaining crypto keys and wallet data.