AltcoinBuzzAltcoinBuzz
Subscribe
  • Crypto News
  • Crypto Research
  • Technical Analysis
AltcoinBuzzAltcoinBuzz

An independent digital media outlet delivering crypto research, news, and technical analysis to a community of 600,000+ users.

Follow us on:

Discover

  • Crypto Research
  • Crypto News
  • Technical Analysis
  • Key Opinions
  • Upcoming Launches

Categories

  • Bitcoin BTC
  • RWA
  • Technology
  • Altcoins
  • Regulation

Company

  • Affiliates
  • Partners & Sponsors
  • Careers
  • Contact
  • Terms of Use
  • Subscription Terms
  • About the ALTCOIN BUZZ
  • Privacy Policy
  • Contact ALTCOIN BUZZ
  • Advertise with us

Copyright 2026 ALTCOIN BUZZ. All rights reserved.Something is buzzzzzzzing.
HomeCrypto NewsCrypto-draining FOMO App was Live on Apple's App Store for 8 days
Crypto NewsTechnologyPrivacy

Crypto-draining FOMO App was Live on Apple's App Store for 8 days

SlowMist found FOMO, a crypto-draining app, on Apple's App Store for 8 days. It exploited a WebKit flaw to steal seed phrases and private keys from iPhones.

BBikash Deka•Sep 22, 2026
Pop-art comic cover of a cracked iPhone with a malicious FOMO app icon breaking through its screen while a masked figure pulls a crypto key and seed phrase out of the device, with the Apple logo on the phone's back.

A malicious app called FOMO stayed on Apple's App Store for 8 days, from September 9 to September 17, with crypto-draining malware on board, blockchain security firm SlowMist found. SlowMist's chief information security officer, Shān Zhang, urged iPhone users to update to the latest iOS version after the discovery.

The app was promoted by crypto key opinion leaders and contained malware hidden in modules capable of stealing seed phrases and private keys. SlowMist's analysts also flagged a separate wave of crypto-stealing malware spread through malicious Safari links exploiting the same iOS flaw.

How the drain worked

The FOMO modules exploited a memory-corruption flaw in WebKit and JavaScriptCore, the engine pair that powers Safari and many in-app browsers on iPhone. According to Zhang, iOS versions 13 to 26.5 are vulnerable to malicious Safari links that use the same flaw, which analysts call DarkSword.

The flaw gives an attacker read and write access to the JavaScript layer, the part of a browser that runs page scripts. From there, the malware can bypass pointer authentication codes, escape the WebContent sandbox, and escalate to kernel privileges, the deepest level of access on an iPhone. That level of access lets the attacker exfiltrate crypto keys and wallet data.

What to do if you installed FOMO

Updating iOS or deleting the app may not be enough, SlowMist warned. The firm advised anyone who installed FOMO to treat their seed phrases, private keys, and other sensitive credentials as compromised, on the assumption they have been seen and copied.

Red flags the case surfaces

  • KOL promotion is not a safety check. FOMO reached users through crypto influencer promotion, even with a malicious payload on board.
  • An App Store listing is not a safety check either. FOMO passed Apple's review and stayed available for 8 days.
  • A software update may not undo the damage. SlowMist's own warning said that for affected users, updating or deleting the app may not be enough.

SlowMist did not publish the total value of crypto drained, the number of victims, or the names of the key opinion leaders who promoted the app.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence.

Copyright Altcoin Buzz Pte Ltd.

Related

Pop-art comic cover of a stack of SEC and CFTC filing papers bursting from a binder stamped with the Kalshi logo, beside a speech bubble reading KALSHI FILES PERPS.
Prediction MarketsRegulation
Sep 22, 2026

Kalshi Files for Perpetual Futures on 58 US Stocks and ETFs

Kalshi filed Sept. 18 with the SEC (SR-KALSHIEX-2026-02) and the CFTC to list perpetual security futures on 58 US stocks and ETFs. CFTC approval pending.

Shitij Gupta
Pop-art comic cover showing a CME Group badge flanked by UNI and Bitcoin Cash coins, marking their addition to CME futures on October 19.
AltcoinsDeFi
Sep 22, 2026

CME adds UNI and BCH Futures to Crypto Derivatives

CME adds Bitcoin Cash and Uniswap futures on October 19, giving institutions restricted from offshore crypto venues a regulated route to both tokens.

UNIBCH
Saloni Rathi
A pop-art illustration of a SoFi Mastercard card overlapped by a large SoFiUSD stablecoin coin, with the SoFi and Mastercard logos flat on the card and coin face.
StablecoinsRWA
Sep 22, 2026

SoFi Launches Stablecoin Settlement on Mastercard Network

SoFi has migrated its card program to SoFiUSD settlement on Mastercard's network, expected to process more than $25 billion in annualized volume.

Anmol Billa