SlowMist Ties $580K in Stolen USDT to an iPhone Whale Tracker

An App Store listing that advertised itself as a read-only wallet tracker carried an iOS kernel exploit for eight days. The security firm SlowMist has traced 579,984 USDT to a single address it attributes to whoever ran it. The app is FomoPeek, published under the developer name WhaleScanv as a tracker for Ethereum, Solana and Tron. Versions 1.1 and 1.2 held the malicious code. Version 1.3, out on 17 September, does not.
Two frameworks, eight ways in
SlowMist published its analysis on 19 September and names two embedded components. One, apptrace, talked to a control server. The other, libapptracecore, carried the exploit chain: kernel read and write, privilege escalation, escape from the sandbox, and collection of whatever it could then reach. A sandbox is the wall iOS puts around each app to keep it out of every other app's files. SlowMist counted eight exploitation strategies with automatic version matching, and says the framework declared coverage for iOS 12.0 through 18.7.2 and for 26.0 to 26.1. CCN and The Crypto Times both give the ceiling as 18.7, without the point release. Neither side explains the gap.
What the framework went after was specific. SlowMist lists 19 applications on the collection target list, among them MetaMask, Trust Wallet, OKX Wallet, SafePal, imToken, TronLink and the container Apple Notes writes to. It also decrypted the system keychain, where an iPhone keeps passwords and, for some wallet software, the keys themselves. It is the same failure mode behind most of this year's losses; our September tally of stolen keys against code bugs put key theft well ahead.
"After a successful attack, the app can break through the iOS sandbox isolation mechanism, then read and decrypt the system keychain," SlowMist founder Yu Xian said in remarks carried by CryptoSlate.
The money, and an argument about where it went
The address SlowMist names went active on 15 September and took 579,984.34 USDT across TRON, Ethereum, BNB Chain and Arbitrum. SlowMist then follows four downstream splits, the largest 227,154 USDT and the next 159,000 USDT, which it says moved on to the swap service FixedFloat. Its own list of routes runs FixedFloat, cce.cash, OKX DEX, Meson.fi and Bridgers Swap. Cointelegraph's account on Wednesday puts KuCoin on that list, and CryptoSlate did the same a day earlier. The primary report names no centralized exchange anywhere in the chain. The two versions do not reconcile, and neither secondary account says where its KuCoin leg came from.
SlowMist worked the case with OKX's security team after users began reporting drained wallets on 16 September. CryptoSlate adds the analysis firm Salus to the list of parties that traced the funds; no other report we checked names Salus.
Deleting the app does not close it
The advice to anyone who installed 1.1 or 1.2 is blunt. "Uninstalling the app or upgrading to 1.3 does not mean that the device is already secure," SlowMist wrote. "Once the framework has been successfully exploited, the data it accessed has already left the device." Its remedy is a new wallet on a clean device, a fresh seed phrase, revoked approvals and changed credentials. Exchanges pushed the same message. CryptoSlate names Binance, OKX, Gate, Bitget Wallet and Rabby among those that told users to move assets; CCN names only Binance and Gate.io. Users on the receiving end of phishing mail sent from Trezor's own domain in September got a version of the same instruction.
What nobody has said
The number of people who lost money is still undisclosed. The Crypto Times, CCN and The Currency Analytics all report that neither SlowMist nor OKX has given a figure. Whether Apple has pulled the listing is also unsettled. The Currency Analytics says the company removed it, and that is the only account we found that makes the claim; CCN states plainly that it cannot say whether a removal happened or when. Cointelegraph said on Wednesday that it approached Apple, SlowMist and OKX and had no reply before publication. Until Apple says something, the only dated facts are the four version releases and one address with 579,984 USDT in it.
Read also: Ledger Patched an Ethereum Signing Flaw, Then Fought Over the Disclosure