Crypto Card News

Gate Warns of FomoPeek iOS Malware That Steals Wallet Logins

Published: Sep 19, 2026By Aleksandar Dukic

Key Analysis

Gate's security team flagged FomoPeek, an iOS app that reads the clipboard and steals wallet credentials. Risk controls blocked losses. Here is what to do.

Gate Warns of FomoPeek iOS Malware That Steals Wallet Logins

Listen To This Article

Gate Warns of FomoPeek iOS Malware That Steals Wallet Logins

3m 53s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

Gate's security team issued a public warning on September 19, 2026, about a malicious iOS app called FomoPeek that exploits device-level vulnerabilities to attack other apps on the same phone. According to the exchange's official post, the app can read the clipboard, scan sensitive data, and steal login credentials from any wallet application installed alongside it, including seed phrases that are not stored securely.

Gate said its own risk control systems, which run continuously in the background, meant no Gate users lost funds. The warning is aimed at the broader exposure: FomoPeek does not need to target the exchange directly to be dangerous, because it reads from whatever else is on the device.

The specific attack surface

The threat here is lateral. FomoPeek installs as its own app, then uses iOS vulnerabilities to reach across app boundaries that are normally isolated. The clipboard is the obvious prize. Anyone who copies a wallet address, a one-time code, or a recovery phrase leaves it sitting in clipboard memory, and a background app that can read it captures that value without any further interaction.

Credential theft is the second layer. If a wallet stores a seed phrase in plain text, a note, a screenshot, or a password manager entry that the malware can reach, that phrase can be exfiltrated. A stolen seed phrase is game over for the account it controls, because it reconstructs the wallet on the attacker's device with no password reset or support ticket to slow things down.

Gate's remediation steps

The exchange listed four actions for anyone who has FomoPeek installed. Uninstall the app immediately. Update iOS to the latest version, which is where the patched vulnerabilities live. Restart the phone, then log back into Gate and any other apps. Move Web3 wallet assets to a secure address that has never touched the compromised device.

That last step matters most for self-custody holders. If a seed phrase may have been exposed, changing a password does nothing. The only safe move is to generate a fresh wallet on a clean device and transfer assets out of the old one before an attacker does.

The card user's blast radius

Gate runs a card program built around its Gate Card, and the funding account for any exchange-linked card lives inside the same app the malware is hunting. The advisory reaches well beyond Gate's own customers, though. Most crypto card users fund their spending from a wallet app on their phone, whether that is a custodial exchange balance or a self-custody wallet that holds the keys directly.

For self-custody card holders the exposure is sharper. When the card spends straight from your own wallet, the seed phrase is the master credential for both your savings and your spending float. A phone-based stealer that captures it drains everything at once. Keeping the recovery phrase off the device entirely, on paper or a hardware backup, removes the single item this class of malware wants most.

The pattern is not new. Fake or trojanized mobile apps that harvest clipboard data and credentials have become one of the more common vectors against crypto users this year, and they rarely announce themselves as anything other than an ordinary utility. Gate catching FomoPeek before its users lost money is the useful part of this disclosure. The uncomfortable part is that the same app sitting on someone else's phone, next to a wallet with weaker storage habits, would have a very different outcome.

Overview

Gate warned that FomoPeek, a malicious iOS app, exploits device vulnerabilities to read the clipboard and steal login credentials and seed phrases from other wallet apps on the same phone. Gate's risk controls blocked losses for its own users. Affected users should uninstall the app, update iOS, restart, and move Web3 assets to a secure address. Card holders who fund spending from a mobile wallet, especially self-custody users, are directly in the blast radius and should keep recovery phrases off the device.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.