SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.

🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨 We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek App versions 1.1–1.2. A joint investigation by the @SlowMist_Team and @okx security teams confirmed that the app contains malicious code.⚠️ Besides its normal features, FomoPeek includes two modules that are unrelated to its stated business functions. One of them contains an #iOS kernel exploitation framework with eight different exploit methods. The framework can automatically choose an attack method based on the device model and iOS version. ‼️Affected iOS versions: iOS 12.0–18.7 and iOS 26.0–26.1.‼️ If the exploit succeeds, the app may escape the iOS sandbox, access and decrypt Keychain data, and read files belonging to other apps on the device. 🔐 This means sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, and files, may be exposed. The app also connects to hidden servers that are unrelated to its public-facing services and can receive remote commands. Based on plaintext traffic captured during our analysis, the attack functionality is currently enabled and runs automatically at regular intervals. In general, devices running older iOS versions are at higher risk. If you have installed or used FomoPeek versions 1.1–1.2, we recommend that you take action immediately: 1️⃣ Check your accounts and assets for any unusual activity. 2️⃣ On a trusted device where FomoPeek has never been installed, create a new account and generate a new private key and seed phrase. 3️⃣ Move your assets to the new account as soon as possible. 4️⃣ Update your device to the latest available iOS version. 5️⃣ Do not continue using or reinstalling FomoPeek. 6️⃣ If you notice any suspicious asset activity, contact the official support team of the relevant platform and keep the affected device and related evidence for further investigation.
53
75
268
640,943
We’re working closely with @bitget on the ongoing investigation. For further details, please refer to Bitget’s official updates.
Replying to @bitget
[UPDATES] We are currently working with independent third-party experts Mandiant and SlowMist for a full investigation. Our first priority is our users. User balances remain intact, and Bitget's User Protection Fund covers the impact on this platform-wide incident. Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastructure from Bitget Exchange and was not affected by this incident. Bitget Wallet users' assets remain onchain under users' control and remain unaffected. The Bitget Exchange platform continues to operate normally. Withdrawals are still temporarily paused while we complete additional security checks, and we will restore them as soon as we are confident that it is safe to do so. We know that during an incident like this, users want answers quickly. We will provide timely updates through Bitget's official channels.
9
10
81
17,812
So far, we have identified the following addresses associated with the @bitget exploiter that still hold funds. We will continue to update this list. @GracyBitget @xiejiayinBitget @Bitget_zh docs.google.com/spreadsheets…
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
2
14
66
83,010
🚨 SlowMist TI Alert 🚨 MemTensor's AI memory tooling has been compromised: MemoryOS (PyPI), the company's open-source long-term memory library for LLM and AI agents, and memtensor/memos-cloud-openclaw-plugin (npm), the official plugin connecting it to the OpenClaw agent runtime. Affected versions bundle cross-platform Go binaries that execute when the package is loaded or imported: MemoryOS==2.0.34 on PyPI, and plugin versions 0.1.21, 0.1.23 and 0.1.25 on npm. You are affected if the PyPI version has been imported in your environment, or if the npm plugin is installed and the OpenClaw gateway has been started. Potential attacker actions include harvesting npm/PyPI tokens, GitHub/GitLab credentials, AWS keys, SSH keys, API tokens, environment secrets, and other developer credentials, with data sent to infrastructure under skyleen[.]fr. The affected npm plugin may also expose user prompt content. Users should remove or downgrade affected packages to known-good versions (0.1.20 for npm and 2.0.33 for PyPI), terminate sckit processes, block associated infrastructure, review network activity, and rotate credentials accessible from affected environments. You can also visit misteye.io/ to check for free whether the npm packages, pip packages, domains, or IPs you use are safe. Reference: aikido.dev/blog/supplychain-… As always, stay vigilant! enterprise.misteye.io/threat…
9
8
24
9,313
Thanks to @Cointelegraph for covering our investigation into the FomoPeek App Store poisoning and iOS kernel exploitation, conducted together with the @wallet security team. 🫡 We appreciate the opportunity to share our findings and help users better understand the risks and recommended response. 🌟 Read more 👉: cointelegraph.com/news/fomop…
7
4
22
8,135
📖 FATF Report | How to Understand and Address Risks in Gaming and Gambling FATF’s latest report examines the money laundering, terrorist financing, and proliferation financing risks across the gaming and gambling ecosystem. 🎰 As gambling platforms increasingly connect with online, cross-border operations and multiple payment methods, including virtual assets, related fund flows can extend beyond gambling platforms to exchanges, payment institutions, and other #VASPs. 🔍 For VASPs, identifying an address linked to gambling is only the starting point. A more meaningful risk assessment requires understanding where the funds come from, who they interact with, how they move, and whether the transaction behavior is consistent with historical activity. 🧩 In our latest article, SlowMist breaks down #FATF’s key risk indicators and explores how on-chain analysis can help institutions move from one-time screening to continuous risk management with @MistTrack_io . 🔗 Read the full analysis: slowmist.medium.com/fatf-rep…
2
3
10
6,097
🇯🇵🇺🇸🇦🇺🇩🇪 On Sep 18, Japan’s NPA and National Cybersecurity Office, the U.S. FBI and DC3, Australia’s ASD/ACSC, and Germany’s BND and BfV jointly released a report on North Korea-linked #WaterPlum, also known as “Contagious Interview” . SlowMist analyzed the report, examining the links between fake-job phishing, malware attacks, and “Laptop Farm” operations. 📄 Official report: npa.go.jp/bureau/cyber/pdf/2… 🔎 What the report reveals • Dec 2025–Jul 2026: 30,000+ computers infected across 100+ countries and regions • Data from 7,000+ crypto wallets stolen; at least JPY 1.7B (~USD 10.71M) flowed into wallets controlled by WaterPlum • Fake technical interviews can be used to deliver malware, steal credentials and wallet data, and enable further intrusion into corporate networks • Japan disclosed its first Laptop Farm seizure and dismantling 👤 For individuals / freelancers Don’t run unfamiliar interview code on machines holding wallets or sensitive work data. If an alert fires, disconnect from the internet first. 🏢 For hiring / outsourcing teams Treat unusually broad résumés, crypto-only payment requests, and refusal to work on-site as security signals worth investigating. 📖 Full analysis: slowmist.medium.com/analysis…
8
1
11
8,367
🚨SlowMist TI Alert🚨 💸 @DoinGudHQ Loss: ~$35k 🔍 Root Cause: In `acceptOffer` (0x5c924960) of Implementation 0x123aafc8d0a07ce1a146e53aa899e77f21a2dde1, after transferring `offer.price` USDC to `msg.sender`, the offer record is never deleted or zeroed — the swap-and-pop logic that `cancelOffer` performs is missing. This is compounded by absent checks: no `offerer != msg.sender` restriction and no `offerAmount > 0` requirement. An `amount=0` input also defeats `_updateListingAfterTransfer` cleanup (`0 > 0` is false), so the same offer can be replayed with identical calldata, paying out the full price each time. 📌 Attacker: 0xb8c717239bcace558c3a8dc471c16e07bf57a1eb (EOA) / 0xe588834aa3161a0720e8f6bf223748d6098a4b76 📌 Victim: 0xe3a161edd679fc5ce2db2316a4b6f7ab33a8ed6a 📌 Vulnerable Contract: 0x123aafc8d0a07ce1a146e53aa899e77f21a2dde1 Impact: Two replayed `acceptOffer` calls drained the contract's entire escrow balance (70,973.871434 USDC outflow in one tx); attacker profited ~35,380 USDC with zero NFT or principal, funded via flash loan. Powered by SlowMist.AI Tx: polygonscan.com/tx/0x56818a6…
3
3
24
5,053
🚨SlowMist TI Alert🚨 Attackers posing as a Web3 company used a remote job interview as a pretext to ask a candidate to deploy and run a project locally: hxxps://bitbucket[.]org/poc_review58/demoroyalcity Disguised as a real estate and crypto investment application, RoyalCity contained obfuscated malicious code in tailwind.config.js. Running or building the project can trigger payloads capable of stealing browser credentials and wallet extension data, exfiltrating local files, monitoring clipboard contents, and enabling remote control. A separate server-side backdoor in errorHandler.js retrieves and executes remote code. This case closely resembles the recruitment-themed GitHub poisoning attack we previously analyzed, sharing the interview lure, execution through Tailwind, and highly similar payloads for data theft and remote access. Our previous analysis (slowmist.medium.com/threat-i…) provides more detail on this attack pattern. 🔍 IOCs Malicious IP: 144[.]172[.]107[.]50 Malicious domain: server-azure-tau[.]vercel[.]app URLs: hxxp://144[.]172[.]107[.]50:8085/upload hxxp://144[.]172[.]107[.]50:8086/upload ws://144[.]172[.]107[.]50:8087 hxxps://server-azure-tau[.]vercel[.]app/api/ipcheck-encrypted/604 Malicious dependency/repository reference: bitbucket:https://bitbucket[.]org/poc_review58/demoroyalcity Malicious files — SHA-256: tailwind.config.js 62a98662f2f84001edd71b68e8fa318140c750ba9af096f5e4c9a0bb5502eb6e errorHandler.js d6705f52757af8bc2708a39647fc8c34dc02ffab7838a1d9c10fd44cfe9a7081 ⚠️ Verify recruiters independently. Review unfamiliar projects before running them, and keep interview tasks isolated from your everyday development environment, wallets, and sensitive credentials. You can also visit misteye.io/ to check for free whether the npm packages, pip packages, domains, or IPs you use are safe. As always, stay vigilant! enterprise.misteye.io/threat… Thanks to @jhh_kh37332 for sharing the lead.
8
12
34
8,833
SlowMist retweeted
⚠️ Security Alert: FomoPeek v1.1-1.2 A joint investigation by our security team and @SlowMist_Team has found malicious code in FomoPeek App versions 1.1–1.2 that may expose private keys, seed phrases, credentials, and other sensitive data on iOS devices. If you've installed or used these versions: • Stop using FomoPeek immediately • Create a new wallet with new keys on a trusted device where FomoPeek was never installed • Transfer your assets to the new wallet as soon as possible • Update iOS to the latest available version • Check your accounts for suspicious activity If you detect unauthorized activity, contact the relevant platform's official support team and retain the affected device and evidence for investigation. Protect your keys. Stay vigilant.
29
28
116
48,705
SlowMist retweeted
⚠️ Security Advisory | iPhone Users: Check Whether You’ve Ever Installed the FomoPeek App Binance is aware of a security incident recently disclosed by the community. According to security firms including SlowMist, the third-party app FomoPeek (versions 1.1–1.2) contains malicious code that can exploit iOS system vulnerabilities to gain the highest level of device privileges, potentially accessing sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, files, and more. Please note that this type of malware targets the device itself. If an attack succeeds, data from all apps on the affected device may be accessed. Please check the following: 1. Are you using an iPhone or iPad running iOS 26.x or earlier? 2. Have you ever installed the FomoPeek app? If both apply to you, we recommend taking the following steps immediately: 1. Delete the FomoPeek app and do not reinstall it. 2. Update your iOS to the latest available version. 3. For self-custody wallet users: On a device that has never had the app installed, create a new wallet and transfer your assets to the new wallet address. 4. If you notice any unusual asset activity, preserve the affected device and relevant evidence, and contact Binance Customer Support for further investigation. We also remind all users: Do not install apps from untrusted sources, and keep your device software up to date.
53
61
222
164,513
🚨SlowMist TI Alert: TraderTraitor Resurfaces via Weaponized Terraform Projects🚨 DPRK-aligned threat actor #TraderTraitor (aka UNC4899, Jade Sleet) — previously behind the April 2026 LayerZero/KelpDAO breach (~$292M stolen) has compromised a new victim: an India-based IT services company with no ties to crypto. ⚠️ Attack chain: 🎯 Fake job interview lures target DevOps/crypto engineers on GitHub 📦 Weaponized .terraform.lock.hcl files point to attacker-controlled Terraform provider domains ⚙️ Running terraform init triggers download & execution of malicious provider modules 💻 Deploys two macOS backdoors (Rust/ARM64): FLATROOF & ROOFDECK — same families used in the LayerZero attack 🔑 Capabilities include: • Credential and sensitive data theft • Shell and command execution • File collection and exfiltration • Cloud and source-control access 📌 This shows TraderTraitor is casting a wider net — even orgs with zero crypto exposure are being targeted, likely for whatever cloud/API access their developers can reach (AWS, GCP, OVH, OpenStack). 🛡️ Recommendations: 👉 Treat unknown Terraform provider registries as suspect — verify against registry.terraform.io. 👉 Flag engineers with cloud/source-control access for enhanced endpoint monitoring. 👉 Be wary of unsolicited coding "interview assignments" and repos from recruiters. 👉 Avoid using personal/corporate dev workstations for external job interviews. 🔎 Source: @LabsSentinel sentinelone.com/labs/dont-ca…
5
2
39
7,480
🚨 SlowMist TI Alert: Muse Zero-Day 🚨 According to a disclosure by @patrickwardle, a zero-day vulnerability in Muse for Mac could allow a local process without special privileges to hijack the AI assistant by modifying an undocumented setting. ⚠️ The flaw can redirect dictated prompts to an attacker-controlled endpoint, potentially enabling: 🎙️ Prompt/audio capture 💉 Prompt injection 🔑 Theft of authentication material 📱 Remote tasking of the user's connected mobile devices Since Muse can access user-authorized data such as messages, emails, and financial information, a successful attack could potentially expose sensitive information accessible to the assistant. 🛡️ Users should avoid installing or running untrusted Muse-related PoCs and monitor for suspicious local activity until mitigations are available. 🔎 One of 0day PoCs: github.com/pwardle/not-a-mus…
Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀 Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it. Let me show you. 🧵
1
9
5,615
🚨SlowMist TI Alert🚨 💸 GaslessReservoirEnabler Loss: ~$23k 🔍 Root Cause: GaslessReservoirEnabler’s erc20WithTransfersAndExecute → _executeInternal checked module addresses but did not bind ERC20 transferFrom instructions to an authorized asset owner, allowing arbitrary callers to spend victims’ existing allowances through whitelisted tokens. 📌 Attacker: 0x46f54c1a86575679fc3d29666c1717e9786279aa 📌 Victim: 997 token-holder addresses, including 0x2f785ef4f514f6b785ab93062e05cfcc937fac96 📌 Vulnerable Contract: 0x9b58fdadc16e30fba313e044bf9e88689c3f163e Impact: Existing WETH and ZED balances were transferred from token holders; proceeds were consolidated and deposited into a bridge on Polygon. Powered by SlowMist.AI Tx: polygonscan.com/tx/0x2e47674…
2
2
30
5,127
🚨 Threat Intelligence | PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager SlowMist Security Team identified a PolinRider sample in a development branch of the #LaravelNova extension package visanduma/nova-two-factor, which has 700,000+ cumulative downloads. The malicious code is hidden in tailwind.config.js and executes during frontend builds. Instead of hardcoding C2 addresses, the loader queries #Ethereum transactions to dynamically resolve delivery server IPs, allowing the operator to switch servers without republishing the package. The final payload is a cross-platform credential stealer targeting: 🔹 Browser accounts, cookies, and credentials 🔹 Crypto wallet data and extension storage 🔹 Password managers 🔹 Git, GitHub CLI, and other developer credentials ⚠️ Developers and CI/build environments using affected versions should inspect composer.lock and tailwind.config.js, review build-time network activity, and treat successfully executed builds as compromised. Rotate exposed credentials and wallet keys from a clean environment. Full analysis👇 slowmist.medium.com/threat-i…
8
7
24
6,445
🚨 Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation Following our earlier alert on FomoPeek v1.1–1.2, the SlowMist security team has completed the full technical analysis, based on a joint investigation with the @okx, @OKXWallet_CN security team. Through static analysis and dynamic verification of historical IPAs obtained from the official App Store, we confirmed that #FomoPeek versions 1.1 and 1.2 contained two malicious modules — apptrace and libapptracecore. Together, these modules provided capabilities including remote configuration, iOS kernel exploitation, sandbox escape, Keychain decryption, and cross-application data collection. 🧵👇
🚨 SlowMist TI Alert: FomoPeek App v1.1–1.2 Asset Theft 🚨 We have recently received multiple reports of users having assets stolen. Our investigation found that the affected cases involved private key exposure, and some of the users had previously installed and used @FomoPeek App versions 1.1–1.2. A joint investigation by the @SlowMist_Team and @okx security teams confirmed that the app contains malicious code.⚠️ Besides its normal features, FomoPeek includes two modules that are unrelated to its stated business functions. One of them contains an #iOS kernel exploitation framework with eight different exploit methods. The framework can automatically choose an attack method based on the device model and iOS version. ‼️Affected iOS versions: iOS 12.0–18.7 and iOS 26.0–26.1.‼️ If the exploit succeeds, the app may escape the iOS sandbox, access and decrypt Keychain data, and read files belonging to other apps on the device. 🔐 This means sensitive data stored on the device, including private keys, seed phrases, login credentials, chat history, and files, may be exposed. The app also connects to hidden servers that are unrelated to its public-facing services and can receive remote commands. Based on plaintext traffic captured during our analysis, the attack functionality is currently enabled and runs automatically at regular intervals. In general, devices running older iOS versions are at higher risk. If you have installed or used FomoPeek versions 1.1–1.2, we recommend that you take action immediately: 1️⃣ Check your accounts and assets for any unusual activity. 2️⃣ On a trusted device where FomoPeek has never been installed, create a new account and generate a new private key and seed phrase. 3️⃣ Move your assets to the new account as soon as possible. 4️⃣ Update your device to the latest available iOS version. 5️⃣ Do not continue using or reinstalling FomoPeek. 6️⃣ If you notice any suspicious asset activity, contact the official support team of the relevant platform and keep the affected device and related evidence for further investigation.
12
16
64
54,103
5/ @MistTrack_io tracing showed that the funds associated with this incident moved across multiple chains, including #TRON, #Ethereum, #BNBChain, and others. 🔴 The primary hacker address (0x6d37…f4BB) became active on September 15 and received a total of 579,984.34 $USDT. 🕵️ Most of the funds were consolidated on Ethereum. Funds on other chains were mainly converted to $USDT through services including OKX DEX, Meson[.]fi, Relay[.]link, and Mayan Finance before being bridged to #Ethereum. The consolidated funds were subsequently transferred in batches to downstream addresses that interacted with services including #FixedFloat, cce[.]cash, #OKX, and #KuCoin. We will continue monitoring the related addresses and fund movements.
1
3
2,920
6/ 🔐 Recommendations 🔹 Users: If a device ever installed FomoPeek 1.1 or 1.2 (Sep 9–17), uninstalling or upgrading to 1.3 does not clear historical exposure. Stop using the app and do not reinstall it. On a clean device that has never had #FomoPeek, create a new wallet with a new seed phrase, move assets immediately, and treat old seeds and keys as compromised. Review transfers and approvals, rotate credentials, and keep evidence. 🔹 Platforms: Treat 1.1 / 1.2 installs as credential exposure, not a finished app-update issue. Alert affected users, ingest the sample hashes and network IOCs into detection rules, and block assisaint[.]com and bitbucket[.]org/discordseven/*. More technical details, IOCs, and FAQs are provided below 👇 slowmist.medium.com/threat-i…
4
2,010