Web3 Daily Exploits — 19 Sep 2026: Quiet Window + FomoPeek Malware
Required monitors reported no new first-report smart-contract protocol drains in the last 24 hours. Combined live loss on this card is ~$0. SlowMist and OKX flagged FomoPeek App v1.1–1.2 as containing iOS kernel exploits capable of Keychain and private-key theft. Prior Nostra ~$3.5M, Nimiq ~$50k and Likwid remain on the 18 Sep brief.
Required monitors were checked through the 19 Sep 2026 America/Panama cutoff: DefimonAlerts, CertiKAlert, Phalcon, GoPlusSecurity, SlowMist_Team, PeckShieldAlert, BlockSecTeam, Lookonchain, ZachXBT, CyversAlerts, Immunefi, and rekt.news. No new first-report smart-contract protocol drain with a fresh loss figure landed in this slice. Combined live loss scored on this card is approximately $0. This is a quiet window for on-chain DeFi exploits after the 18 Sep cluster (Nostra ~$3.5M, Nimiq ~$50.4k, Likwid 74.31 BNB).
The sole material security item first surfaced or amplified in the required-monitor set during the window is a joint SlowMist / OKX advisory on the FomoPeek iOS app (versions 1.1–1.2). That is client-side malware / private-key exposure, not a protocol smart-contract drain, and is therefore not scored as a live-loss incident on this card. All prior-day protocol losses remain on their original briefs and are carried as status only.
FomoPeek App v1.1–1.2 — iOS malware / private-key exposure — Confirmed advisory
What happened: On 19 Sep 2026 SlowMist published a TI alert, jointly investigated with OKX security teams, stating that multiple users who had installed FomoPeek App versions 1.1–1.2 reported asset theft. Analysis found the app contains malicious modules unrelated to its stated features, including an iOS kernel exploitation framework with eight different exploit methods that can auto-select based on device model and iOS version.
Protocol / chain / asset: Not a blockchain protocol. Client-side iOS application. Affected iOS versions cited: iOS 12.0–18.7 and iOS 26.0–26.1. Successful exploitation can escape the sandbox, access and decrypt Keychain data, and read files belonging to other apps, exposing private keys, seed phrases, credentials and related data. The app also connects to hidden servers and can receive remote commands; plaintext traffic analysis indicated attack functionality is currently enabled and runs automatically at intervals.
Loss: No aggregate dollar figure published by required monitors. Individual user reports of stolen assets; not scored as a protocol live-loss total on this card.
Attack type: Malicious mobile application / iOS kernel exploit chain leading to Keychain and private-key theft. Not a smart-contract vulnerability.
Technical details: SlowMist: two modules unrelated to stated business functions; one contains an iOS kernel exploitation framework. If the exploit succeeds the app may escape the sandbox and read Keychain and other-app files. Recommended actions from the advisory: check accounts for unusual activity; on a trusted device that never had FomoPeek installed, generate new keys/seed; move assets; update iOS; do not reinstall FomoPeek; preserve device and evidence if theft is observed.
Explorer links: Not applicable (client malware, not an on-chain drain).
Status: Confirmed by SlowMist TI and joint OKX investigation. Advisory live. No protocol pause or on-chain return path applies.
Sources: https://x.com/SlowMist_Team/status/2101211432541192615
Nostra money market — Starknet — UPDATE (not re-scored)
What happened: First report remains on the 18 Sep brief. ~$3.5M borrow via NSTR oracle manipulation. As of the prior window ~$1.92–1.93M had been bridged to Ethereum and ~$1.55M remained on Starknet at the named borrow account. No required monitor published a return transaction or a revised final-loss figure in this 24h slice. Carried as status only.
Status: Money market remains paused per last official note. Final loss still under reconciliation.
Sources: Prior 18 Sep brief; https://x.com/nostrafinance/status/2100577538053493076, https://x.com/PeckShieldAlert/status/2100747001516454390, https://x.com/CertiKAlert/status/2100774528494526812
Also noted
- Nostra / Nimiq / Likwid (UPDATE, not re-scored): ~$3.5M + ~$50.4k + 74.31 BNB remain on the 18 Sep brief.
- Flamincome / PrimeFi (UPDATE, not re-scored): ~$346k + ~$33k remain on the 17 Sep brief.
- rsETH / yoink (UPDATE, not re-scored): ~$7.8M stack remains under Kelp temporary pause; carried as status only across prior briefs.
- RISEx XLP / RWA strategy: Defimon surfaced an on-chain white-hat-style recovery message regarding a 3 Aug 2026 unauthorized withdrawal already disclosed and covered by the project; not a new first-report drain in this window.
- Lookonchain: Whale ETH/BTC deposits, Machi position sizing, ZEC short liquidations. Market-flow notes, not exploit first-reports.
- ZachXBT: NFT mint commentary and impersonation warning. Not a protocol-drain first-report.
- CertiKAlert, Phalcon, GoPlusSecurity, PeckShieldAlert, BlockSecTeam, CyversAlerts, Immunefi, rekt.news: no additional first-report smart-contract drain with a fresh loss figure after the 18 Sep brief cutoff in the required-monitor set.
Sources & references
- https://x.com/SlowMist_Team/status/2101211432541192615
- https://x.com/nostrafinance/status/2100577538053493076
- https://x.com/PeckShieldAlert/status/2100747001516454390
- https://x.com/CertiKAlert/status/2100774528494526812
- https://x.com/DefimonAlerts/status/2101200596015435847
- https://x.com/DefimonAlerts/status/2100868892742602793
- https://x.com/SlowMist_Team/status/2100896541859054006
- https://x.com/SlowMist_Team/status/2100785330849009937
Editor’s note: Card live-loss is this window’s confirmed realized protocol drains only (~$0). FomoPeek is recorded as a confirmed malware advisory, not a protocol loss figure. Prior-day items remain on their original briefs and are carried as status only. White-hat and bounty claims are recorded as claims. No how-to or exploit reproduction steps. Stay tuned or stay rekt.
Read more
Web3 Daily Exploits — 18 Sep 2026: Nostra ~$3.5M + Nimiq ~$50k + Likwid
Nostra money market on Starknet lost ~$3.5M after NSTR oracle manipulation let one account over-borrow. Nimiq swap handlers on Polygon lost ~$50.4k via OpenGSN signature bypass. Likwid margin on BNB lost 74.31 BNB after a pair-reserve accounting bug. Combined live loss ~$3.6M.
Web3 Daily Exploits — 17 Sep 2026: Flamincome ~$346k + PrimeFi ~$33k
Legacy Flamincome USDT Strategy on Ethereum lost ~$346k after share-price inflation via Convex stakeFor and Curve virtual-price. PrimeFi on HyperEVM lost ~$33k after permissionless oracle report replay inflated PRFI. Quiet otherwise.
Web3 Daily Exploits — 16 Sep 2026: Bonfire ~$50k Approval Drain
BonfireSwap router on BNB Chain lost ~$47–50k after an access-control gap in transfer let anyone spend holders’ standing approvals. rsETH / yoink stack remains parked under Kelp’s temporary pause. Quiet window otherwise.
Web3 Daily Exploits — 15 Sep 2026: rsETH Safe $7.8M + Yoink Frontrun
A Gnosis Safe holding leveraged aEthrsETH was drained for ~$7.8M on Ethereum. MEV bot yoink front-ran the public-mempool exploit and parked ~2,882 rsETH. Bridgeless posted a 48-hour Zano ETHX whitehat burn offer.

