Food Delivery App or Crypto Trap? SlowMist Founder Exposes New iOS Threat
The founder of blockchain security firm SlowMist, Yu Xian, recently raised the alarm about a sophisticated new threat targeting cryptocurrency holders. A seemingly legitimate food delivery application called "ComeCome" is actually malicious software designed to steal digital assets from users' devices.
The "Poisoning" Tactic: Advanced Camouflage for Malware
According to Yu Xian's analysis, this app employs a classic "poisoning" attack method. Malicious code is embedded within a fully functional, ordinary-looking application, allowing it to bypass initial app store reviews and users' common sense. Once installed and run, the app can silently scan the device in the background to steal sensitive information from cryptocurrency wallets, such as seed phrases and private keys.
This is not a novel approach. Yu Xian pointed out that its strategy is identical to the previously exposed malicious app FomoPeek. Both exploit users' trust in everyday applications—like utility, entertainment, or lifestyle apps—to carry out highly covert asset theft.
Who is at Risk? Beyond iPhone Users
While this case primarily targets iPhones, the risk profile is broader. Yu Xian specifically warned that all users within the Apple ecosystem must be vigilant:
- iPhone Users: The primary targets. Should immediately audit their devices for apps from unknown sources.
- iPad Users: Run the same iOS/iPadOS system and face identical risks.
- Mac Users: With the adoption of Apple Silicon and converging app ecosystems, the risk of cross-device malware propagation is increasing.
Take Action Now: Essential User Protections
Against such a stealthy threat, passive caution is insufficient. Yu Xian provided clear action steps:
The first and most critical step is to immediately update your iOS, iPadOS, or macOS device to the latest official version. Apple frequently patches known security vulnerabilities through system updates, forming the most effective foundational defense against known attack methods.
Additionally, users should cultivate these security habits:
- Download apps exclusively from the official Apple App Store. Avoid installing apps distributed via web links, third-party stores, or TestFlight whenever possible.
- Be skeptical of apps requesting excessive permissions, especially those unrelated to their core function (e.g., a food delivery app asking for keychain access or extensive background data).
- Regularly review the list of installed applications on your device and remove any unused or suspicious software.
This incident serves as another stark reminder that in the world of digital assets, security threats are becoming increasingly indistinguishable. Malware no longer always appears as obvious viruses; it may be disguised as the familiar, everyday icon we rely on most.