Security Research

FomoPeek iOS Attack: What Crypto Wallet Users Should Do
Main Takeaway: FomoPeek was an App Store poisoning incident. Versions 1.1 and 1.2 carried malicious modules for iOS exploitation, sandbox escape and cross-App data collection. Anyone who installed either version should treat phone-stored secrets as possibly exposed and move affected assets using a separate device. Quick reference Term What it means here App Store poisoning Malicious code distributed inside an App from an official software store. iOS sandbox The boundary intended to stop one App from reading another App's private files. Keychain The encrypted iOS store used by Apps for passwords, tokens and sensitive data. Private key The secret that authorizes transactions from a crypto address. What happened in the FomoPeek incident? SlowMist and the OKX security team found two malicious modules inside FomoPeek versions 1.1 and 1.2. The modules could receive remote commands, exploit iOS, escape the sandbox and collect data from other Apps. Historical packages showed that the modules arrived through official App Store releases. SlowMist's technical analysis...

Seed Entropy: How to Check Whether Your Wallet Actually Has It
The Coldcard flaw was a silent build error: a software RNG stood in for the hardware one for five years. What happened, how ELLIPAL generates randomness, and the parts you...

Crypto Security in 2025 and 2026: 5 Major Events and What They Mean for Self-Custody
From the Trust Wallet $7M browser hack to the Drift $285M multisig takeover, 5 events in 2025-2026 reshape what self-custody looks like in 2026. Here's what each teaches.

Drift Protocol Hacked for $285M: What It Reveals About Exchange Risk
The Drift Protocol exploit proved "decentralized" doesn't mean safe. Here's why self-custody with an air-gapped hardware wallet is the only real protection.

North Korean Hackers Just Poisoned a Library Used by 83 Million Apps: Why Your Air-Gapped Wallet Didn't Flinch
North Korean hackers compromised Axios, an npm library downloaded 83 million times per week, injecting malware that targets crypto assets. Meanwhile, two teens drove...

Trust Wallet $7M Hack: What It Means for Wallet Security in 2026
$7 million stolen. 2,520 wallets drained. 48 hours. The Trust Wallet Christmas hack proved browser wallets are fundamentally vulnerable. With crypto theft hitting $3.4...

Supply Chain Attack on NPM: What It Means for Crypto Users
Your crypto could be stolen without you knowing. A malicious NPM package is live. ELLIPAL’s Clear Signing cold wallets are the only defense.

What are Supply Chain Attacks on Hardware Wallets and How to Prevent Them?
Hardware wallets protect crypto offline, but supply chain attacks can compromise them before arrival. Learn to spot tampering and secure your device from factory...

Cross-Chain Bridge Security: Using Hardware Wallets For Multi-Chain Transactions
Learn how hardware wallets protect your assets during cross-chain transactions and why they are essential for secure, seamless multi-chain crypto operations.

The Bybit Heist: How Hardware Wallet Screens Became Crypto's Last Line of Defense
On February 21, 2025, Bybit—the world’s third-largest cryptocurrency exchange—was hit by a heist of cinematic proportions. North Korea’s notorious Lazarus Group made off with...

Beware of the Zero Transfer Scam
Cryptocurrencies have grown quickly, offering a ton of benefits and opening up new ways for people to invest and achieve financial freedom. But, just...

DEXX Exposed: The Importance of True Decentralized Wallets
Recently, the DEXX platform suffered a security breach that raised serious concerns within the Web3 community. Despite claiming to offer “non-custodial” services, DEXX stored...




