We told you all summer: September was the time to lock in. We did. Robinhood Chain, airdrop farming, the Arc launch, and steadily DCAing into my ZEC, NEAR, and HYPE positions. Did you? Honestly, I haven’t had this much fun being active in crypto since the early NFT days. But the FomoPeek wallet-theft reports are a reminder that scammers have clocked back in too.
It’s looking increasingly likely to me that Bitcoin front-ran the four-year cycle bottom. That’s my read, anyway. When has this market ever politely followed the calendar everyone agreed on?
I hope you’ve been reading along, and that something we covered gave you the push to get involved. If you’ve been watching from the sidelines, there’s still time to learn, explore, and build a plan. Don’t stay sidelined forever, anon.
Just stay sharp while you’re out there. We recently covered fake YouTube tutorials that convinced users to deploy a supposed AI trading bot, only to drain their own wallets. Now, researchers have linked malicious versions of an iPhone app called FomoPeek to nearly $580,000 in stolen crypto.
My first thought was that the name might be trying to ride the popularity of the FOMO app. That’s a suspicion, not an established connection. Similar branding deserves a closer look before you download anything.
We keep an eye on everything that happens in the market. Here’s what else needs your attention.
1. Beni vs. Kalshi: The Volume Fight Reaches the WSJ
Earlier this week, we shared Beni’s allegations about wash trading on Kalshi. He appeared to have put real work into the numbers. Now, the Wall Street Journal has picked up the trading pattern, bringing a much bigger audience to the argument.
The Journal’s report examines an unusual burst of activity in Kalshi’s ether perpetual market. Here are the cliffs:
- The repetition: Almost one million trades since August involved nearly matching amounts, clustered around $5,500.
- The scale: Those trades represented more than one-third of recent transactions in that market and over $5 billion in volume during the past month.
- The regulatory interest: The CFTC is reportedly reviewing the activity before deciding whether an enforcement investigation is warranted. That does not establish wrongdoing.
- Kalshi’s explanation: Hundreds of different traders were involved, the company says. Market makers repeatedly posted fixed-size orders, which faster traders then filled.
- The incentives question: Kalshi says its liquidity programs pay for maintaining quotes at particular sizes and spreads. It also says self-trading is blocked and coordinated wash trading is prohibited and monitored.
The reporting names Jump Trading and Wintermute among participants in the rapid transactions. Jump says it trades for profit, prevents self-matches, and does not coordinate trades with other participants.
So, has Beni proved his case? That would be getting ahead of the evidence. Repeated order sizes can have legitimate explanations. Still, a pattern this large deserves scrutiny, especially when headline volume helps shape how people judge an exchange.
The debate now needs more than screenshots and confident replies.
2. Airdrop Updates: JUMP, Starknet, Arcus and ZetaChain
Don’t farm for months and then disappear when the project finally posts an update. Registration windows, claim deadlines, and migration requirements can decide whether your earlier activity counts. We’d hate to see you do the work and miss out because you skipped one announcement.
These are the updates to keep on your radar:
- Jumper: The upcoming token’s ticker is JUMP. The company has also announced a planned token sale through Legion, with the token launch intended to follow the fundraising process. Its announcement does not provide a firm TGE date or full tokenomics. A ticker reveal is not a live airdrop claim.
- Starknet: Check registration for the latest strkBTC faucet round. The official faucet uses a registration and selection process, so signing up does not guarantee an allocation. Check the live round status before assuming you still have time.
- Arcus: Perpetual-market maker fees are 0% for the remainder of beta, while taker fees have been halved. The fee update lowers trading costs, but it doesn’t remove funding costs or liquidation risk.
- ZetaChain: Holders approved a plan to retire the Layer 1 and move native ZETA to Solana. The chain has not already shut down. A second proposal is expected to establish the snapshot, migration process, and shutdown timing. If you still have funds there, check your positions and official withdrawal instructions now. Don’t leave forgotten balances to become a last-minute problem. See the migration report.
Somehow, even in 2026, people are still missing the best way to find airdrops, so we finally wrote it down.
3. FomoPeek: The iPhone App Linked to Nearly $580K in Theft
FomoPeek is an iOS app whose malicious versions were distributed through Apple’s App Store. According to SlowMist’s investigation, those versions contained code designed to exploit iOS vulnerabilities and reach sensitive information outside the app’s own storage.
That makes this case particularly nasty. A user didn’t need to open a suspicious website first. SlowMist says the malicious framework loaded when the app launched, with a remote server controlling exploitation and data collection.
Which FomoPeek Versions Were Affected?
SlowMist identified versions 1.1 and 1.2, released on September 9 and September 12, as affected. Version 1.3, released September 17, removed the malicious components identified in the investigation.
The framework included eight attack methods and claimed compatibility across a broad range of iOS releases. That declared support should not be confused with proof that every listed version or device was successfully compromised.
Investigators working with OKX’s security team found a target configuration naming 19 wallet and notes apps. Those included MetaMask, Trust Wallet, SafePal, OKX Wallet, and Apple Notes.
SlowMist demonstrated that the framework could collect application data in a controlled environment, including data from Apple Notes. However, that does not prove every named wallet had a seed phrase or private key extracted.
The firm’s onchain tracing identified a main attacker address that received approximately 579,984 USDT. Funds moved across multiple networks before being consolidated and routed onward.
What Should Affected Users Do?
SlowMist advises users who installed FomoPeek 1.1 or 1.2 to treat potentially exposed wallet credentials as compromised. Its recommendation is to create a fresh wallet on an unaffected device and transfer assets there.
Simply deleting the app cannot erase information an attacker already copied. Neither can updating to a later version. If the seed was exposed, importing that same seed into a different wallet app doesn’t solve the problem either.
The uncomfortable lesson here is that an App Store listing cannot guarantee an app is harmless. Your download habits matter just as much as the transactions you sign.
4. Zcash Clears $1,600, but Old Sprout Funds Need Attention
As someone who’s been DCAing into ZEC, I’ve obviously enjoyed this part of the market. Zcash pushed above $1,600 this week, while 21Shares added another route for traditional investors to get exposure.
The issuer launched a physically backed Zcash ETP on Euronext Paris and Amsterdam, alongside an ETHFI product. The Zcash product carries a 2.5% annual fee, according to the 21Shares factsheet.
That’s broader access through brokerage accounts, although access alone doesn’t tell us how much demand will follow. The rally has also brought plenty of attention and leverage. Enjoying a position and chasing every green candle are very different decisions.
For longtime holders, there’s a more practical issue than the price: ZEC sitting in the legacy Sprout shielded pool could become unspendable under the proposed NU7 changes.
What the Sprout Proposal Would Change
ZIP 2003 proposes disabling version 4 transactions, the older format needed to spend Sprout funds. If adopted and activated, that would leave any remaining Sprout balance without a supported way to move.
The coins would not be burned. However, future access is not guaranteed, and holders could be unable to spend them indefinitely.
This warning applies specifically to Sprout funds, rather than every Zcash wallet or shielded balance. If you have an old wallet backup gathering dust, check what it actually holds before assuming you’re unaffected.
The reported NU7 timeline targets an October 6 testnet activation, an October 20 decision on proceeding, and a possible November 5 mainnet activation. Those are planned milestones, not a reason to wait until November to investigate an old wallet.
Green candles are fun. Discovering that your ancient wallet needs attention the day after an upgrade is considerably less fun.
5. White Hats Secure 52.37 BTC Linked to the Coldcard Exploit
Finally, a security update with some encouraging news.
Galaxy Digital research head Alex Thorn says 52.37 BTC associated with the Coldcard exploit has been consolidated into an address apparently controlled by Crypto Recovery Trust. The finding suggests white hats reached those vulnerable funds before malicious attackers could take them.
According to the reported onchain analysis, the rescued amount represents roughly 2.8% of the exploit total. It also changes how researchers interpret the second wave of wallet sweeps: approximately 40% now appears to have been protective activity.
Another 3.0134 BTC arrived in the same transaction, but Thorn has not confirmed whether it came from the same incident. It should stay outside the confirmed recovery tally for now.
The next challenge is returning the funds. When compromised credentials may be held by both a victim and an attacker, possession of a key cannot settle ownership on its own. Evidence such as exchange withdrawal records, earlier reports, and device forensics may help establish legitimate claims.
These funds appear to have reached protective custody. That is meaningful progress, even though it does not mean victims have already been repaid.
Final Words
September has given us plenty to work with: new chains, farming opportunities, token announcements, and a ZEC chart that’s made checking the portfolio unusually enjoyable.
It has also given attackers a fresh crowd of excited users. The FomoPeek case is a good reason to slow down before installing the next app everyone starts sharing. A few minutes spent checking a download can matter more than catching the next entry.
Stay on top of your airdrop updates. Check those forgotten balances. And if you installed an affected FomoPeek version, make wallet security the priority.
Lock in, anon. Keeping what you earn is part of the job.

Frequently Asked Questions
What is FomoPeek?
FomoPeek is an iOS app linked by SlowMist to a crypto-theft investigation involving nearly $580,000. Researchers identified malicious components in versions 1.1 and 1.2 that could exploit iOS vulnerabilities and access other apps’ data.
Does deleting FomoPeek protect my wallet?
Deleting it cannot undo an earlier theft of sensitive information. SlowMist recommends that affected users treat potentially exposed credentials as compromised and move assets to a newly generated wallet on an unaffected device.
Is FomoPeek connected to the FOMO trading app?
The reporting discussed here does not establish a connection. Similar names are not proof of shared ownership, an affiliation, or an endorsement.
Will Zcash’s NU7 upgrade freeze all ZEC?
No. The proposed spending restriction concerns ZEC remaining in the legacy Sprout pool. It does not apply to all ZEC balances, and activation remains subject to the upgrade process.
Credit: Source link

















