深潮TechFlow
深潮TechFlow|Oct 08, 2026 02:30
[SlowMist Yu Jian: Beware of Bookmark Phishing Attacks Targeting FOMO Web Clients] Deep Tide TechFlow reports, on October 8th, according to SlowMist founder Cos (Yu Jian) (@evilcos), a new bookmark phishing attack method targeting FOMO web clients has recently emerged. Attackers create fake CAPTCHA verification pages to lure users into dragging malicious JavaScript code into their browser bookmarks, forming a 'bookmark.' After users click on this bookmark two to three times, their previously logged-in FOMO accounts are hijacked, and the crypto assets within the accounts are stolen. This method essentially exploits an old technique targeting @privy_io. Since the bookmark executes JavaScript under FOMO's own domain, logged-in sessions are directly exposed without requiring users to click on phishing links. Currently, relevant samples and the attackers' wallet addresses have been retained, and the SlowMist team will provide detailed disclosures later. Security Tip: Any operation that asks you to 'drag code into bookmarks' is phishing behavior—do not execute it. If you have already fallen victim, in addition to immediately transferring your assets, you must forcibly log out all sessions of your FOMO account. Simply changing your password will not resolve the issue.
+2
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads