SlowMist|Oct 08, 2026 12:20
🔍 In a recent investigation, SlowMist analyzed a malicious bookmark #phishing attack targeting @fomo users and uncovered a fake “human verification” page designed to execute malicious JavaScript in the context of a logged-in Fomo page.
Victims were instructed to identify an icon, drag it to the browser bookmarks bar, and click the bookmark three times.
The malicious bookmarklet then collected Privy access/refresh tokens, browser storage, IndexedDB data, and wallet-related information, while also containing logic related to MFA/TOTP.
🕵️ Using @MistTrack_io , we traced the stolen funds and found a complex flow involving repeated USDC/SOL swaps, multi-address splitting, cross-chain transfers, and deposits to Privacy Cash and gambling platforms.
🛡️ Security tip: Legitimate human verification should not require dragging an icon to the bookmarks bar and clicking it on a wallet or trading page. Stop immediately if you encounter such a request. Regularly check your bookmarks, enable MFA, and revoke abnormal sessions from a trusted device if you have executed a suspicious bookmark.
📖 Read the full analysis:
https://slowmist.medium.com/threat-intelligence-analysis-of-a-malicious-bookmark-phishing-attack-targeting-fomo-users-0985bff1ed36
Share To
HotFlash
APP
X
Telegram
CopyLink