SlowMist has detailed a phishing campaign targeting users of the Fomo web platform through malicious browser bookmarks, showing how an attacker can compromise an authenticated crypto session without obtaining a seed phrase or prompting an on-chain approval. The attack relies on persuading the victim to execute JavaScript inside an already logged-in Fomo page, turning the browser itself into the delivery mechanism for credential theft.
The investigation began after a Fomo user reported losing about $48,000 while viewing the MOONLET token. According to SlowMist, the victim followed a project website link displayed on Fomo to voltage.family, where a fake human-verification process instructed them to drag an icon into the browser’s bookmark bar and click it three times. What appeared to be a CAPTCHA step actually installed a JavaScript bookmarklet designed to execute within Fomo’s authenticated browser context.
🔍 In a recent investigation, SlowMist analyzed a malicious bookmark #phishing attack targeting @fomo users and uncovered a fake “human verification” page designed to execute malicious JavaScript in the context of a logged-in Fomo page.
Victims were instructed to identify an… https://t.co/BNQeHjbAXv
— SlowMist (@SlowMist_Team) October 8, 2026
Bookmarklet Targets Privy Session Credentials
SlowMist’s script analysis found that the bookmarklet collected Privy access and refresh tokens alongside browser-storage and wallet-related information. The payload gathered data from localStorage and IndexedDB and included logic involving MFA information before transmitting the resulting dataset to attacker-controlled infrastructure. The immediate security boundary was the authenticated browser session and its locally stored credentials, rather than the underlying blockchain or a conventional smart-contract exploit.
That distinction also means the incident should not automatically be described as a vulnerability in Fomo or Privy. The attack required the victim to add and execute attacker-supplied JavaScript, although doing so allowed the code to operate within the trusted origin of the logged-in application. SlowMist said the stolen credentials could potentially enable wallet takeover, private-key recovery or unauthorized transactions, while the precise mechanism used to complete the asset transfer remained under investigation.
The technique is not new. SlowMist has documented malicious bookmark phishing in earlier security research, including cases where JavaScript executed inside logged-in browser sessions to steal authentication tokens. The attack fits a wider shift toward compromising the client-side environment, also visible in incidents such as the Trust Wallet Chrome extension compromise. In both models, trusted browser functionality becomes part of the attack surface even though the underlying blockchain continues operating normally.
SlowMist Traces Funds Across Solana and Privacy Tools
In a subsequent SlowMist tracing update, the security firm said its MistTrack analysis identified repeated USDC-to-SOL conversions, address splitting, cross-chain transfers and deposits into Privacy Cash and gambling-related platforms. The observed fund movement extended the investigation from credential compromise into post-theft asset routing.
One address examined by SlowMist deposited a cumulative 1,568.33 SOL into the Privacy Cash pool. The firm also documented transfers involving Stake and Winna, including 11.34 SOL and 1,500 USDC sent to Winna-associated addresses. Those larger wallet flows should not be equated with the approximately $48,000 reported stolen from the identified Fomo victim, because SlowMist’s tracing describes broader activity associated with the investigated address rather than establishing that every asset originated from the same compromise.
The episode also illustrates a security tradeoff surrounding embedded wallets and browser-based financial applications. Privy infrastructure is used across other crypto products, including the embedded wallet architecture behind Nansen’s on-chain trading interface, but self-custody or embedded-wallet design does not eliminate risks at the application and session layers. Protecting private keys is only one part of the threat model when authenticated browser credentials can themselves authorize access to financial functionality.
The social-engineering element is equally important. Crypto attackers have increasingly targeted trusted user workflows rather than exclusively searching for protocol vulnerabilities, a pattern also seen in fake video-conference campaigns used to compromise crypto wallets. In the Fomo case, no sophisticated blockchain exploit was required: the critical action was convincing a user that executing unfamiliar browser code was part of a legitimate verification process.