SlowMist Traces Fomo Phishing Attack to Malicious Bookmark

Semi-realistic browser window with a bookmarklet icon triggering a fake CAPTCHA and a warning shield

SlowMist has detailed a phishing campaign targeting users of the Fomo web platform through malicious browser bookmarks, showing how an attacker can compromise an authenticated crypto session without obtaining a seed phrase or prompting an on-chain approval. The attack relies on persuading the victim to execute JavaScript inside an already logged-in Fomo page, turning the browser itself into the delivery mechanism for credential theft.

The investigation began after a Fomo user reported losing about $48,000 while viewing the MOONLET token. According to SlowMist, the victim followed a project website link displayed on Fomo to voltage.family, where a fake human-verification process instructed them to drag an icon into the browser’s bookmark bar and click it three times. What appeared to be a CAPTCHA step actually installed a JavaScript bookmarklet designed to execute within Fomo’s authenticated browser context.

Bookmarklet Targets Privy Session Credentials

SlowMist’s script analysis found that the bookmarklet collected Privy access and refresh tokens alongside browser-storage and wallet-related information. The payload gathered data from localStorage and IndexedDB and included logic involving MFA information before transmitting the resulting dataset to attacker-controlled infrastructure. The immediate security boundary was the authenticated browser session and its locally stored credentials, rather than the underlying blockchain or a conventional smart-contract exploit.

That distinction also means the incident should not automatically be described as a vulnerability in Fomo or Privy. The attack required the victim to add and execute attacker-supplied JavaScript, although doing so allowed the code to operate within the trusted origin of the logged-in application. SlowMist said the stolen credentials could potentially enable wallet takeover, private-key recovery or unauthorized transactions, while the precise mechanism used to complete the asset transfer remained under investigation.

The technique is not new. SlowMist has documented malicious bookmark phishing in earlier security research, including cases where JavaScript executed inside logged-in browser sessions to steal authentication tokens. The attack fits a wider shift toward compromising the client-side environment, also visible in incidents such as the Trust Wallet Chrome extension compromise. In both models, trusted browser functionality becomes part of the attack surface even though the underlying blockchain continues operating normally.

SlowMist Traces Funds Across Solana and Privacy Tools

In a subsequent SlowMist tracing update, the security firm said its MistTrack analysis identified repeated USDC-to-SOL conversions, address splitting, cross-chain transfers and deposits into Privacy Cash and gambling-related platforms. The observed fund movement extended the investigation from credential compromise into post-theft asset routing.

One address examined by SlowMist deposited a cumulative 1,568.33 SOL into the Privacy Cash pool. The firm also documented transfers involving Stake and Winna, including 11.34 SOL and 1,500 USDC sent to Winna-associated addresses. Those larger wallet flows should not be equated with the approximately $48,000 reported stolen from the identified Fomo victim, because SlowMist’s tracing describes broader activity associated with the investigated address rather than establishing that every asset originated from the same compromise.

The episode also illustrates a security tradeoff surrounding embedded wallets and browser-based financial applications. Privy infrastructure is used across other crypto products, including the embedded wallet architecture behind Nansen’s on-chain trading interface, but self-custody or embedded-wallet design does not eliminate risks at the application and session layers. Protecting private keys is only one part of the threat model when authenticated browser credentials can themselves authorize access to financial functionality.

The social-engineering element is equally important. Crypto attackers have increasingly targeted trusted user workflows rather than exclusively searching for protocol vulnerabilities, a pattern also seen in fake video-conference campaigns used to compromise crypto wallets. In the Fomo case, no sophisticated blockchain exploit was required: the critical action was convincing a user that executing unfamiliar browser code was part of a legitimate verification process.

Find Us on Socials

Join Our
Newsletter

Subscribe to get latest crypto news!

Latest News

You may also like

The Chain Observer
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.