Skip to content
Basis Desk

New: Basis Desk Verify for Chrome — fact-check crypto news on any page, free.Add to Chrome →

Security & Hacks · 1 min read

SlowMist Uncovers Bookmark Phishing Scheme Draining Embedded Wallets on Fomo

A malicious bookmarklet disguised as human verification extracted login tokens and stole roughly $48,000 from a Fomo user.

Editorial oversight: Julian Mercer, Chief Editor
Bearish

At a glance

What happened
SlowMist reported a bookmarklet phishing attack on Fomo that drained approximately $48,000 in assets by stealing embedded wallet session tokens.
Why it matters
The attack bypassed traditional Web3 protections without requiring on-chain approvals, seed phrases, or external wallet connections.
Who is affected
Fomo users navigating external token website links, particularly those using embedded wallets without two-factor authentication.
What's next
SlowMist synchronized threat alerts via its MistEye intelligence feeds as web platforms review third-party link risks.
Primary source
SlowMist: Threat Intelligence | Analysis of a Malicious Bookmark Phishing Attack Targeting Fomo Users

Key points

  • A Fomo user lost roughly $48,000 after following a fake verification prompt linked from a MOONLET token page 1.
  • The attack used a malicious bookmarklet to siphon session tokens and Privy embedded-wallet data directly from browser storage 1.
  • No private key input, seed phrase disclosure, or on-chain transaction approval was required to execute the theft 1.

A malicious bookmark phishing campaign targeting users of the Fomo web platform drained approximately $48,000 from a victim without requiring any on-chain wallet signatures or seed phrase inputs, according to a threat intelligence report published by SlowMist on Oct. 8 1.

The incident began when a user viewing the MOONLET token details page on Fomo clicked an external project website link pointing to voltage.family 1. Upon visiting the site, the platform presented a fake human verification prompt directing the visitor to locate a specific icon, drag it to their browser bookmark bar, and click it three times 1. Instead of a legitimate verification mechanism, the added item contained an executable JavaScript bookmarklet 1. Because the victim had authenticated into Fomo using Google and lacked two-factor authentication, the attacker exploited the bookmarklet to run code inside the user's active session 1.

Credential Extraction and Embedded Wallet Hijacking

SlowMist reported that the compressed bookmarklet script scanned the browser's localStorage, sessionStorage, and IndexedDB environments for target strings, specifically looking for credentials associated with embedded wallet provider Privy alongside keywords like seed, secret, and turnkey 1. After extracting active authorization tokens and refresh tokens, the malicious script attempted to query Privy authentication endpoints, establish time-based one-time passwords (TOTP), and siphon keys through a hidden iframe 1. The user never connected an external wallet or authorized transactions directly, highlighting risks explored in common crypto scams 1.

SlowMist noted that its MistEye security system has synchronized threat intelligence regarding the domain and attack infrastructure across client monitoring channels 1. With social engineering tactics shifting toward client-side JavaScript execution, decentralized applications relying on embedded web wallets remain sensitive to external link hygiene and mandatory multi-factor authentication controls 1.

Questions this story raises

How did the malicious bookmark compromise the wallet without a signature?
The bookmark contained JavaScript that ran in the browser context of the target domain, extracting Privy login and session tokens stored in localStorage and IndexedDB to hijack the account directly.
Did the victim enter their private keys or seed phrase?
No. The victim never connected an external wallet, signed an on-chain transaction, or entered a seed phrase or private key.

Sources

  1. [1] Threat Intelligence | Analysis of a Malicious Bookmark Phishing Attack Targeting Fomo Users — SlowMist, October 8, 2026

Written by Basis Desk's newsroom system from the primary sources above and machine-verified against them before publication. Market figures marked "at the time of writing" come from live exchange data. Report an error: corrections@basisdesk.news · corrections policy.

Community read
How do you read this story for the assets involved? One vote a day, anonymous.
Be the first to vote

The Daily Brief, in your inbox at 07:00 ET

Five stories, the numbers that moved, what to watch. Three minutes. No hype, no advice, unsubscribe in one click.

Not financial advice. Basis Desk publishes information, not recommendations. Crypto assets are volatile and you can lose what you invest.