---
title: "SlowMist Uncovers Bookmark Phishing Scheme Draining Embedded Wallets on Fomo"
description: "A malicious bookmarklet disguised as human verification extracted login tokens and stole roughly $48,000 from a Fomo user."
url: https://basisdesk.news/news/slowmist-fomo-bookmark-phishing-privy
published: 2026-10-08T11:21:15.003Z
modified: 2026-10-08T11:21:15.003Z
section: Security & Hacks
author: Basis Desk Newsroom (AI-generated, source-verified)
sentiment: bearish
tickers: []
tags: [phishing, slowmist, fomo, privy, embedded-wallets, cybersecurity]
license: Quote with attribution to Basis Desk (basisdesk.news). Not financial advice.
---

# SlowMist Uncovers Bookmark Phishing Scheme Draining Embedded Wallets on Fomo

A malicious bookmarklet disguised as human verification extracted login tokens and stole roughly $48,000 from a Fomo user.

## At a glance

- **What happened:** SlowMist reported a bookmarklet phishing attack on Fomo that drained approximately $48,000 in assets by stealing embedded wallet session tokens.
- **Why it matters:** The attack bypassed traditional Web3 protections without requiring on-chain approvals, seed phrases, or external wallet connections.
- **Who is affected:** Fomo users navigating external token website links, particularly those using embedded wallets without two-factor authentication.
- **What's next:** SlowMist synchronized threat alerts via its MistEye intelligence feeds as web platforms review third-party link risks.
- **Primary source:** [Threat Intelligence | Analysis of a Malicious Bookmark Phishing Attack Targeting Fomo Users](https://slowmist.medium.com/threat-intelligence-analysis-of-a-malicious-bookmark-phishing-attack-targeting-fomo-users-0985bff1ed36?source=rss-4ceeedda40e8------2) — SlowMist

## Key points

- A Fomo user lost roughly $48,000 after following a fake verification prompt linked from a MOONLET token page [1].
- The attack used a malicious bookmarklet to siphon session tokens and Privy embedded-wallet data directly from browser storage [1].
- No private key input, seed phrase disclosure, or on-chain transaction approval was required to execute the theft [1].

## Editorial remark

- **Context:** Attackers are increasingly deploying browser-based bookmarklet techniques to bypass Web3 security checks by executing malicious scripts directly in authenticated web sessions.
- **Impact:** Users of embedded web wallets without two-factor authentication risk having their access tokens and session stores scraped through malicious external links.
- **Watch:** Platform remediations on token directory links and further threat indicator feeds deployed by SlowMist's MistEye system.

A malicious bookmark phishing campaign targeting users of the Fomo web platform drained approximately $48,000 from a victim without requiring any on-chain wallet signatures or seed phrase inputs, according to a threat intelligence report published by SlowMist on Oct. 8 [1].

The incident began when a user viewing the MOONLET token details page on Fomo clicked an external project website link pointing to voltage.family [1]. Upon visiting the site, the platform presented a fake human verification prompt directing the visitor to locate a specific icon, drag it to their browser bookmark bar, and click it three times [1]. Instead of a legitimate verification mechanism, the added item contained an executable JavaScript bookmarklet [1]. Because the victim had authenticated into Fomo using Google and lacked two-factor authentication, the attacker exploited the bookmarklet to run code inside the user's active session [1].

## Credential Extraction and Embedded Wallet Hijacking

SlowMist reported that the compressed bookmarklet script scanned the browser's `localStorage`, `sessionStorage`, and `IndexedDB` environments for target strings, specifically looking for credentials associated with embedded wallet provider Privy alongside keywords like seed, secret, and turnkey [1]. After extracting active authorization tokens and refresh tokens, the malicious script attempted to query Privy authentication endpoints, establish time-based one-time passwords (TOTP), and siphon keys through a hidden iframe [1]. The user never connected an external wallet or authorized transactions directly, highlighting risks explored in [common crypto scams](https://basisdesk.news/news/common-crypto-scams) [1].

SlowMist noted that its MistEye security system has synchronized threat intelligence regarding the domain and attack infrastructure across client monitoring channels [1]. With social engineering tactics shifting toward client-side JavaScript execution, decentralized applications relying on embedded web wallets remain sensitive to external link hygiene and mandatory multi-factor authentication controls [1].

## FAQ

**How did the malicious bookmark compromise the wallet without a signature?**

The bookmark contained JavaScript that ran in the browser context of the target domain, extracting Privy login and session tokens stored in localStorage and IndexedDB to hijack the account directly.

**Did the victim enter their private keys or seed phrase?**

No. The victim never connected an external wallet, signed an on-chain transaction, or entered a seed phrase or private key.

## Sources

1. [Threat Intelligence | Analysis of a Malicious Bookmark Phishing Attack Targeting Fomo Users](https://slowmist.medium.com/threat-intelligence-analysis-of-a-malicious-bookmark-phishing-attack-targeting-fomo-users-0985bff1ed36?source=rss-4ceeedda40e8------2) — SlowMist, 2026-10-08

---
Basis Desk Newsroom · AI-generated, source-verified · https://basisdesk.news/about/how-we-use-ai
