AI disclosure: drafted by Basis Desk's AI newsroom and machine-checked against the primary sources listed below — how we use AI. Originally published on Basis Desk.
A malicious bookmarklet disguised as human verification extracted login tokens and stole roughly $48,000 from a Fomo user.
Key points
- A Fomo user lost roughly $48,000 after following a fake verification prompt linked from a MOONLET token page [1].
- The attack used a malicious bookmarklet to siphon session tokens and Privy embedded-wallet data directly from browser storage [1].
- No private key input, seed phrase disclosure, or on-chain transaction approval was required to execute the theft [1].
A malicious bookmark phishing campaign targeting users of the Fomo web platform drained approximately $48,000 from a victim without requiring any on-chain wallet signatures or seed phrase inputs, according to a threat intelligence report published by SlowMist on Oct. 8 [1].
The incident began when a user viewing the MOONLET token details page on Fomo clicked an external project website link pointing to voltage.family [1]. Upon visiting the site, the platform presented a fake human verification prompt directing the visitor to locate a specific icon, drag it to their browser bookmark bar, and click it three times [1]. Instead of a legitimate verification mechanism, the added item contained an executable JavaScript bookmarklet [1]. Because the victim had authenticated into Fomo using Google and lacked two-factor authentication, the attacker exploited the bookmarklet to run code inside the user's active session [1].
Credential Extraction and Embedded Wallet Hijacking
SlowMist reported that the compressed bookmarklet script scanned the browser's localStorage, sessionStorage, and IndexedDB environments for target strings, specifically looking for credentials associated with embedded wallet provider Privy alongside keywords like seed, secret, and turnkey [1]. After extracting active authorization tokens and refresh tokens, the malicious script attempted to query Privy authentication endpoints, establish time-based one-time passwords (TOTP), and siphon keys through a hidden iframe [1]. The user never connected an external wallet or authorized transactions directly, highlighting risks explored in common crypto scams [1].
SlowMist noted that its MistEye security system has synchronized threat intelligence regarding the domain and attack infrastructure across client monitoring channels [1]. With social engineering tactics shifting toward client-side JavaScript execution, decentralized applications relying on embedded web wallets remain sensitive to external link hygiene and mandatory multi-factor authentication controls [1].
FAQ
How did the malicious bookmark compromise the wallet without a signature?
The bookmark contained JavaScript that ran in the browser context of the target domain, extracting Privy login and session tokens stored in localStorage and IndexedDB to hijack the account directly.
Did the victim enter their private keys or seed phrase?
No. The victim never connected an external wallet, signed an on-chain transaction, or entered a seed phrase or private key.
Sources
- Threat Intelligence | Analysis of a Malicious Bookmark Phishing Attack Targeting Fomo Users — SlowMist
Basis Desk is a source-verified crypto newsroom. Market data, a free MCP server for AI agents and JSON APIs: basisdesk.news/developers. Not investment advice.
Top comments (0)