SlowMist Cosine: Beware of Bookmark Phishing Attacks Targeting the FOMO Web Interface for Crypto Theft
On October 8, according to SlowMist founder Cos (@evilcos), a bookmark phishing attack targeting the FOMO web platform has recently emerged. Attackers use fake human verification pages to induce users to drag malicious JavaScript code into their browser favorites to form a "bookmark." After clicking this bookmark two or three times, previously logged-in FOMO accounts are hijacked, and the encrypted assets within are subsequently stolen.
This technique is essentially a legacy exploit targeting @privy_io. Since the bookmark executes JS under FOMO's own domain, active sessions are directly exposed without requiring users to click on phishing links. Relevant samples and the attacker's wallet address have been archived, and the SlowMist team will provide detailed disclosures later.
Security Tip:
- Any operation that requires "dragging code into favorites" is a phishing attempt and must not be performed
- If compromised, beyond immediately transferring assets, you must forcibly terminate all sessions of the FOMO account; simply changing the password will not solve the issue