1 min read

FOMO Web Users Face Bookmark Phishing Attack That Steals Crypto

Fake human-verification pages install malicious JavaScript in browser bookmarks, allowing attackers to hijack previously logged-in accounts.

A hand hovers over a browser toolbar beside an open wallet / TokenPost.ai
A hand hovers over a browser toolbar beside an open wallet / TokenPost.ai

A bookmark-based phishing attack targeting FOMO’s web interface is hijacking previously logged-in accounts and stealing crypto assets.

The attack begins with a fake human-verification page. Users are prompted to drag malicious JavaScript into their browser’s bookmarks and save it. Clicking the bookmark two or three times can then give attackers control of an account that was already logged in.

Crypto assets held in the compromised account may be stolen immediately after the account is hijacked. The browser-bookmark step is central to the theft process.

The incident highlights the risk of executing unfamiliar JavaScript in a browser, especially through a bookmark or other feature that can run code while a crypto account is open. The warning surfaced Oct. 7 at 9:05 p.m. ET (01:05 UTC Thursday).

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…