Security experts at SlowMist have identified a sophisticated new phishing technique targeting users of the FOMO web-side platform. According to monitoring data released by SlowMist founder Cosine on October 8, 2026, attackers are utilizing deceptive bookmark-based JavaScript execution to hijack active accounts. The scheme specifically targets the psychological urgency of cryptocurrency traders to gain unauthorized access to digital asset wallets and drain funds.
Mechanism of the Fake CAPTCHA Attack
The attack begins when a user visits a fraudulent website designed to mimic a legitimate cryptocurrency service. These phishing pages prompt the visitor to complete a fake CAPTCHA verification process. Instead of a standard security check, the interface instructs the user to drag a specific button or element into their browser’s favorites bar.
This action essentially saves a "bookmarklet" containing malicious JavaScript code directly into the user's browser environment.
The attack relies on a multi-step interaction:
- The user is lured to a malicious FOMO-themed phishing page.
- A deceptive prompt induces the saving of a malicious bookmark.
- The user is later prompted to click the bookmark 2 to 3 times while on a legitimate or targeted page.
- The script executes, capturing the session cookies or authorization tokens of the logged-in FOMO account.
Asset Theft and Account Hijacking
Once the user interacts with the bookmark as instructed, the embedded code bypasses standard browser security boundaries by executing within the context of the active session. Attackers gain immediate control over the victim's FOMO account. According to security reports, the perpetrators move quickly to transfer encrypted assets to external addresses controlled by the malicious actors, often leaving the victim with no recourse once the transaction is broadcast to the blockchain.
"These phishing pages induce users to complete fake CAPTCHA verification, dragging malicious JavaScript code into the browser's favorites and saving it as a bookmark... previously logged-in FOMO accounts will be hijacked", SlowMist reported.
To mitigate these risks, investors are advised to scrutinize any request to add bookmarks or run scripts within their browser. Users should ensure that Two-Factor Authentication (2FA) is active on all platforms and avoid interacting with unconventional "verification" methods that require manual changes to browser settings. As the Web3 security landscape evolves, maintaining a high level of technical vigilance remains the most effective defense against social engineering tactics.
Frequently Asked Questions
Quick answers to the most common questions about this topic.