Skip to content
FOMO Bookmark Phishing Attack Drains Crypto via Malicious Ja

FOMO Bookmark Phishing Attack Drains Crypto via Malicious Ja

Phemex • October 8, 2026

A new bookmark phishing attack is targeting users of the FOMO web platform, tricking victims into dragging malicious JavaScript code into their browser bookmarks under the guise of a fake CAPTCHA verification. After clicking the compromised bookmark two to three times, attackers hijack active FOMO sessions and immediately drain crypto assets from the account.

Security researchers have documented samples of the phishing pages and preserved associated attacker wallet addresses for further investigation. Users are advised to avoid dragging any code into browser bookmarks during verification processes and to verify the legitimacy of authentication prompts on the FOMO platform.

Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)