Skip to content
Bookmark Phishing Attack Targets FOMO Users

Bookmark Phishing Attack Targets FOMO Users

First seen 8 Oct 2026, 13:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 14:31 UTC
  • •FOMO users are targeted by a bookmark phishing attack that drains crypto assets.
  • •Attackers use fake CAPTCHA prompts to trick users into activating malicious bookmarks.
  • •Security researchers are documenting the phishing pages and attacker wallet addresses.

FOMO users are facing a new phishing threat involving malicious bookmarks that hijack accounts. Attackers trick users into dragging JavaScript code into their bookmarks under the pretense of completing a CAPTCHA verification. Once activated, these bookmarks can drain crypto assets from the compromised accounts after a few clicks. Security researchers have documented the phishing pages and associated wallet addresses for investigation. Users are advised to be cautious and verify the legitimacy of authentication prompts on the FOMO platform. The phishing method exploits the growing sophistication of online threats, particularly in the crypto space. As of now, trading volumes on FOMO are reported to be at zero, indicating a potential decline in user confidence amidst these security alerts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-08
Phishing attack reported
SlowMist alerts FOMO users about a bookmark-based phishing attack that can hijack accounts and drain assets.
Coinfomania
2026-10-08
Security research published
Phemex reports on the phishing method and advises users to avoid dragging code into bookmarks during verification.
Phemex

More articles in this cluster (2)

Common questions

How does the phishing attack work?
Attackers use fake CAPTCHA prompts to trick users into dragging malicious JavaScript code into their bookmarks, which can hijack their sessions.
What should FOMO users do to protect themselves?
Users should avoid dragging any code into bookmarks during verification processes and verify the legitimacy of prompts on the FOMO platform.
Is there any ongoing investigation into this attack?
Yes, security researchers are documenting the phishing pages and associated attacker wallet addresses for further investigation.