October 09, 2026

A fake verification step can move the attack surface into an already authenticated browser page. In this case, the decisive analytical distinction is between evidence of a malicious bookmark, evidence of token transfers, and proof of how those transfers were authorized. Those are related questions, but they are not interchangeable.
Our direct explorer review identified three USDC transfers from one source owner to the recipient named in SlowMist's original technical analysis. They total exactly 45,106.851598 USDC and span 63 seconds. That matches the reported 45,106.85 USDC total when rounded to two decimal places. The match makes them strong candidate incident anchors; it does not independently establish the source wallet owner's identity or the victim's consent.
Measure | Value / interpretation |
|---|---|
Network | Solana |
Candidate inbound total | 45,106.851598 USDC; three unique successful transactions |
Candidate transfer window | 2026-10-04 08:58:45–08:59:48 UTC |
Review cutoff | 2026-10-09 00:32 UTC; historical transaction snapshots, not a complete chain audit |
Public loss report | Approximately $48,000 in assets, as relayed by SlowMist; not equated with the exact USDC subtotal |
Independent victim confirmation | Not obtained; attribution remains a documented candidate match |
The review deduplicates by transaction signature and counts only the single USDC transfer in each candidate transaction. SOL network fees are recorded separately and are not added to the USDC amount. Address-wide activity is kept outside the candidate incident subtotal.
Question: can the reported three withdrawals be distinguished from the recipient's other inflows? The three transactions below share the same source owner, destination owner, USDC mint and decoded transferChecked method. Their exact sum, count and destination fit the public report. The source wallet is therefore an investigative candidate, not a newly identified person.
UTC on 4 October | USDC transferred | Evidence |
|---|---|---|
08:58:45 | 32652.960737 | |
08:59:23 | 5002.490046 | |
08:59:48 | 7451.400815 |
The arithmetic is 32,652.960737 + 5,002.490046 + 7,451.400815 = 45,106.851598 USDC. The 0.001598 USDC difference from the two-decimal public figure is rounding, not a separately identified transfer. What remains uncertain is independent confirmation that these exact signatures correspond to the reported victim's withdrawals.

Figure 1. Directly checked candidate transfers. A dashed co-signer panel is an authorization observation, not a money-flow edge. Downstream attribution is deliberately not shown.
Question: does the chain tell us whether an attacker exported a key or requested remote signing? Each candidate transaction lists the source owner and a second signer that Solscan labels “Fomo Co-signer.” That is evidence about transaction signers and a provider label, not proof of who initiated the request, which authentication material was used, or whether any signing service was compromised.
Role | Public address / account |
|---|---|
Source owner / transfer authority | |
Second signer; Solscan label “Fomo Co-signer” | |
Source USDC token account | |
Destination USDC token account | |
Destination owner named by SlowMist |
The owner-level explorer summary and the decoded instruction describe different layers: the summary resolves wallet owners, whereas the instruction names the SPL token accounts being debited and credited. A token account must not be presented as a separate attacker wallet merely because it has a different address.
Question: can an address-wide service exposure be treated as this victim's recovered path? A separate successful transaction sends 212.492295 SOL from the named collection owner to a pool Solscan labels Privacy Cash Pool on 5 October at 07:46:10 UTC. This directly supports an address-to-pool transfer. It does not by itself show that those SOL were purchased with the three candidate USDC transfers.
Observation | Evidence / limit |
|---|---|
Transaction | 4YM1bkC7UjJwLX8zc6FgPbg7yFViDLQfo2hgJ8u9iGAjDDxFv9crdwJ1JkZurmE13JsD56CneJibLtvekoieT3Mx |
Amount and UTC | 212.492295 SOL; 2026-10-05 07:46:10 UTC |
Pool destination | |
Program | |
Attribution boundary | Address-history evidence only. No independently reconciled route from candidate USDC anchors yet. |
SlowMist's reported 1,568.33 SOL cumulative Privacy Cash outflow concerns the address's history. It is not substituted for the incident's 45,106.85 USDC subtotal, nor independently reproduced by the single transaction checked here. The intervening swaps, balances and other inflows must be reconciled before assigning a victim-specific downstream amount.
According to SlowMist's original technical analysis, a token-page link led to a fake human-verification page that prompted a bookmark action. The saved JavaScript then ran in the logged-in FOMO context and targeted browser storage, IndexedDB and Privy session material. We did not execute the malicious sample or connect to its collection endpoint.

Figure 2. Source-based mechanism reconstruction, not an independently replayed exploit or transaction trace. The unresolved signing step is dashed.
The useful security conclusion is narrower than “a wallet connection stole the funds”: the described lure sought code execution within a trusted application session. Conversely, the source's conditional MFA logic and the victim's reported absence of 2FA do not establish a demonstrated MFA bypass. Initiating an enrollment flow would also not prove successful enrollment.
UTC | Event and evidence level |
|---|---|
2026-10-04 08:58:45 | A01: 32,652.960737 USDC, directly checked |
2026-10-04 08:59:23 | A02: 5,002.490046 USDC, directly checked |
2026-10-04 08:59:48 | A03: 7,451.400815 USDC, directly checked |
2026-10-05 07:46:10 | T01: 212.492295 SOL to provider-labeled Privacy Cash pool; separate address history |
2026-10-08 | SlowMist public alert and analysis; not the attack date |
The attack's initial browser-execution time is not established here. The collection address's reported first activity on 17 September is not assigned as the incident start time.
The three-transfer match could be strengthened by an original withdrawal record or source confirmation naming the signatures. A transaction's valid signatures do not reveal whether the human account owner approved it. Application-side authentication, session revocation, withdrawal and signing logs would be needed to test competing key-export and remote-signing explanations.
For downstream analysis, identical asset values or nearby timestamps are insufficient to prove a bridge connection. A defensible cross-chain edge requires a source transaction, bridge order or fulfillment record, and destination transaction. Ethereum and Bitcoin candidates mentioned by the source remain external leads until that chain of evidence is available; they are not drawn as verified branches here.
For the affected account, preserve the bookmark URL and browser/session chronology without executing the bookmark again. Application operators can correlate the three candidate signatures with withdrawal requests and signing-policy decisions, then evaluate session and refresh-token revocation. A password change alone should not be assumed to invalidate every previously issued session artifact.
For investigators, preserve the full source/destination token-account mapping and block references before expanding a cluster. For any service request, provide the specific transaction and account history being queried, and distinguish the verified transfer from a claim about stolen-fund ownership. Provider labels are leads for corroboration, not legal identity findings.
ID / slot | Full transaction signature |
|---|---|
A01 Solana slot 453209474 | 44uGoQH6KQRyVDCLuDTUHW3KxR61j9pGnnWWKoGtWFh9b3jUFRQ9t5MMVHoFr5ZWFLgEgWKmgxuR5Wq8tS36XkzN |
A02 Solana slot 453209617 | 4pgANnxQ2Q5139ToXuc7LvHWqBZKKsBXwAVKA4eSi1wLnYdpukbgL2ZheTxXAMevU84HVKJCe1TBTTZ1VN2TZrH9 |
A03 Solana slot 453209712 | xM1eCwjwhV4h9ECr2dTpL4TTDq3YafKiME3qyJcCAiLM3iqZosCVSW3rdQPcUr8AXWhzDrJzd4JKDZDWBJ6q4KM |
T01 Solana slot 453515871 | 4YM1bkC7UjJwLX8zc6FgPbg7yFViDLQfo2hgJ8u9iGAjDDxFv9crdwJ1JkZurmE13JsD56CneJibLtvekoieT3Mx |
Token / technical property | Value |
|---|---|
USDC mint | |
Candidate instruction | SPL Token Program transferChecked |
Per-candidate fee | 0.00001507 SOL; separate from USDC principal |
Source basis | |
Reproducibility limit | Explorer-decoded detail checked; no raw RPC replay, victim-account access or complete downstream reconciliation claimed |
This report separates directly observed chain transactions, explorer-provided labels, external reporting and analytical inference. It does not identify an attacker or attribute every historical recipient transaction to this case.
11 reads