Community Investigation

FOMO Bookmark Phishing: Three Transfers Match the Reported 45,106.85 USDC Withdrawal Total

Philippark
Philippark

October 09, 2026

FOMO Bookmark Phishing — original Fomo and Solana logos on a white ChainBounty investigation cover

A fake verification step can move the attack surface into an already authenticated browser page. In this case, the decisive analytical distinction is between evidence of a malicious bookmark, evidence of token transfers, and proof of how those transfers were authorized. Those are related questions, but they are not interchangeable.

Our direct explorer review identified three USDC transfers from one source owner to the recipient named in SlowMist's original technical analysis. They total exactly 45,106.851598 USDC and span 63 seconds. That matches the reported 45,106.85 USDC total when rounded to two decimal places. The match makes them strong candidate incident anchors; it does not independently establish the source wallet owner's identity or the victim's consent.

Scope and evidence boundary

Measure

Value / interpretation

Network

Solana

Candidate inbound total

45,106.851598 USDC; three unique successful transactions

Candidate transfer window

2026-10-04 08:58:45–08:59:48 UTC

Review cutoff

2026-10-09 00:32 UTC; historical transaction snapshots, not a complete chain audit

Public loss report

Approximately $48,000 in assets, as relayed by SlowMist; not equated with the exact USDC subtotal

Independent victim confirmation

Not obtained; attribution remains a documented candidate match

The review deduplicates by transaction signature and counts only the single USDC transfer in each candidate transaction. SOL network fees are recorded separately and are not added to the USDC amount. Address-wide activity is kept outside the candidate incident subtotal.

Three findings that matter

1. The reported withdrawal total has a specific, reproducible candidate match

Question: can the reported three withdrawals be distinguished from the recipient's other inflows? The three transactions below share the same source owner, destination owner, USDC mint and decoded transferChecked method. Their exact sum, count and destination fit the public report. The source wallet is therefore an investigative candidate, not a newly identified person.

UTC on 4 October

USDC transferred

Evidence

08:58:45

32652.960737

A01: transaction detail

08:59:23

5002.490046

A02: transaction detail

08:59:48

7451.400815

A03: transaction detail

The arithmetic is 32,652.960737 + 5,002.490046 + 7,451.400815 = 45,106.851598 USDC. The 0.001598 USDC difference from the two-decimal public figure is rounding, not a separately identified transfer. What remains uncertain is independent confirmation that these exact signatures correspond to the reported victim's withdrawals.

Candidate USDC transfer map separating wallet owners, token accounts and co-signing from the transfer path

Figure 1. Directly checked candidate transfers. A dashed co-signer panel is an authorization observation, not a money-flow edge. Downstream attribution is deliberately not shown.

2. A co-signer label does not resolve the compromise mechanism

Question: does the chain tell us whether an attacker exported a key or requested remote signing? Each candidate transaction lists the source owner and a second signer that Solscan labels “Fomo Co-signer.” That is evidence about transaction signers and a provider label, not proof of who initiated the request, which authentication material was used, or whether any signing service was compromised.

Role

Public address / account

Source owner / transfer authority

6R6stpcbSij7scSpD7Refq1eap2gN1Qj3omFeGu3gJPc

Second signer; Solscan label “Fomo Co-signer”

AgmLJBMDCqWynYnQiPCuj9ewsNNsBJXyzoUhD9LJzN51

Source USDC token account

BcxGQtcyAgX1VrM8sS94aMbFridPqkJ3u8qQx4e4X3Pg

Destination USDC token account

EpAjLMVnttREdDiXGddym5eYgsn5hH2oPPnQcarTKajM

Destination owner named by SlowMist

D783JqupQ2FYhkxUfGEd1gaFEoAJDXRX1NEb4aVH2hZ6

The owner-level explorer summary and the decoded instruction describe different layers: the summary resolves wallet owners, whereas the instruction names the SPL token accounts being debited and credited. A token account must not be presented as a separate attacker wallet merely because it has a different address.

3. A Privacy Cash transfer is verified; its victim attribution is not

Question: can an address-wide service exposure be treated as this victim's recovered path? A separate successful transaction sends 212.492295 SOL from the named collection owner to a pool Solscan labels Privacy Cash Pool on 5 October at 07:46:10 UTC. This directly supports an address-to-pool transfer. It does not by itself show that those SOL were purchased with the three candidate USDC transfers.

Observation

Evidence / limit

Transaction

4YM1bkC7UjJwLX8zc6FgPbg7yFViDLQfo2hgJ8u9iGAjDDxFv9crdwJ1JkZurmE13JsD56CneJibLtvekoieT3Mx

Amount and UTC

212.492295 SOL; 2026-10-05 07:46:10 UTC

Pool destination

4AV2Qzp3N4c9RfzyEbNZs2wqWfW4EwKnnxFAZCndvfGh

Program

9fhQBbumKEFuXtMBDw8AaQyAjCorLGJQiS3skWZdQyQD

Attribution boundary

Address-history evidence only. No independently reconciled route from candidate USDC anchors yet.

SlowMist's reported 1,568.33 SOL cumulative Privacy Cash outflow concerns the address's history. It is not substituted for the incident's 45,106.85 USDC subtotal, nor independently reproduced by the single transaction checked here. The intervening swaps, balances and other inflows must be reconciled before assigning a victim-specific downstream amount.

How the bookmark crosses the trust boundary

According to SlowMist's original technical analysis, a token-page link led to a fake human-verification page that prompted a bookmark action. The saved JavaScript then ran in the logged-in FOMO context and targeted browser storage, IndexedDB and Privy session material. We did not execute the malicious sample or connect to its collection endpoint.

Source-based bookmark phishing sequence, with the final wallet-execution step explicitly unresolved

Figure 2. Source-based mechanism reconstruction, not an independently replayed exploit or transaction trace. The unresolved signing step is dashed.

The useful security conclusion is narrower than “a wallet connection stole the funds”: the described lure sought code execution within a trusted application session. Conversely, the source's conditional MFA logic and the victim's reported absence of 2FA do not establish a demonstrated MFA bypass. Initiating an enrollment flow would also not prove successful enrollment.

Timeline: observations rather than invented milestones

UTC

Event and evidence level

2026-10-04 08:58:45

A01: 32,652.960737 USDC, directly checked

2026-10-04 08:59:23

A02: 5,002.490046 USDC, directly checked

2026-10-04 08:59:48

A03: 7,451.400815 USDC, directly checked

2026-10-05 07:46:10

T01: 212.492295 SOL to provider-labeled Privacy Cash pool; separate address history

2026-10-08

SlowMist public alert and analysis; not the attack date

The attack's initial browser-execution time is not established here. The collection address's reported first activity on 17 September is not assigned as the incident start time.

Alternative explanations and what would resolve them

The three-transfer match could be strengthened by an original withdrawal record or source confirmation naming the signatures. A transaction's valid signatures do not reveal whether the human account owner approved it. Application-side authentication, session revocation, withdrawal and signing logs would be needed to test competing key-export and remote-signing explanations.

For downstream analysis, identical asset values or nearby timestamps are insufficient to prove a bridge connection. A defensible cross-chain edge requires a source transaction, bridge order or fulfillment record, and destination transaction. Ethereum and Bitcoin candidates mentioned by the source remain external leads until that chain of evidence is available; they are not drawn as verified branches here.

Case-specific response points

For the affected account, preserve the bookmark URL and browser/session chronology without executing the bookmark again. Application operators can correlate the three candidate signatures with withdrawal requests and signing-policy decisions, then evaluate session and refresh-token revocation. A password change alone should not be assumed to invalidate every previously issued session artifact.

For investigators, preserve the full source/destination token-account mapping and block references before expanding a cluster. For any service request, provide the specific transaction and account history being queried, and distinguish the verified transfer from a claim about stolen-fund ownership. Provider labels are leads for corroboration, not legal identity findings.

Evidence appendix

ID / slot

Full transaction signature

A01

Solana slot 453209474

44uGoQH6KQRyVDCLuDTUHW3KxR61j9pGnnWWKoGtWFh9b3jUFRQ9t5MMVHoFr5ZWFLgEgWKmgxuR5Wq8tS36XkzN

A02

Solana slot 453209617

4pgANnxQ2Q5139ToXuc7LvHWqBZKKsBXwAVKA4eSi1wLnYdpukbgL2ZheTxXAMevU84HVKJCe1TBTTZ1VN2TZrH9

A03

Solana slot 453209712

xM1eCwjwhV4h9ECr2dTpL4TTDq3YafKiME3qyJcCAiLM3iqZosCVSW3rdQPcUr8AXWhzDrJzd4JKDZDWBJ6q4KM

T01

Solana slot 453515871

4YM1bkC7UjJwLX8zc6FgPbg7yFViDLQfo2hgJ8u9iGAjDDxFv9crdwJ1JkZurmE13JsD56CneJibLtvekoieT3Mx

Token / technical property

Value

USDC mint

EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v

Candidate instruction

SPL Token Program transferChecked

Per-candidate fee

0.00001507 SOL; separate from USDC principal

Source basis

SlowMist's original technical analysis

Reproducibility limit

Explorer-decoded detail checked; no raw RPC replay, victim-account access or complete downstream reconciliation claimed

This report separates directly observed chain transactions, explorer-provided labels, external reporting and analytical inference. It does not identify an attacker or attribute every historical recipient transaction to this case.

post_like_sub0
post_total_comment_sub0

11 reads

0/500 bytes