Bitcoin Forum
December 26, 2025, 08:58:10 PM *
News: Latest Bitcoin Core release: 30.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Feels like a dream to lose crypto this way, one of the strangest of it's kind.  (Read 65 times)
5W-KILO (OP)
Member
**
Offline Offline

Activity: 255
Merit: 41


View Profile
Today at 05:04:00 PM
Last edit: Today at 06:50:10 PM by 5W-KILO
 #1

In the end no one will warn you to stop using your laptops to run and keep your Bitcoin and. Cryptocurrencies, sit back and keep relaxing like nothing is going on, so far 2025 have been a bizarre year for crypto wallets running on PC and smartphones.

Like we have seen the weirdest shit already only to see this today again.

A crypto trader got drained of $200,000 simply by bookmarking a website, I have never heard about this one since I've been using a computer, this is one of the weirdest so far.

It seems bookmarking the webpage automatically launched a script underground and do it's thing.



After doing some research around someone came up with how this can ever be possible, the victim dragged the website using his mouse directly into his bookmark tab and this ran a script.

Link: https://x.com/i/status/2004457753159651646



You are not safe as you think you are, doing all your crypto things using a computer, the risk is too much that every little things matters, even the ones you least expected to attack your crypto wallet, you can safe yourself from all this by having every devices for what they are intentionally created for.

Buy a airgapped hardware wallet going into 2026, don't risk the attacks that will likely be coming in 2026.
d5000
Legendary
*
Offline Offline

Activity: 4508
Merit: 10038


Decentralization Maximalist


View Profile
Today at 05:14:35 PM
Merited by Findingnemo (1)
 #2

Unfortunately you haven't posted any link to the post or an article where it's described, because some details would be missing.

First, of course if you visit an infected website and then bookmark it, the site's JavaScript code will be executed of course. The victim didn't clarify that they did "not" visit the website before bookmarking it.

Second, if it wasn't a traditional bookmark but a bookmarklet, then it directly would store JavaScript code, which can probably be infected too. It seems that the code is executed indeed when storing it, so this could be the reason. So the advice would be: don't use bookmarklets on computers where you're dealing with crypto.

Faisal2202
Hero Member
*****
Offline Offline

Activity: 1792
Merit: 541


✅ #kycfree


View Profile WWW
Today at 05:37:51 PM
 #3

Quote
The bookmark mentioned here is a browser bookmark. The contents of this bookmark contain a piece of malicious JavaScript code. When a user clicks on the malicious JavaScript code, it executes the Discord domain where the user is located and steals the token. Once the attacker gains access to the NFT projects’ discord token, they can directly take over relevant permissions of the account.
https://slowmist.medium.com/how-scammer-used-malicious-bookmark-to-gain-access-to-discords-of-nft-projects-7c3b325ff2e9

Well according to this article they have explained how this hack take place, actually the site we are bookmarking is the javascript code itself, like a link we click on it and we ge hacked but in your case like the one you reported, they just bookmarked it but seriously it is really crazy idea that no one would have thought before and I am pretty sure I have read about it before but almost forgot until now.

So now we should avoid bookmarking as well?

▄▄███████▄▄
▄███████████████▄
▄██▀▀█▀▀█████▀██▀▀██▄
▄██▀▄▄███████▄██▀▄▄▀██▄
▄███████████████████████▄
▄█████████████████▄
█████████████
█████████████
████████████
▀███████████████▀
▀█████████████████▀
▀███████████████▀
▀▀███████▀▀
 
  Bridgoro 
|
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄██
▄▄▄░▄▄███
██████████
▀████▀▀███
▄█████████
▄████████████
█████████████
▀████████████
██████████
▄████▄▄███
██████████
▀▀▀░▀▀███
▀██
|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄█████████████████████▄
▄███████████▀▀▀████████▄
████████▀▀██████████████
█████▀████▄▄█▀███▐███████
███████▄▄██▀█████▐███████
▀██████████▄▄███████████▀
▀█████████████▄▄██████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
BIT-BENDER
Hero Member
*****
Offline Offline

Activity: 2086
Merit: 849



View Profile
Today at 06:04:47 PM
 #4

Quote
The bookmark mentioned here is a browser bookmark. The contents of this bookmark contain a piece of malicious JavaScript code. When a user clicks on the malicious JavaScript code, it executes the Discord domain where the user is located and steals the token. Once the attacker gains access to the NFT projects’ discord token, they can directly take over relevant permissions of the account.
https://slowmist.medium.com/how-scammer-used-malicious-bookmark-to-gain-access-to-discords-of-nft-projects-7c3b325ff2e9

Well according to this article they have explained how this hack take place, actually the site we are bookmarking is the javascript code itself, like a link we click on it and we ge hacked but in your case like the one you reported, they just bookmarked it but seriously it is really crazy idea that no one would have thought before and I am pretty sure I have read about it before but almost forgot until now.

So now we should avoid bookmarking as well?
We should avoid bookmarking so who would be the next victim so that we can learn what to avoid next? I have not read about this book marking scam but I have read about many stranger scam this year alone than the bookmarking scam.
Is the solution to keep a list of what to avoid doing. I like what the OP pointed about that the Attacks are happening on PC and Mobile devices but if your wallet is on an offline wallet you are safer that those with wallet online.

      ▄▄██████████▄▄
   ▄███▀ ▀▀██████████▄
  █████     ▀▀█████████▄
 ██████▄       ▀▀████████
█████████▄        ▀▀█████▄
██████▀  ▀▀█▄▄       ▀████
██████      ▀▀█▄▄      ███
███████        ▀▀█▄▄  ▄███
█████████▄        ▀██████▀
 █████▀  ▀▀█▄   ▄███████▀
  ▀███       ██████████▀
    ▀██▄  ▄▄█████████▀
       ▀▀████████▀▀
.
.CASINOBET.
██████████████████████████
██████████████████████████
████████████  ████████████
██████████▀ ██ ▀██████████
█████████▀▄█▀▀█▄▀█████████
████████▀▄██████▄▀████████
███████▀▄██ ██ ██▄▀███████
██████ ▄█▀██▀▀█▀▀█▄ ██████
█████ ▄██▄██▄▄█▄▄██▄ █████
████▄ ▀▀▀▀▀▀▀▀▀▀▀▀▀▀ ▄████
██████████████████████████
██████████████████████████
.THE HOME OF CRYPTO REWARDS..
.............. UP TO 65% RAKEBACK + CASHBACK   ..............
██████████████████████████
██████████████████████████
████████▀▀▀ ▄▄ ▀▀▀████████
██████▀ ▄███▀▀███▄ ▀██████
█████ ▄█▀██▀▀▀▀██▀█▄ █████
████▀ █▄▄▀ ▄██▄ ▀▄▄█ ▀████
████ ████ ██████ ████ ████
████▄ █▀▀▄ ▀██▀ ▄▀▀█ ▄████
█████▄▀█▄██▄▄▄▄██▄█▀▄█████
██████▄ ▀███▄▄███▀ ▄██████
████████▄▄▄ ▀▀ ▄▄▄████████
██████████████████████████
..2 ETH GIVEAWAY   |   150% + 500 FS..
..... FOLLOW & PLAY TO WIN       |           WELCOME OFFER.........
..PLAY NOW..
5W-KILO (OP)
Member
**
Offline Offline

Activity: 255
Merit: 41


View Profile
Today at 06:47:58 PM
Merited by d5000 (1)
 #5

Unfortunately you haven't posted any link to the post or an article where it's described, because some details would be missing.

First, of course if you visit an infected website and then bookmark it, the site's JavaScript code will be executed of course. The victim didn't clarify that they did "not" visit the website before bookmarking it.

Second, if it wasn't a traditional bookmark but a bookmarklet, then it directly would store JavaScript code, which can probably be infected too. It seems that the code is executed indeed when storing it, so this could be the reason. So the advice would be: don't use bookmarklets on computers where you're dealing with crypto.

Sorry, I am looking into this incident more and more and it's becoming scary.

Here is another victim claiming they fell for the same thing just by bookmarking the webpage.

https://x.com/i/status/1993680223649308942





Link to original is also available.
BitMaxz
Legendary
*
Offline Offline

Activity: 3850
Merit: 3510


Greediness is destructive.


View Profile WWW
Today at 06:58:12 PM
 #6

https://slowmist.medium.com/how-scammer-used-malicious-bookmark-to-gain-access-to-discords-of-nft-projects-7c3b325ff2e9

Well according to this article they have explained how this hack take place, actually the site we are bookmarking is the javascript code itself, like a link we click on it and we ge hacked but in your case like the one you reported, they just bookmarked it but seriously it is really crazy idea that no one would have thought before and I am pretty sure I have read about it before but almost forgot until now.

So now we should avoid bookmarking as well?

That's a weird part—how will bookmarking become JavaScript itself? You might be talking about bookmarklets, not bookmarking, since when we bookmark a page, it only saves the URL and the name of the page, not the JavaScript from the site.
The other option is to have that Javascript if you downloaded the page that includes all things from the site downloaded locally on your device that you can open offline and execute all codes, including the HTML, CSS, images, and Javascripts.

Bookmarking should have nothing to do with compromising our wallet. The one who is a victim from the OP might have been infected already before the hacking happened.

.
 betpanda.io 
 
ANONYMOUS & INSTANT
.......ONLINE CASINO.......
▄███████████████████████▄
█████████████████████████
█████████████████████████
████████▀▀▀▀▀▀███████████
████▀▀▀█░▀▀░░░░░░▄███████
████░▄▄█▄▄▀█▄░░░█▄░▄█████
████▀██▀░▄█▀░░░█▀░░██████
██████░░▄▀░░░░▐░░░▐█▄████
██████▄▄█░▀▀░░░█▄▄▄██████
█████████████████████████
█████████████████████████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀░░░▀██████████
█████████░░░░░░░█████████
███████░░░░░░░░░███████
████████░░░░░░░░░████████
█████████▄░░░░░▄█████████
███████▀▀▀█▄▄▄█▀▀▀███████
██████░░░░▄░▄░▄░░░░██████
██████░░░░█▀█▀█░░░░██████
██████░░░░░░░░░░░░░██████
█████████████████████████
▀███████████████████████▀
▄███████████████████████▄
█████████████████████████
██████████▀▀▀▀▀▀█████████
███████▀▀░░░░░░░░░███████
██████░░░░░░░░░░░░▀█████
██████░░░░░░░░░░░░░░▀████
██████▄░░░░░░▄▄░░░░░░████
████▀▀▀▀▀░░░█░░█░░░░░████
████░▀░▀░░░░░▀▀░░░░░█████
████░▀░▀▄░░░░░░▄▄▄▄██████
█████░▀░█████████████████
█████████████████████████
▀███████████████████████▀
.
SLOT GAMES
....SPORTS....
LIVE CASINO
▄░░▄█▄░░▄
▀█▀░▄▀▄░▀█▀
▄▄▄▄▄▄▄▄▄▄▄   
█████████████
█░░░░░░░░░░░█
█████████████

▄▀▄██▀▄▄▄▄▄███▄▀▄
▄▀▄█████▄██▄▀▄
▄▀▄▐▐▌▐▐▌▄▀▄
▄▀▄█▀██▀█▄▀▄
▄▀▄█████▀▄████▄▀▄
▀▄▀▄▀█████▀▄▀▄▀
▀▀▀▄█▀█▄▀▄▀▀

Regional Sponsor of the
Argentina National Team
Satofan44
Sr. Member
****
Offline Offline

Activity: 252
Merit: 746


Don't hold me responsible for your shortcomings.


View Profile
Today at 08:03:54 PM
 #7

Unfortunately you haven't posted any link to the post or an article where it's described, because some details would be missing.

First, of course if you visit an infected website and then bookmark it, the site's JavaScript code will be executed of course. The victim didn't clarify that they did "not" visit the website before bookmarking it.
Often these stories are posted by engagement farmers on X, and they tend to have incomplete and sometimes even completely wrong information. There was one about a market maker these days, completely fabricated and not even the basic information within it was correct.

Second, if it wasn't a traditional bookmark but a bookmarklet, then it directly would store JavaScript code, which can probably be infected too. It seems that the code is executed indeed when storing it, so this could be the reason. So the advice would be: don't use bookmarklets on computers where you're dealing with crypto.
In terms of bookmarklet and bookmarks, I believe that this is just a case where most people will use the word bookmark when referring to either one of those and in most cases it is fine. I think that your advice on the disuse of bookmarklets is insufficient, the problem here is much deeper. JavaScript is an abomination and extremely insecure, but so is the interpreter the browser. So extension wallets with a browser that accepts JavaScript is a security nightmare. However, the fault is most often with the users. If we take an analysis at those that get hacked in these stories, we will often find that they have no justifiable reason for keeping a large amount of money in the Extension wallet (such as high speed but manual DeFi trading would require). They are either just lazy or stupid. There is no reason to have $10k, $30k on an extension wallet unless you have $30-$300m in your hardware wallet. In that case though, I expect the person not to complain but humbly accept the expected loss.


That's a weird part—how will bookmarking become JavaScript itself? You might be talking about bookmarklets, not bookmarking, since when we bookmark a page, it only saves the URL and the name of the page, not the JavaScript from the site.
The other option is to have that Javascript if you downloaded the page that includes all things from the site downloaded locally on your device that you can open offline and execute all codes, including the HTML, CSS, images, and Javascripts.
There is no need to write the same thing that d5000 wrote with different phrasing and to use AI too to do it.

Bookmarking should have nothing to do with compromising our wallet. The one who is a victim from the OP might have been infected already before the hacking happened.
Your general statement is useless and wrong. This was a targeted attack with malicious JavaScript.

▄▄█████████████████▄▄
▄█████████████████████▄
███▀▀█████▀▀░░▀▀███████

██▄░░▀▀░░▄▄██▄░░█████
█████░░░████████░░█████
████▌░▄░░█████▀░░██████
███▌░▐█▌░░▀▀▀▀░░▄██████
███░░▌██░░▄░░▄█████████
███▌░▀▄▀░░█▄░░█████████
████▄░░░▄███▄░░▀▀█▀▀███
██████████████▄▄░░░▄███
▀█████████████████████▀
▀▀█████████████████▀▀
Rainbet.com
CRYPTO CASINO & SPORTSBOOK
|
█▄█▄█▄███████▄█▄█▄█
███████████████████
███████████████████
███████████████████
█████▀█▀▀▄▄▄▀██████
█████▀▄▀████░██████
█████░██░█▀▄███████
████▄▀▀▄▄▀███████
█████████▄▀▄███
█████████████████
███████████████████
██████████████████
███████████████████
 
 $20,000 
WEEKLY RAFFLE
|



█████████
█████████ ██
▄▄█░▄░▄█▄░▄░█▄▄
▀██░▐█████▌░██▀
▄█▄░▀▀▀▀▀░▄█▄
▀▀▀█▄▄░▄▄█▀▀▀
▀█▀░▀█▀
10K
WEEKLY
RACE
100K
MONTHLY
RACE
|

██









█████
███████
███████
█▄
██████
████▄▄
█████████████▄
███████████████▄
░▄████████████████▄
▄██████████████████▄
███████████████▀████
██████████▀██████████
██████████████████
░█████████████████▀
░░▀███████████████▀
████▀▀███
███████▀▀
████████████████████   ██
 
[..►PLAY..]
 
████████   ██████████████
Findingnemo
Legendary
*
Offline Offline

Activity: 2926
Merit: 1065


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 08:28:30 PM
 #8

One with $200K portfolio value still using a hot wallet? If he learned about the basic steps of securing the cryptos and about the internet security practices, then he might be aware that no device is safe from attacks when it is connected to the internet.

It was a costly lesson, I hope others don't need to spend that much to learn that. Tongue

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
sunsilk
Hero Member
*****
Online Online

Activity: 3514
Merit: 651



View Profile
Today at 08:47:30 PM
 #9

So it's not bookmarking alone, the victim visited the website and later on, bookmarked it.

If it's a random website that contains malicious content then that's how he got drained. It's just sad that it's another amount that probably his life savings.

But because of losing that security to himself and by not verifying the website he's visiting, that's how he has lost his funds.

 
 RAZED  
█████████████████████
█████████████████████████
████████████▀░░░░▀███████
██████████▀░░▄▀▀▄░░▀█████
██████████▄▄██▄▄██▄░▀████
█████▀░░░░░░░▀██░░█░░████
████░░████▀▀█░░██▀░░▄████
████░░████▄▄█░░█░░▄██████
████░░█▀▀████░░██████████
████░░█▄▄███▀░░██████████
█████▄░░░░░░░▄███████████
█████████████████████████
█████████████████████
█████████████████████
█████████████████████████
██████████▀▀░░░░░▀▀██████
████████▀░░▄▄█░░▀▄░░█████
██████▀░░▄█████▄░░▀░░████
█████░░▄████▄▀░░█▄▄░░████
████░░▄███▄▀░░▄▀██▀░░████
████░░▀▀██░░▄▀███▀░░█████
████░░▄░░▀█████▀░░▄██████
█████░░▀▄░░█▀▀░░▄████████
██████▄▄░░░░░▄▄██████████
█████████████████████████
█████████████████████
 
 NO 
KYC
 
  $1,000,000 Cash Airdrop     CLAIM YOUR SHARE      
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!