MOFO

Safety

MOFO extension · version 0.9.2 · 1 October 2026

MOFO only runs on fomo.family, has no wallet code and can't place trades or sign anything. Its code is public, and you can check in one minute that the version in the Chrome Web Store is exactly that code.

read the code check it yourself bug bounty

What Chrome lets it do

When you add MOFO, Chrome shows one permission: read and change your data on fomo.family. That's the whole list.

PermissionWhat it means
runs on fomo.family onlyMOFO can't see any other website, other tabs, or other extensions like MetaMask, Phantom or any wallet.
storageSaves your settings, rules and trade journal inside the extension, on your computer.

No access to all websites, no tabs, cookies, clipboard or downloads. Chrome Web Store rules ban code loaded after review, so everything that runs is the published code.

What it never does

Every server it talks to

ServerWhy, and what it gets
mindoverfomo.toolsDownloads a small settings file with the addresses below. Sends nothing.
mofo-proxy.mofo-proxy.workers.devThe free MOFO service: narrative, Ask MOFO and holder data. Gets the token or wallet address you look at; for Ask MOFO, your question with the chart snapshot, your open position and today's P&L; and a random install id for the daily limits.
api.mindoverfomo.toolsTHE CALL. Gets a random account id, your calls, and the name and fomo username if you set them.
api.geckoterminal.comPublic price history to grade your closed trades. Gets the token address.
prod-api.fomo.familyTrader stats on fomo profiles. Uses your fomo.family session, see below.

Links to block explorers and X only open when you click them.

Your fomo.family login

fomo.family trades don't show up on-chain, so the trader card on a profile reads that trader's swap history from fomo.family's own API, the same request the fomo.family page makes. MOFO reuses the login the page itself sends for this. It stays in the open tab's memory, only ever goes back to fomo.family, and is never saved or sent to MOFO or anyone else. You can see this in the code: src/net.js, NET.api.

Check it yourself

  1. The permissions. Open chrome://extensions, click Details on MOFO and look at Site access: only fomo.family.
  2. The code is the store version. In a terminal:
    git clone https://github.com/mindoverfomotools-blip/mofo-extension
    cd mofo-extension
    python3 verify.py
    It downloads MOFO from Google's Chrome Web Store servers and compares every file with the public code. You should see MATCH and this fingerprint for 0.9.2: 01f6cee3e6ea6bee2db55ef60636461737b5bfffc6c49d8f01a688246596502f
  3. Where it connects. Open chrome://extensions, turn on Developer mode, and under MOFO click service worker. In the window that opens, go to Network and use fomo.family normally: every request goes to the servers in the table above. The trader card's request to fomo.family shows in the fomo.family tab's own DevTools.
  4. An outside view. Chrome-Stats lists MOFO's permissions and lets you download the store package to inspect it yourself.

Every version and its fingerprint is listed in RELEASES.md.

Bug bounty

up to $1,000 For the first report of a way MOFO, or someone abusing MOFO, could move funds, start a trade, sign anything, leak wallet data or the fomo.family session, run code that isn't public, or act on any site other than fomo.family. Report it privately to mindoverfomotools@gmail.com with SECURITY in the subject. Full rules in SECURITY.md.

Contact

mindoverfomotools@gmail.com · support · privacy · terms

MOFO is an independent tool and is not affiliated with or endorsed by fomo.family.