Tweet by Bored Ape Yacht Club
Primary Source ↗Incident Details
The Bored Ape Yacht Club’s Instagram account was compromised and used to advertised a fake airdrop for metaverse land. This was particularly believable, as the much-anticipated project announced it would be launching this week.The post invited people to visit a website that prompted users to connect their wallets in order to receive the airdrop. Users who did so found their NFTs transferred out of their wallet to the scammer. So far, 44 people have fallen for the scam site, transferring a total of 133 NFTs with an estimated value of around $2.4 million. The stolen NFTs included items from pricey collections including Bored Apes, Mutant Apes, Bored Ape Kennel Club, and CloneX. Several of the NFTs had previously been sold for over $100,000 each.
Total loss estimated at $2,400,000.
Technical Details
- Initial Attack Vector
- Smart contract exploit / hack
- Vendor / Product
- Bored Apes Instagram
Timeline
- 2022-04-25 Breach occurred
- 2022-04-25 Publicly disclosed