Cryptocurrency

Tweet by BoredApeYC

2022-04-01 [vendor] Multiple Discord compromises [chain] ethereum
Primary Source ↗
Blockchain(s) Ethereum

Incident Details

Another day, another Discord compromise — or in this case, many Discord compromises. Bored Apes wrote on their Twitter account in the early hours of the morning, “STAY SAFE. Do not mint anything from any Discord right now. A webhook in our Discord was briefly compromised. We caught it immediately but please know: we are not doing any April Fools stealth mints / airdrops etc. Other Discords are also being attacked right now.“Other Discords reported to be compromised include several other big-name projects including Doodles, which had previously endured a Discord compromise in late February. This particular compromise appeared to stem from a series of compromised Discord bots, including a very popular CAPTCHA bot used to fight spammers. It’s unclear if anyone lost money to the fake links posted by seemingly-official Discord accounts, or how much, but these types of attacks often lure in at least some victims, and the higher-priced NFT projects like Bored Apes and Doodles enable scammers to ask for quite a lot of money without raising an eyebrow.

Technical Details

Initial Attack Vector
Smart contract exploit / hack
Vendor / Product
Multiple Discord compromises

Timeline

  1. 2022-04-01 Breach occurred
  2. 2022-04-01 Publicly disclosed