The Cryptos News | Daily Bitcoin News
  • Home
  • News
  • Market Cap
  • Top Cryptos
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Binance Coin (BNB)
    • Cardano (ADA)
    • Solana (SOL)
    • Tether (USDT)
    • XRP (XRP)
    • Polkadot (DOT)
    • Dogecoin (DOGE)
    • USD Coin (USDC)
  • Prices
  • Wallet
  • Crash
  • Investment
  • Exchange
  • Mining
  • Trading
  • Home
  • News
  • Market Cap
  • Top Cryptos
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Binance Coin (BNB)
    • Cardano (ADA)
    • Solana (SOL)
    • Tether (USDT)
    • XRP (XRP)
    • Polkadot (DOT)
    • Dogecoin (DOGE)
    • USD Coin (USDC)
  • Prices
  • Wallet
  • Crash
  • Investment
  • Exchange
  • Mining
  • Trading
The Cryptos News | Daily Bitcoin News
No Result
View All Result
Home News

Discord hacking is the newest threat for NFT buyers

Discord hacking is the newest threat for NFT buyers
Share on FacebookShare on Twitter


On Tuesday, December 21st, two NFT projects fell victim to the same attack. Like many projects in the crypto world, the NFT collection Monkey Kingdom and in-game asset marketplace Fractal both engaged heavily with their communities through Discord chat servers. Both projects were about to distribute rewards to their community members: Monkey Kingdom through an NFT presale on the day of the 21st and Fractal through a token airdrop — essentially a free distribution to early supporters — a few days later.

Then, disaster struck. Posts appeared in the official “announcements” channel of each project claiming that a surprise mint would reward community members with a limited edition NFT. Hundreds jumped at the chance — but for those who followed the links and connected their crypto wallets, a costly surprise was waiting. Rather than receiving an NFT, wallets were being drained of the Solana cryptocurrency, which both projects used for purchases.

In the space of an hour, a Twitter post, first from Monkey Kingdom and then from Fractal, informed followers that their Discord servers had been hacked; news of the NFT mints was bogus, the links a phishing fraud. In the case of Fractal, the scammers got away with about $150,000 worth of cryptocurrency. For Monkey Kingdom, the estimated total was reported to be $1.3 million.

the same techniques that hype up a sale can also open the door to hackers

Neither attack targeted the blockchain or the tokens themselves. Instead, the thieves exploited weaknesses in the infrastructure used to sell the tokens — specifically, the Discord chatrooms where NFT fans gather. It’s a reminder of a persistent weakness in the growing NFT economy, where surprise drops have primed buyers to move fast or risk missing out. But the same techniques that hype up a sale can also open the door to hackers — and in this case, a single compromise can end up spreading to more than one community at once.

In this case, the NFTs thieves had targeted a feature known as a webhook. Webhooks are used by many web applications (Discord included) to listen for a message sent to a particular URL and trigger an event in response, like posting content to a certain channel. You can think of a webhook like a secret phone number, a unique identifier that can be “called” (or, in a closer approximation, “texted”) to connect to an application on the other end.

By gaining access to webhooks belonging to the Fractal and Monkey Kingdom Discord servers, the hackers were able to send messages that were broadcast to all members of certain channels: a feature meant to be used only for official communications from the project teams. This was where the fake “announcement” had come from and why it had pointed to a scam address. In hindsight, the content should have raised some red flags — but given the distribution method, it looked just legitimate enough that many were fooled.

“we are always working to make it harder for these attacks to happen and will continue to invest in education and tools to help protect our users”

Discord webhooks are used to automate messages based on activities in other applications: for example, the official documentation describes making a bot that notifies a channel of new GitHub commits. But it’s easy to lose track of those bots amid the various third-party service integrations, and crucially, there’s no way to switch off all of them at once if you’ve been hacked. The result is a major opportunity for attackers and a liability for any Discord communities who aren’t paying attention to their integrations.

A Discord spokesperson said the company cautioned people to be careful when giving others access to their devices and personal information and pointed to guidance made available through its Moderator Academy resource center.

“Discord takes the safety of all users and communities very seriously, including social engineering attacks like these,” said Peter Day, senior manager of corporate communications at Discord. “While there are clear controls in place, we are always working to make it harder for these attacks to happen and will continue to invest in education and tools to help protect our users.”

“This is one of those things that really hurts you, both in terms of pride and professionalism”

The origin of the hack appears to have been a service called Grape Network, which provides community management tools to Fractal, Monkey Kingdom, and hundreds of other crypto projects that used Discord. Roughly a week before the cryptocurrency theft, an employee of Grape Network going by the screen name Arximedis had been caught by a separate scam on another Discord server entirely, this one belonging to Solana.

By first manipulating a Solana moderator, then Arximedis himself, through a phishing attack that involves getting the target banned, the hackers had managed to obtain an account access token that let them perform actions on behalf of the Grape administrator. It was enough to let them create an avenue to send messages to the Fractal and Monkey Kingdom Discord channels. With the groundwork in place, the hackers kept quiet and waited for a time to strike.

Grape Network founder Dean Pappas confirmed to The Verge that his colleague had been the target of the initial hack and that this first hack had been exploited to create the webhooks that were used in the second. “This is one of those things that really hurts you, both in terms of pride and professionalism,” Pappas said. “It’s a very difficult situation.”

In a statement sent via Twitter, the head of the Monkey Kingdom project (who asked to be referred to by the pseudonym “Monkey King”) said that additional security measures had now been put in place to avoid future attacks and ensure the safety of users. The Monkey King also pointed to the money raised by the project to refund victims of the scam.

NFT projects are particularly vulnerable to this kind of attack because they move so quickly. Hyped projects often sell out within hours — or sometimes minutes — so early adopters are conditioned to act fast. And Discord, now the go-to platform for NFT communities, is where the early intel on presales and airdrops is released first. That means community members are primed to jump on any announcements that give them an edge, which, in turn, lets scammers leverage fake messages to devastating effect.

community members are primed to jump on any announcements that give them an edge

In the most heated drops, making a successful transaction can be difficult even for the early movers. A Chainalysis examination of one popular project showed that more than 26,000 unsuccessful mint transactions occurred within the first hour after launch, each of which used up nonrefundable transaction fees. All told, more than $4 million was spent on gas fees for unsuccessful transactions.

There’s no indication yet that the NFT craze will slow in 2022, which means there’ll be no shortage of new projects looking to scale by using off-the-shelf solutions to build their infrastructure. There are signs that Discord, the beating social pulse of the NFT community, is also a goldmine for unscrupulous individuals looking to separate marks from their hard-earned coins — but perhaps as techniques of moderation and server administration in the community improve, more rigorous management of problem areas (like webhooks and third-party plugins) will reduce risk.

The good news is that, for the two projects affected by this particular hack, there may be sunnier days ahead. Fractal, the game asset marketplace, went live on the penultimate day of 2021. And having reimbursed money that was lost by members, Monkey Kingdom is relaunching the NFT line that was interrupted by the hack. The community is loyal, the Monkey King told us, and fans are once again ready to pick up a deal.





Read More:Discord hacking is the newest threat for NFT buyers

Tags: buyersDiscordhackingnewestNFTThreat
Previous Post

Cathie Wood Loads Up On These 3 Crypto-Exposed Stocks Amid Bitcoin Crash | Benzinga

Next Post

GameStop soars on building NFT trading hub, crypto partnerships

Related Posts

SHIB’s Shibarium Public Beta Is Planned for Deployment in Q3 – Bitcoin News

SHIB’s Shibarium Public Beta Is Planned for Deployment in Q3 – Bitcoin News

by The Cryptos News
June 24, 2022
0

The shiba inu crypto community is anticipating the launch of the layer two (L2) scaling solution Shibarium after it...

Bitcoin’s Energy Consumption Drops By A Quarter Following Crypto Crash – Decrypt

Bitcoin’s Energy Consumption Drops By A Quarter Following Crypto Crash – Decrypt

by The Cryptos News
June 24, 2022
0

The Bitcoin network's power consumption has fallen to 11 GW as of yesterday, down 27% from 15 GW in...

The Pre-Bitcoin History You Should Know: Basic Cash Versus Fiduciary Media

The Pre-Bitcoin History You Should Know: Basic Cash Versus Fiduciary Media

by The Cryptos News
June 24, 2022
0

This is an opinion editorial by Matthew Mezinskis, creator of the “Crypto Voices” podcast and Porkopolis Economics.Take a moment...

Three Arrows Capital Allegedly Owes Voyager Digital $655M — Crypto Firm Is ‘Unable to

Three Arrows Capital Allegedly Owes Voyager Digital $655M — Crypto Firm Is ‘Unable to

by The Cryptos News
June 23, 2022
0

According to reports, the TSX-listed Voyager Digital is another company that has been negatively affected by financial issues tied...

Next Post
GameStop soars on building NFT trading hub, crypto partnerships

GameStop soars on building NFT trading hub, crypto partnerships

Subscribe
Login
Notify of
guest
guest
0 Comments
Inline Feedbacks
View all comments

Trending News

Baked Bean Fork Season is Here

Baked Bean Fork Season is Here

April 18, 2022
A new Cryptocurrency Exchange – Something Big Waiting To Happen? – Digital Journal

A new Cryptocurrency Exchange – Something Big Waiting To Happen? – Digital Journal

December 10, 2021
DAXE – The First Multi-Chain Certificate of Deposit

DAXE – The First Multi-Chain Certificate of Deposit

April 18, 2022
ADVERTISEMENT

Investment

UK Government Considering Expansion of Investment Transactions List to Include

UK Government Considering Expansion of Investment Transactions List to Include

June 25, 2022
Sam-Bankman Fried’s FTX in talks to invest in crypto lender BlockFi (OTCMKTS:VYGVF)

Sam-Bankman Fried’s FTX in talks to invest in crypto lender BlockFi (OTCMKTS:VYGVF)

June 24, 2022
Today in Crypto: CoinFLEX Stops Some Withdrawals

Today in Crypto: CoinFLEX Stops Some Withdrawals

June 24, 2022
Once Again, Twitter Is Roasting Matt Damon For His Crypto Ad

Once Again, Twitter Is Roasting Matt Damon For His Crypto Ad

June 23, 2022
Access Softek Adds Cryptocurrency Investment with Launch of EasyCoin

Access Softek Adds Cryptocurrency Investment with Launch of EasyCoin

June 23, 2022

Prices

Snoop Dogg and Eminem’s Bored Ape music video is here to try and sell us on tokens

Snoop Dogg and Eminem’s Bored Ape music video is here to try and sell us on tokens

June 25, 2022
Solana Announces Web 3.0 Smartphone, Prompting SOL Crypto Gains

Solana Announces Web 3.0 Smartphone, Prompting SOL Crypto Gains

June 24, 2022
Top cryptocurrency prices 6/24: Polygon (Matic), Avalanche, XRP jump upto 18%; whales buy

Top cryptocurrency prices 6/24: Polygon (Matic), Avalanche, XRP jump upto 18%; whales buy

June 24, 2022
Crypto Crash May Spell Trouble for Graphics Card Makers

Crypto Crash May Spell Trouble for Graphics Card Makers

June 23, 2022

Trading

Cryptocurrency Exchange Uphold Leaves Venezuela Due to US Sanctions – Emerging Markets

Cryptocurrency Exchange Uphold Leaves Venezuela Due to US Sanctions – Emerging Markets

June 24, 2022
India Clarifies Crypto Taxes, as Trading Volumes Crater – Blockworks

India Clarifies Crypto Taxes, as Trading Volumes Crater – Blockworks

June 24, 2022
Another Crypto Exchange Pauses Withdrawals

Another Crypto Exchange Pauses Withdrawals

June 24, 2022
Ethereum Whale Accumulates 163,200,000,000 Shiba Inu (SHIB) As Memecoin Witnesses Trading

Ethereum Whale Accumulates 163,200,000,000 Shiba Inu (SHIB) As Memecoin Witnesses Trading

June 23, 2022
Coinbase to Shut Professional Crypto Trading Platform Coinbase Pro

Coinbase to Shut Professional Crypto Trading Platform Coinbase Pro

June 23, 2022
  • About Us
  • Contact Us
  • Terms of Use
  • Privacy Policy
  • DMCA

© 2021 Thecryptosnews.com

No Result
View All Result
  • Home
  • News
  • Market Cap
  • Top Cryptos
    • Bitcoin (BTC)
    • Ethereum (ETH)
    • Binance Coin (BNB)
    • Cardano (ADA)
    • Solana (SOL)
    • Tether (USDT)
    • XRP (XRP)
    • Polkadot (DOT)
    • Dogecoin (DOGE)
    • USD Coin (USDC)
  • Prices
  • Wallet
  • Crash
  • Investment
  • Exchange
  • Mining
  • Trading

© 2021 Thecryptosnews.com

wpDiscuz