27/07/2022 NFT Projects Lost $22M to Largely the Same Hackers on Discord: Reports

One analysis concludes that hackers targeting Bored Ape Yacht Club and other NFT projects are part of a 'wider network.'

hackers-gID_5.jpg

Two Web3 security firms have issued reports focused on the recent scourge of hacks targeting NFT projects, likely by a linked group of hackers using compromised Discord server administrator accounts.

According to arecent analysisby TRM Labs, cyber attacks against NFT collections have steadily risen in 2022, costing the NFT community over $22 million in May alone. NFTsare blockchain-based tokens that show ownership over digital or physical assets.

In the report,TRM Labs—which specializes in digital asset compliance and risk management—says cyberattacks linked to NFT minting scams deployed through compromised Discord accounts subsequently increased by 55% in June 2022 compared to the previous month.

"Since 2022, we've seen these compromises happening at scale, specifically on Discord," TRM Labs investigator Monika Laird toldDecryptin an interview.

TRM Labs says it has received over 100 reports of Discord channel hacks in the past two months through itsChainabusereporting platform. Laird says that the attacks happen weekly and often targetERC-721tokens, which is a token standard on the Ethereum blockchain for non-fungible tokens.

On the on-chain side, she said the relationship between the common consolidation points (exchanges, mixers) and wallets suggests that the same actors run the bulk of these attacks.

Yuga Labs, the company behind the NFT status symbol Bored Apes Yacht Club, said on Twitter last week: "Our security team has been tracking a persistent threat group that targets the NFT community. We believe that they may soon be launching a coordinated attack targeting multiple communities via compromised social media accounts. Please be vigilant and stay safe."

TRM Labs says on-chain data suggest many of the Discord compromises are linked to the same hacker that targeted theBored Ape Yacht Clubin June. According to the firm, other targeted projects include Bubbleworld, Parallel, Lacoste, Tasties, Anata, and more.

As Laird explained, there have been over 150 compromises since May targeting an admin role within a larger NFT project channel. Once the hackers control the admin account, they send out links to promotional giveaways and "exclusive" NFTs mints pushing people to jump into these malicious websites by creating a false sense of urgency.

"It isn't necessarily that Discord in and of itself has a weakness, but it just makes it a very target-rich environment," says Chris Janczewski, head of global investigations at TRM Labs. "If you're looking for people that own NFTs, you go to a place where they're all hanging out, and you have a point to be able to make [contact] with them."

While cyberattacks targeting Discord have been successful, Laird pointed out that hackers also compromised Twitter and Instagram accounts in recent months.

TRM Labs says that the rate at which the attacks are happening, and the fact that they occur across multiple blockchains, suggests that they could be separate attacks by rival cyber criminals running scams at the same time using tools provided as a "Scam-as-a-Service," turn-key, pay-as-you-go services to launch attacks.

In a separate report due out Thursday and previewed byDecrypt, blockchain security firmHalbornhas also seen an increase in threats targeting crypto, separately pointing to the North KoreanLazarus Group, which the U.S. Treasury Department claims orchestrated the $622 million hack of the Axie Infinity Ronin Network.

While TRM Labs did not specify where the attacks are coming from, Halborn sees the threat originating from within China.

"Our analysis indicates that this attack came from a Chinese group that aims for high-value individuals," Alpcan Onaran, Halborn offensive security engineer, toldDecrypt via Telegram. "We are expecting a logarithmic increase in advanced persistent attack (APT) activity and also expect to see different adversaries targeting Web 3.0 companies and individuals."

Onaran says that in Web3, security should be considered in all aspects, both technically and non-technically, to defend against these new threats.

"There's a saying that there's no such thing as new crimes [or] new scams; there are the old ones repackaged," Janczewski says. "So it makes perfect sense that all the kind of spear phishing, the FOMO, the getting people to do things irrationally very quickly, has pivoted into the new space, which is NFTs."

Arts

https://decrypt.co/106024/nft-projects-lost-22m-to-hackers-in-one-month-via-discord-report?amp=1

Interesting NFTs
Genesis
JosĂ© Delbo sent me his striking pencil sketch and powerful inked work, which I then interpreted in oil on canvas. I wanted to create a very painterly piece with obvious brush marks etc, but I was also aiming for a nostalgic feel, a kind of 1980’s superhero comic book look, the kind I grew up with. My goal with this animation was to try to recreate, in part, the creative process that both artists went through with the visual information I had. I was able to showcase my painting process more accurately as I could take photographs of my progress throughout. Consecutive images could then be layered like brush strokes over José’s drawing to create the impression that this was one continuous artwork from pencil, to ink, to completed painting. The representation of the line sketch at the beginning, then pencil/ink and lastly the paint layers being applied demonstrate both artists’ struggle for the right lines, tone, form, and colour until the work is finally completed. As the oil was still wet with each photograph the glare of my studio lights can be seen in the brush strokes. Eventually, the figure emerges and as it does, our hero comes to life, looking directly at the viewer -- but is he grimacing in approval or disgust? We will never know for sure as just before he can say anything, white paint is brushed across the canvas entirely and the process begins again. Only the bat is quick enough to escape.
#6368
By OthersideDeployer
Alex in Wonderland
A figure, Alex, stands mostly naked in the midst of a physical and psychological maelstrom. He is clad only in nostalgic 80’s era socks, on a tenuous island between active waters and a variety of shark denizens. Sharks on the right side of the image are all beached, including a shark with a quartz crystal snout, an orange shark wrapped in a life buoy, and a shark further in the distance wearing an 80’s style shirt with the number “88”. On the left side is the largest shark, wearing bright glossy red lipstick and brandishing prominent teeth with braces. She is cordoned off from the figure by a roped float divider, and within her thought bubble is a warning symbol. Behind the figure, hovering in the air, are Grey aliens emerging from the distance, out of a series of elliptical UFO shaped interdimensional membranes. The Greys take on the visual form of spermazoa ostensibly impregnating the interdimensional thresholds. As is typical, these Greys inhabit a zone just behind the unconscious topology of Alex’s dissociative mind. Though Alex’s bottom half is representative, his top half mutates into a psychological cornucopia. In a manner akin to “Auto-Erotic Sphinx”, a predecessor work, the figure has self suctioned—an act of sensual infatuation, enjoyment, and exploration. Upward exists the figure’s primary conscious eye, adorned with a revolutionary beret emblazoned with a Bitcoin badge. The figure’s summit features the nose of a fighter jet facing off against video game Bullet Bills, one of whom is marked by a communist North Korean star. A cropped section of a UFO observes the contest. Alex’s mind branches both left and right. To the left is more singular embodied consciousness, manifesting two eyes and a Ganesh trunk grasping crayons. The right branch dissociates upward diagonally, emerging into an array of eyes, faces, teeth, tail, a unicorn horn, and much more—all of which participate in expressing his unconscious being; a democracy of psychic factions representing thought impressions and associations. All illumination and darkness– fernal, infernal, high consciousness and corporeal underbelly–reside in this realm. In the distance are relatively languid, light clouds, and against the firmament hovers a colossal distant eye peering over the scene and far beyond. This painting possesses underlying genetic traits with previous works such as “Auto-Erotic Sphinx with Toys”, “Dionysus”, and “Fuku-Shiva”. The work serves also as a nod to an earlier period of art inspiration during late teens and early twenties— born out of the nakedness, vulnerability, curiosity, and wonder inherent to coming of age and all subsequent psychedelic revelation.
Fluffy Meantooth
Ugh! Fluffy Meantooth here. I'm here to enjoy chasing red dots and reading garfield. I once got in a fight with a labradoodle, and won. It's pawesome to meet you!
Her Mind Had Gone Out For A Stroll & Fallen Down The Rabbit Hole
Her Mind Had Gone Out For A Stroll & Fallen Down The Rabbit Hole' is the first programmable piece of art by Kitty Bast. The owner constructs, modifies & tattoos their very own Doll Lady... Is she falling down a rabbit hole, lost in a sea of cats or gazing into the unknown void? Do you like Pink Ladies or Lilac Ladies? Or do you pick the Wild Card? There's always a wild side to an innocent doll face. Is she obsessed with crypto ponies or crypto kitties? Or does she have an insatiable desire for Mr. Honey Badger. Come inside and have a nice cup of NFTea with the bunnies. Is your lady chained to the blockhain? Does your lady shed Bitcoin tears or ETH tears? Does your doll face don a Rotten Heart? Do you HODL to the Moon to meet the ETH Kitty? Do you have an obsession for cyborgs or Puddin'? Would you like a slice of Death by Pink? Is The Cat's Eye green or golden? Little trolls with mini daggers not included. The cheshire cat might trade you his ears for your goggles. Modifications of the Host. How long is forever? Sometimes, just one second.