27/07/2022 NFT Projects Lost $22M to Largely the Same Hackers on Discord: Reports

One analysis concludes that hackers targeting Bored Ape Yacht Club and other NFT projects are part of a 'wider network.'

hackers-gID_5.jpg

Two Web3 security firms have issued reports focused on the recent scourge of hacks targeting NFT projects, likely by a linked group of hackers using compromised Discord server administrator accounts.

According to arecent analysisby TRM Labs, cyber attacks against NFT collections have steadily risen in 2022, costing the NFT community over $22 million in May alone. NFTsare blockchain-based tokens that show ownership over digital or physical assets.

In the report,TRM Labsโ€”which specializes in digital asset compliance and risk managementโ€”says cyberattacks linked to NFT minting scams deployed through compromised Discord accounts subsequently increased by 55% in June 2022 compared to the previous month.

"Since 2022, we've seen these compromises happening at scale, specifically on Discord," TRM Labs investigator Monika Laird toldDecryptin an interview.

TRM Labs says it has received over 100 reports of Discord channel hacks in the past two months through itsChainabusereporting platform. Laird says that the attacks happen weekly and often targetERC-721tokens, which is a token standard on the Ethereum blockchain for non-fungible tokens.

On the on-chain side, she said the relationship between the common consolidation points (exchanges, mixers) and wallets suggests that the same actors run the bulk of these attacks.

Yuga Labs, the company behind the NFT status symbol Bored Apes Yacht Club, said on Twitter last week: "Our security team has been tracking a persistent threat group that targets the NFT community. We believe that they may soon be launching a coordinated attack targeting multiple communities via compromised social media accounts. Please be vigilant and stay safe."

TRM Labs says on-chain data suggest many of the Discord compromises are linked to the same hacker that targeted theBored Ape Yacht Clubin June. According to the firm, other targeted projects include Bubbleworld, Parallel, Lacoste, Tasties, Anata, and more.

As Laird explained, there have been over 150 compromises since May targeting an admin role within a larger NFT project channel. Once the hackers control the admin account, they send out links to promotional giveaways and "exclusive" NFTs mints pushing people to jump into these malicious websites by creating a false sense of urgency.

"It isn't necessarily that Discord in and of itself has a weakness, but it just makes it a very target-rich environment," says Chris Janczewski, head of global investigations at TRM Labs. "If you're looking for people that own NFTs, you go to a place where they're all hanging out, and you have a point to be able to make [contact] with them."

While cyberattacks targeting Discord have been successful, Laird pointed out that hackers also compromised Twitter and Instagram accounts in recent months.

TRM Labs says that the rate at which the attacks are happening, and the fact that they occur across multiple blockchains, suggests that they could be separate attacks by rival cyber criminals running scams at the same time using tools provided as a "Scam-as-a-Service," turn-key, pay-as-you-go services to launch attacks.

In a separate report due out Thursday and previewed byDecrypt, blockchain security firmHalbornhas also seen an increase in threats targeting crypto, separately pointing to the North KoreanLazarus Group, which the U.S. Treasury Department claims orchestrated the $622 million hack of the Axie Infinity Ronin Network.

While TRM Labs did not specify where the attacks are coming from, Halborn sees the threat originating from within China.

"Our analysis indicates that this attack came from a Chinese group that aims for high-value individuals," Alpcan Onaran, Halborn offensive security engineer, toldDecrypt via Telegram. "We are expecting a logarithmic increase in advanced persistent attack (APT) activity and also expect to see different adversaries targeting Web 3.0 companies and individuals."

Onaran says that in Web3, security should be considered in all aspects, both technically and non-technically, to defend against these new threats.

"There's a saying that there's no such thing as new crimes [or] new scams; there are the old ones repackaged," Janczewski says. "So it makes perfect sense that all the kind of spear phishing, the FOMO, the getting people to do things irrationally very quickly, has pivoted into the new space, which is NFTs."

Arts

https://decrypt.co/106024/nft-projects-lost-22m-to-hackers-in-one-month-via-discord-report?amp=1

Interesting NFTs
Christmas Sleigh
First Christmas-themed Visual Toy. For this work the artist has created a fantastic sleigh, ornamented in detail and with all the Christmas spirit that transports us to childhood, illusion, innocence. With its gift wrapping machinery, its Santa, a snow globe, the nutcracker, the European-style village and its soundtrack (first time with music) it is a whole Christmas mosaic for the imagination.
Smile to Shreds, Neon Gwen
The First KayPikeFashion Mint Ever. Ever feel so joyful and were grinning so hard you felt you could split in half? That punk rebel yell of glee when you pull of a particularly refined stunt? This is the paint of dreams, fangs and neon. Hellish and hard to pull off. I was able to with this work quietly paint a sweet inner tale of childhood influences, rat fink and autobody shops. All while pretending to paint gwenom for the audience. More on that in bonus material. This is my alternate animation made specifically for crypto art collectors. It will only ever exist in this format. You get the Shiny, unused in media verified image. More on that in the bonus material. Mixed Media: Bio/Digital. Glycerin on 5'9" human skin 10-14 hours Performance art. Shot on Canon EOS RP. 16 + hours Photoshop and DaVinci Resolve. All Works are SFW. Art has been Seen on the front page of Reddit, Featured in the New York Times, Galileo.tv, and multiple other promotions including Twitch.tv, Disney Interactive, RIOT games, WB games, AMD and more! More on how this art is unique and potentially explosive in the NFT world: https://youtu.be/CXbNF2Y6srs ------------------------- The purchase of this NFT Grants the buyer unique bonus material. Physical Mail Bonus Package: A verified physical Art Print. Autographed from the artist in 12x16. Please allow a few weeks for delivery. Digital Bonus Package: This image in .mp4. An "About the Art" Video and an "From the Artist" introduction. A README.txt about the artwork with some personal notes and Links relevant to the artwork.
Really Remote Working Part 1
Created during the lockdown period whilst being confined to the same place every day, this piece is part of a series of imaginary places that I dreamed of being able to work from.
Childhood #3
Don't you dare look back.
Bicco
๋น„์ฝ”๋Š” ํ–‰์šด์„ ์ƒ์ง•ํ•˜๋Š” ํ•œ๊ตญ์˜ ์‹ ํ™” ์† ๋™๋ฌผ์ž…๋‹ˆ๋‹ค. 2018 ๋ถ€์‚ฐ ์ธ๋””์ปค๋„ฅํŠธ ํŽ˜์Šคํ‹ฐ๋ฒŒ(BIC)์—์„œ ์ฒ˜์Œ ๋“ฑ์žฅํ•˜์˜€์ฃ . ๊ทธ์˜ ์ด๋ฆ„์€ ๊ท€์—ฌ์šด ์™ธ๋ชจ ๋•์— ํ–‰์‚ฌ์—์„œ ๋”ฐ์˜จ BIC๊ณผ Biccy(ํ˜ธ์ฃผ์—์„œ ๋น„์Šคํ‚ท์„ ํ†ต์ƒ์ ์œผ๋กœ ๋ถ€๋ฅด๋Š” ๋ง)๊ฐ€ ํ•ฉ์ณ์ ธ ๋งŒ๋“ค์–ด์กŒ์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ๊ท€์—ฌ์šด ์™ธ๋ชจ์— ์†์ง€ ๋งˆ์„ธ์š”. ๋น„์ฝ”๋Š” โ€˜์ •์˜์˜ ์ˆ˜ํ˜ธ์žโ€™๋กœ ์•Œ๋ ค์ง„ ๊ฒƒ์ฒ˜๋Ÿผ, ๊ฐ•ํ•œ ๋ฉด๋ชจ ์—ญ์‹œ ๊ฐ€์ง€๊ณ  ์žˆ๋‹ต๋‹ˆ๋‹ค.