K線
數據鏈上
VIP
市值
API
排行
CoinOSNew
CoinClaw🦞
語言
  • 简体中文
  • 繁体中文
  • English
全球行情資料應用程式領跑者,致力於更有效率地提供有價值的資訊。

功能

  • 即時行情
  • 特色功能
  • AI網格

服務

  • 資訊內容
  • 開放數據(API)
  • 機構服務

軟體下載

  • PC版
  • Android版
  • iOS版

聯絡我們

  • 聊天室
  • 商務信箱
  • 官方信箱
  • 官方驗證通道

加入社區

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|舊版

NFT Projects Lost $22M to Largely the Same Hackers on Discord: Reports

CN
Decrypt
關注
3 年前
AI 總結,5秒速覽全文

Two Web3 security firms have issued reports focused on the recent scourge of hacks targeting NFT projects, likely by a linked group of hackers using compromised Discord server administrator accounts.


According to a recent analysis by TRM Labs, cyber attacks against NFT collections have steadily risen in 2022, costing the NFT community over $22 million in May alone. NFTs are blockchain-based tokens that show ownership over digital or physical assets.


In the report, TRM Labs—which specializes in digital asset compliance and risk management—says cyberattacks linked to NFT minting scams deployed through compromised Discord accounts subsequently increased by 55% in June 2022 compared to the previous month.


"Since 2022, we've seen these compromises happening at scale, specifically on Discord," TRM Labs investigator Monika Laird told Decrypt in an interview.



TRM Labs says it has received over 100 reports of Discord channel hacks in the past two months through its Chainabuse reporting platform. Laird says that the attacks happen weekly and often target ERC-721 tokens, which is a token standard on the Ethereum blockchain for non-fungible tokens.


On the on-chain side, she said the relationship between the common consolidation points (exchanges, mixers) and wallets suggests that the same actors run the bulk of these attacks.



Yuga Labs, the company behind the NFT status symbol Bored Apes Yacht Club, said on Twitter last week: "Our security team has been tracking a persistent threat group that targets the NFT community. We believe that they may soon be launching a coordinated attack targeting multiple communities via compromised social media accounts. Please be vigilant and stay safe."


TRM Labs says on-chain data suggest many of the Discord compromises are linked to the same hacker that targeted the Bored Ape Yacht Club in June. According to the firm, other targeted projects include Bubbleworld, Parallel, Lacoste, Tasties, Anata, and more.



As Laird explained, there have been over 150 compromises since May targeting an admin role within a larger NFT project channel. Once the hackers control the admin account, they send out links to promotional giveaways and "exclusive" NFTs mints pushing people to jump into these malicious websites by creating a false sense of urgency.


"It isn't necessarily that Discord in and of itself has a weakness, but it just makes it a very target-rich environment," says Chris Janczewski, head of global investigations at TRM Labs. "If you're looking for people that own NFTs, you go to a place where they're all hanging out, and you have a point to be able to make [contact] with them."


While cyberattacks targeting Discord have been successful, Laird pointed out that hackers also compromised Twitter and Instagram accounts in recent months.


TRM Labs says that the rate at which the attacks are happening, and the fact that they occur across multiple blockchains, suggests that they could be separate attacks by rival cyber criminals running scams at the same time using tools provided as a "Scam-as-a-Service," turn-key, pay-as-you-go services to launch attacks.


In a separate report due out Thursday and previewed by Decrypt, blockchain security firm Halborn has also seen an increase in threats targeting crypto, separately pointing to the North Korean Lazarus Group, which the U.S. Treasury Department claims orchestrated the $622 million hack of the Axie Infinity Ronin Network.


But unlike TRM Labs, Halborn sees the threat originating from within China.


"Our analysis indicates that this attack came from a Chinese group that aims for high-value individuals," Alpcan Onaran, Halborn offensive security engineer, told Decrypt via Telegram. "We are expecting a logarithmic increase in advanced persistent attack (APT) activity and also expect to see different adversaries targeting Web 3.0 companies and individuals."


Onaran says that in Web3, security should be considered in all aspects, both technically and non-technically, to defend against these new threats.


"There's a saying that there's no such thing as new crimes [or] new scams; there are the old ones repackaged," Janczewski says. "So it makes perfect sense that all the kind of spear phishing, the FOMO, the getting people to do things irrationally very quickly, has pivoted into the new space, which is NFTs."


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

|
|
APP下載
Windows
Mac
分享至:

X

Telegram

Facebook

Reddit

複製鏈接

|
|
APP下載
Windows
Mac
分享至:

X

Telegram

Facebook

Reddit

複製鏈接

Decrypt的精選文章

41 分鐘前
亚马逊将在人工智能需求激增之际,再投资高达250亿美元于Anthropic。
3 小時前
Block的现金应用程序为年轻孩子推出账户——不提供比特币访问权限
3 小時前
乐观主义者称“隐私提升”法案为以太坊企业的转折点
查看更多

目錄

|
|
APP下載
Windows
Mac
分享至:

X

Telegram

Facebook

Reddit

複製鏈接

相關文章

avatar
avatarbitcoin.com
3 分鐘前
查尔斯·霍斯金森指出卡尔达诺和午夜是解决KelpDAO黑客攻击背后跨链缺陷的方案。
avatar
avatarDecrypt
41 分鐘前
亚马逊将在人工智能需求激增之际,再投资高达250亿美元于Anthropic。
avatar
avatarbitcoin.com
54 分鐘前
证券交易委员会主席推动支持加密货币的议程,因为链上证券交易的创新豁免即将到来。
avatar
avatarcoindesk
1 小時前
Aave的核心市场一次性达到100%的利用率,这并不是一件好事。
avatar
avatarcoindesk
1 小時前
人工智能的混乱产生了一个加密公司无法忽视的搜索问题
APP下載
Windows
Mac

X

Telegram

Facebook

Reddit

複製鏈接