Rare Bears Discord phishing attack nabs $800K in NFTs

Rare Bears Discord phishing attack nabs $800K in NFTs

Recently launched NFT project, Rare Bears, was hit with an attack, after a hacker posted a phishing link in the project's Discord channel, stealing nearly $800,000 in NFTs.

Analysis from blockchain security firm Peckshield detailed that the attacker was able to steal 179 NFTs, including Rare Bears and other NFTs from various collections, including CloneX, Azuki, a “mfer” from artist sartoshi, and 6 LAND tokens used for The Sandbox metaverse.

Our top trading bots

According to on-chain analysis, most of the NFTs were sold, netting the hacker 286 ETH, worth over $795,500, most of which was promptly put through Tornado Cash, a crypto mixer used to obfuscate the source of funds.

A slate of similar phishing scams have occurred in recent months on Discord, suggesting some teams need to more carefully consider the security on admin accounts. Earlier today, the Rare Bears team posted that they had hired security consultant and auditor “Pandez” for a full security audit of its Discord.

How the attack happened

According to an update posted by the Rare Bears team, the hacker gained access to the account of a Rare Bears Discord moderator known as “Zhodan”, posting an announcement within the group's channel that a new mint of NFTs was taking place.

It was a fake of course — a phishing link designed to steal funds from a users' wallet.

The update from the security audit found that the head of the project’s Discord account was compromised. The attacker, using the compromised account, then banned other members, or removed their roles from the server, thereby removing their ability to delete the posted phishing link.

The attacker then invited a bot which locked all channels on the server, removing the ability for others to publicly communicate that the posts and links were fake.

Rare Bears said the team was able to regain control of the server, removing the compromised account and transferring ownership to a new one, and that the server is secure from another attack.

Related: NCA wants regulation for coin mixers, but the crypto industry is already one step ahead

Speaking to Cointelegraph, security consultant Pandez said that users should look out for a few key signs that could mean a message is a scam.

“Almost no serious project will ever do a stealth mint,” Pandez said, “never click any links which appear like this.”

Pandez said other red flags are if channels are locked during a “drop” of a new NFT collection, if the link differs to those shared on Twitter or other official sources for the project, and if the link is continuously posted in the channel.

Past attacks of a similar nature have happened on Discord. In December, Solana NFT project Monkey Kingdom announced that hackers made off with $1.3 million of the community's crypto funds after a security breach. Attackers there also posting a phishing link which drained users’ wallets.

Last November, members of the Discord of popular NFT artist Beeple were also scammed, with attackers gaining access to a moderators account to post a phishing link, similarly draining user funds.

Continue reading about Cointelegraph
Chainlink launches startup program to provide blockchain resources to early-stage projects
Chainlink Labs recently announced a program that provides a blueprint to help new crypto projects in their blockchain business building journey. According...
Tokens pose lesser risk than gold and oil for UK investors — Survey
A survey on investors across the United Kingdom has revealed a growing interest in the new asset classes that threaten to overshadow traditional finance,...
SEC hits BlockFi with a $100 million penalty, gives 60 days to comply with a 1940 law
On Feb. 14, the Securities and Exchange Commission, or SEC, announced actions against crypto lending company BlockFi over its failure to register high-yield...
Bitfinex hack recovery spurs crypto community responses
On Feb. 1, there were movements of around $2.5 billion from the 2016 Bitfinex hack wallets. After reviewing the transactions, Cointelegraph reported that...
MicroStrategy lost $146M to Bitcoin impairment charges in Q4 2021
MicroStrategy, the fortune 500 company with a 125,051 Bitcoin (BTC)-strong treasury, announced its Q4 2021 financial results on Tuesday.The institutional...
$3.3B Bitcoin mining company Griid to list on NYSE via SPAC deal
In a filing with the United States Securities and Exchange Commission on Tuesday, special purpose acquisition company, or SPAC, Adit EdTech Acquisition...
Money managers with zero crypto exposure risk being left behind — Bloomberg strategist
The career risk surrounding cryptocurrency is shifting to money managers who don’t have exposure to digital assets as opposed to those who are already invested,...
Bitcoin charges toward $64K as Tesla ATH boosts Elon Musk to $250B net worth
The price of Bitcoin (BTC) hurtled toward $64,000 in a fresh round of bullishness on Oct. 25 as the market left a weak weekend behind.BTC/USD 1-hour candle...
Almost 1.1M people have already signed up for Coinbase NFT waitlist
There have already been more than 1 million sign-ups for Coinbase’s NFT platform since the waitlist went live on Oct.12. Coinbase opened up the waitlist...
Avalanche recovers from Evergrande-led sell-off as AVAX rebounds over 30%
Avalanche (AVAX) prices recovered on Sept. 22, paring a portion of losses that hit cryptocurrencies at the beginning of this week, led by worries about...
Bitcoin miner Greenidge set for Nasdaq listing through merger
Bitcoin mining and power generation company Greenidge is set to complete a merger with customer and technical support solutions provider Support.com to...
Is there a right way to regulate crypto? Yes, and this is how
Cryptocurrency is becoming increasingly mainstream. Between the entrance en masse of traditional financial institutions — from investment funds, to banks,...
Microsoft quietly closing down Azure blockchain in September
Microsoft is turning off its corporate Azure Blockchain Service on September 10 and will not accept any new deployments effective immediately, with no official...
Chinese Top Official Offered to Get Blockchain Centralized
China has been known in the world of cyber assets as a country which takes a hard stance on them. Given this fact, it sounds dubious when one of the top...
ICO with love: DateCoin Will Present DTC Tokens To Denim Users On Valentine's Day
On Valentine's Day, more than 700,000 users will receive tokens of the DateCoin project free of charge. Owners of DTC tokens will be users of the existing...