Report: Bored Ape Yacht Club Discord Attacker May Have Been Involved in Previous NFT Phishing Scams

Report: Bored Ape Yacht Club Discord Attacker May Have Been Involved in Previous NFT Phishing Scams

On June 4, 2022, the Bored Ape Yacht Club (BAYC) Discord server was compromised and a phishing scam targeted non-fungible token (NFT) collectors holding BAYC, Mutant Ape Yacht Club (MAYC), and Otherside NFTs. According to an analysis by the Web3 and blockchain auditing and security firm Certik, the BAYC Discord server attacker may have been involved in previous phishing attacks.

Blockchain Security Firm Certik Analyzes the BAYC Discord Phishing Attack

While many NFTs are very expensive, it makes them all the more worthwhile for malicious attackers to steal them. This week the Bored Ape Yacht Club (BAYC) Discord server was breached and an attacker used a phishing scam to lure victims.

Certik, the Web3 and blockchain auditing and security firm, published an analysis of the attack and from the company’s account, the attacker may have been involved with previous phishing attempts. The attack occurred on Saturday and a total of 32 NFTs valued at roughly $360K were stolen from blue-chip NFT holders.

The NFTs stolen stemmed from the Bored Ape Yacht Club (BAYC), the Bored Ape Kennel Club (BAKC), Mutant Ape Yacht Club (MAYC), and NFTs from the Otherdeed collection. Certik’s report says the phishing site was a “carbon copy of the official projects website, yet with subtle differences.”

There were no social media links on the site and there was a tab added titled “claim free land.” After some victims were hooked by the phony phishing ad, the attacker received a number of NFTs and then proceeded to sell them.

The attackers managed to acquire 142 ether and Certik notes that it is likely 100 ETH was sent to the mixing application Tornado Cash. Certik summarizes why the researchers believe some evidence shows that a fraction of ether the hacker acquired was sent to Tornado Cash and possibly sent to one address.

“Whilst it’s impossible to be certain that the 99.5 ETH redeemed by 0x2917… are the funds associated with today’s attack, it is certainly probable that these are the stolen funds post mixer due to the 20.5 ETH being sent to the depositor address,” Certik’s report notes.

The Certik researcher’s analysis adds:

The majority of the funds were sent to [Externally Owned Account (EOA)] 0x5bC1…, which is where they remain at the time of writing.

The blockchain security firm says that links indicate that 0x5bC1 is likely “not only associated with the BAYC phishing attack today, but also previous phishing attacks.” The company mentioned the fact that BAYC was targeted on April 25, 2022, when an attacker compromised the NFT collection’s Instagram account.

At that time, the hacker got away with 888 ether worth of non-fungible tokens by posting a scam link to a fake airdrop. “Users were prompted to sign a ‘safeTransferFrom’ transaction,” Certik’s report concludes. Prior to the Instagram exploit at the end of April, on the first day of April, Mutant Ape Yacht Club #8,662 was stolen via a phishing scam posted to the Discord channel. The celebrity Seth Green recently fell victim to a phishing attack and lost his Bored Ape to the scam. Bored Ape #8,398 called “Fred” was supposed to play a role in Green’s new series called “White Horse Tavern.”

What do you think about the recent BAYC phishing scam? Let us know what you think about this subject in the comments section below.

Earning Passive Income With Crypto

Related Posts

400+ Crypto Advertisements Violate Guidelines in India — ‘Some Influencers Talk About Crypto Without Understanding It’

The Advertising Standards Council of India (ASCI) has reportedly revealed that more than 400 crypto ads violated its guidelines so far this year. The majority of complaints…

Investment: How To Calculate The Attractiveness of a Cryptocurrency

Investment: Asset manager, financier, and cryptocurrency teacher Alexander Alexandrovich Ryabinin says the investment attractiveness of digital assets can be determined by analyzing inflationary and deflationary processes. The…

Rich Dad Poor Dad’s Robert Kiyosaki Says He’s Waiting for Bitcoin to Test $1,100 to Buy More

The famous author of the best-selling book Rich Dad Poor Dad, Robert Kiyosaki, says he’s waiting for the price of bitcoin to test $1,100. He added that…

This is the Future of the Liquid Staking, Based on the Past

Staking and the future: The liquid staking industry is at a turning point, says Simon Furlong, the Co-Founder of Geode Finance. The various opportunities across DeFi and cryptocurrency…

Book by Nigerian Author Reminds New Adopters Why Bitcoin Was Created

Nigerian author and crypto advocate Nathaniel Luz has said his recently published book represents his attempt to remind people of the initial reason why bitcoin was created….

Voyager Digital Issued Notice of 3AC’s Loan Default; Here’s What Might Be Next

Crypto hedge fund Three Arrows Capital (3AC) has defaulted on an estimated loan of $670 million, as per the market update by Voyager Digital. In a release dated June…