{"id":372069,"date":"2021-11-25T04:50:14","date_gmt":"2021-11-25T01:50:14","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/animoca-to-repay-users-265-eth-stolen-in-fake-nft-drop-discord-hack\/"},"modified":"2021-11-25T04:50:14","modified_gmt":"2021-11-25T01:50:14","slug":"animoca-to-repay-users-265-eth-stolen-in-fake-nft-drop-discord-hack","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/animoca-to-repay-users-265-eth-stolen-in-fake-nft-drop-discord-hack\/","title":{"rendered":"# Animoca to repay users 265 ETH stolen in fake NFT drop Discord hack"},"content":{"rendered":"<p>&#8220;<strong># Animoca to repay users 265 ETH stolen in fake NFT drop Discord hack <\/strong>&#8221;<\/p>\n<div class=\"post-content\" data-v-128018ef>Hong Kong-based gaming and venture capital company Animoca Brands and subsidiary Blowfish Studios have promised users that they will repay 265 ETH (US$1.1 million) stolen in a fraudulent nonfungible token (NFT) sale on D`iscord. <\/p>\n<p>The fraudulent minting event occurred at <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>roximately 3 AM AEDT on Nov 19 on the Phantom Galaxies Discord server. It saw 1,571 fake minting transactions over the course of about three hours.<\/p>\n<p>Phantom Galaxies is an upcoming Australian <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/game\/\" data-internallinksmanager029f6b8e52c=\"7\" title=\"Game\" target=\"_blank\" rel=\"noopener\">game<\/a> being developed by Blowfish Studios. The Phantom Galaxies Discord server has 94,000 members. <\/p>\n<p>In an increasingly common occurrence on Discord, hackers gained control of the official Phantom Galaxies server by using a malware bot that compromised the Admin account\u2019s two-factor authentication. Once in control of the Discord server, the hackers banned all staff, advisor, and community moderator accounts. <\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2021-11\/2138f9af-6c84-412a-a83e-b8ed021322a5.jpeg\"><figcaption style=\"text-align: center;\"><em>Screenshot of a fraudulent announcement about the so-called NFT drop. Source: PhantomGalaxies Discord server.<\/em><\/figcaption><\/figure>\n<p>The hackers then began posting announcements, claiming that the game was launching an im<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a>te surprise \u201cstealth\u201d NFT minting event. Users were directed to a fraudulent \u201cPhantom Galaxies NFT minting platform,\u201d which <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/etherscan.io\/address\/0x5b54e19f06f8FB4B28eE2c6958E55F4580F64ae1\">charged<\/a> users a 0.1 ETH \u201cminting fee.\u201d<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2021-11\/912d71be-a4a2-4671-a369-197da97108f7.jpeg\"><figcaption style=\"text-align: center;\"><em>Screenshot of the fraudulent website where users could \u201cmint\u201d PhantomGalaxies NFTs.<\/em><\/figcaption><\/figure>\n<p>Chairman of Animoca Brands Yat Siu warned followers about the fraudulent NFT drop in a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/ysiu\/status\/1461378345052999681?s=20\">tweet<\/a> at around 4AM AEDT Nov. 19. <\/p>\n<p>At 5:22AM he posted another <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/ysiu\/status\/1461399340111392774?s=20\">tweet<\/a>, saying that affected customers will be \u201cappropriately compensated.\u201d This has since been confirmed in a Nov. 24 <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.animocabrands.com\/animoca-brands-update-on-hacking-of-discord-server-of-phantom-galaxies-will-cover-users-losses\">release<\/a> from Animoca, which stated that details regarding compensation will be announced shortly. <\/p>\n<p>\u201c<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/woodz2021?s=20\">Woodz<\/a>,\u201d a Californian project manager for an upcoming NFT project called <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/TerraObscuraNFT?s=20\">Terra Obscura<\/a> lost $1000 USD to this attack. They told Cointelegraph they realized they\u2019d been scammed shortly after \u2018minting\u2019 two non-existent NFTs:<\/p>\n<blockquote><p>\u201cAs I was doing it, it seemed a bit off. The gas was unusually low and the contract looked different. I knew something was wrong but not sure what.\u201d<\/p><\/blockquote>\n<p>Woodz added they \u201cdon\u2019t normally just click links,\u201d but fell into the hacker\u2019s trap because of the way the announcement was positioned inside the official announcement channel. <\/p>\n<p><strong><em>Related: <\/em><\/strong><strong><em>Beeple\u2019s Discord compromised, timed to coincide with Christie\u2019s auction<\/em><\/strong><\/p>\n<p>The attack on Phantom Galaxies comes after a similar recent attack on Nov. 11 involving famed NFT artist, Beeple. Users thought they were signing up for a very affordable NFT drop, timed to coincide with his second Christie\u2019s auction. <\/p>\n<p>The perpetrator impersonated one of the channel admins and the Beeple Announcements Bot to promote a fake NFT drop from Beeple on Nifty Gateway.  Beeple has since removed links to the Discord from his Twitter <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/beeple\">profile<\/a>, and other <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.reddit.com\/r\/beeple\/comments\/m716d8\/join_the_beeple_collectors_discord_server\/\">links<\/a> to the server no longer appear not to work.<\/p>\n<p><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.riskiq.com\/blog\/external-threat-management\/discord-cdn-abuse-malware\/\">According<\/a> to an Oct. 21 report by cyber security company RiskIQ, Discord is becoming an increasingly popular platform for cybercriminals. RiskIQ researchers uncovered 27 unique malware types hosted on Discord&#8217;s CDN servers. <\/p>\n<p>In April, Talos Intelligence similarly found that hackers were increasingly using platforms like Discord to take advantage of users who were at home due to global COVID-19 restrictions. <\/p>\n<p>\u201cAttackers are leveraging collaboration platforms, such as Discord and Slack, to stay under the radar and evade organizational defenses,\u201d it wrote at the time. <\/p>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/animoca-to-repay-users-265-eth-stolen-in-fake-nft-drop-discord-hack\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;# Animoca to repay users 265 ETH stolen in fake NFT drop Discord hack &#8221; Hong Kong-based gaming and venture capital company Animoca Brands and subsidiary Blowfish Studios have promised users that they will repay 265 ETH (US$1.1 million) stolen in a fraudulent nonfungible token (NFT) sale on D`iscord. The fraudulent minting event occurred at&#8230;<\/p>\n","protected":false},"author":1,"featured_media":372070,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/images\/1200_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjEtMTEvNDY5ZTEwNWEtNTY4Yy00YTZhLWE2ZDUtMmMwNDliODc4YjBjLmpwZw==.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[91083,95118,71101],"class_list":["post-372069","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-blockchain-game","tag-nft","tag-scams"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/372069","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=372069"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/372069\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/372070"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=372069"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=372069"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=372069"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}