{"id":26171,"date":"2022-05-06T08:28:28","date_gmt":"2022-05-06T12:28:28","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=26171"},"modified":"2022-05-06T08:31:24","modified_gmt":"2022-05-06T12:31:24","slug":"opensea-discord-server-hacked-as-users-are-warned-of-possible-phishing-scams","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/opensea-discord-server-hacked-as-users-are-warned-of-possible-phishing-scams\/","title":{"rendered":"OpenSea Discord Server Hacked As Users Are Warned Of Possible Phishing Scams"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">The hacker's initial announcement was a claim that <a href=\"https:\/\/coinscreed.com\/staging\/opensea-now-accepts-apecoin-payments.html\" data-type=\"post\" data-id=\"25656\">OpenSea<\/a> had is now in partnership with YouTube to enable their community into the NFT space.<\/h5>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"790\" height=\"395\" data-id=\"26172\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/blog_pic_20_44eec12b92.png\" alt=\"\" class=\"wp-image-26172\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/blog_pic_20_44eec12b92.png 790w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/blog_pic_20_44eec12b92-300x150.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/blog_pic_20_44eec12b92-768x384.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/blog_pic_20_44eec12b92-150x75.png 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/blog_pic_20_44eec12b92-360x180.png 360w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/blog_pic_20_44eec12b92-750x375.png 750w\" sizes=\"(max-width: 790px) 100vw, 790px\" \/><figcaption>NFT phishing scam<\/figcaption><\/figure>\n<\/figure>\n\n\n\n<p>OpenSea, a marketplace for nonfungible tokens (<a href=\"https:\/\/coinscreed.com\/staging\/nfts-market-outperformed-crypto-markets-q1-22.html\" data-type=\"post\" data-id=\"23852\">NFTs<\/a>), experienced a server breach on its primary Discord channel, with hackers posting fake &#8220;YouTube partnership&#8221; announcements.<\/p>\n\n\n\n<p>A screenshot <a href=\"https:\/\/twitter.com\/WuBlockchain\/status\/1522497541312753664\" data-type=\"URL\" data-id=\"https:\/\/twitter.com\/WuBlockchain\/status\/1522497541312753664\" target=\"_blank\" rel=\"noreferrer noopener\">shared<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> on Friday displays bogus collaboration news along with a link to a phishing website. Friday morning, the OpenSea Support Twitter account tweeted that the marketplace's Discord server had been compromised and warned users not to access the channel.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"750\" height=\"755\" data-id=\"26173\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0001.jpg\" alt=\"\" class=\"wp-image-26173\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0001.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0001-298x300.jpg 298w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0001-150x151.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0001-96x96.jpg 96w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0001-75x75.jpg 75w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/figure>\n<\/figure>\n\n\n\n<p>The initial post by the hacker, which was published in the announcements channel, claimed that OpenSea had &#8220;partnered with YouTube to bring their community into the NFT Space.&#8221; Additionally, it was stated that OpenSea will be releasing a mint pass with them that will permit holders to mint their project for free.<\/p>\n\n\n\n<p>It appears that the intruder was able to remain on the server for an extended period before OpenSea staff regained control. To create &#8220;fear of missing out&#8221; among victims, the hacker was successful in reposting follow-ups to the initial fraudulent announcement, rehashing the fake link, and claiming that 70 percent of the supply had been mined.<\/p>\n\n\n\n<p>The con artist also attempted to entice OpenSea users by claiming YouTube would offer &#8220;insane utilities&#8221; to those who claimed the NFTs. Fraudsters typically assert that the offer is exclusive and that there will be no further opportunities to participate.<\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"750\" height=\"638\" data-id=\"26174\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0002.jpg\" alt=\"\" class=\"wp-image-26174\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0002.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0002-300x255.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/IMG-20220506-WA0002-150x128.jpg 150w\" sizes=\"(max-width: 750px) 100vw, 750px\" \/><\/figure>\n<\/figure>\n\n\n\n<p>On-chain <a href=\"https:\/\/etherscan.io\/address\/0x5Bf15Af9B432b3ea4bbF5B219A77b788CE83d113#tokentxnsErc721\" data-type=\"URL\" data-id=\"https:\/\/etherscan.io\/address\/0x5Bf15Af9B432b3ea4bbF5B219A77b788CE83d113#tokentxnsErc721\" target=\"_blank\" rel=\"noreferrer noopener nofollow\" data-schema-attribute=\"mentions\">data<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> indicates 13 wallets have been compromised as of this writing, with a Founders' Pass worth approximately 3.33 ETH or $8,982.58 being the most valuable NFT stolen.<\/p>\n\n\n\n<p>Initial <a href=\"https:\/\/twitter.com\/lackingtalent\/status\/1522491148073414658?s=20&t=RjbEByhAdYrNn82nV5TVvA\" data-type=\"URL\" data-id=\"https:\/\/twitter.com\/lackingtalent\/status\/1522491148073414658?s=20&t=RjbEByhAdYrNn82nV5TVvA\" target=\"_blank\" rel=\"noreferrer noopener\">reports<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a> indicate that the intruder accessed server controls using webhooks. Webhooks are server plugins that allow other applications to receive real-time data. Webhooks are increasingly used as an attack vector by cybercriminals because they allow messages to be sent from official server accounts.<\/p>\n\n\n\n<p>The OpenSea Discord server is not the only one that can be accessed via webhooks. Several popular NFT collections' channels, including Bored Ape Yacht Club, Doodles, and KaijuKings, were compromised in early April due to a similar vulnerability that allowed the hacker to post phishing links using the official server accounts.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The hacker&#8217;s initial announcement was a claim that OpenSea had is now in partnership with YouTube to enable their community into the NFT space. OpenSea, a marketplace for nonfungible tokens (NFTs), experienced a server breach on its primary Discord channel, with hackers posting fake &#8220;YouTube partnership&#8221; announcements. A screenshot shared on Friday displays bogus collaboration [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":26172,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21,62],"tags":[147,1637,1636],"class_list":["post-26171","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-nft-news","tag-nft","tag-nft-marketplace","tag-opensea"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/05\/blog_pic_20_44eec12b92.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/26171","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=26171"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/26171\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/26172"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=26171"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=26171"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=26171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}