{"id":29032,"date":"2022-06-06T14:05:29","date_gmt":"2022-06-06T18:05:29","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=29032"},"modified":"2022-06-06T14:06:51","modified_gmt":"2022-06-06T18:06:51","slug":"certik-gives-security-tips-after-baycs-third-hack-in-2022","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/certik-gives-security-tips-after-baycs-third-hack-in-2022\/","title":{"rendered":"CertiK gives security tips after BAYC&#8217;s third hack in 2022"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\" id=\"h-bored-ape-yacht-club-bayc-was-hacked-for-the-third-time-this-year-on-june-4th-leading-to-the-loss-of-about-250-000-worth-of-nfts-the-sad-event-prompted-certik-to-give-a-few-security-tips\">Bored Ape Yacht Club (<a href=\"https:\/\/coinscreed.com\/staging\/bored-ape-yacht-club-bayc-surpasses-2-billion.html\" target=\"_blank\" rel=\"noreferrer noopener\">BAYC<\/a>) was hacked for the third time this year on June 4th, leading to the loss of about $250,000 worth of NFTs. The sad event prompted Certik to give a few security tips.<\/h5>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-39.png\" alt=\"CertiK gives security tips after BAYC's third hack in 2022\" class=\"wp-image-29090\" width=\"708\" height=\"339\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-39.png 573w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-39-300x143.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-39-150x72.png 150w\" sizes=\"(max-width: 708px) 100vw, 708px\" \/><figcaption>CertiK gives security tips after BAYC's third hack in 2022<\/figcaption><\/figure>\n\n\n\n<p>Hackers obtained access to a <a href=\"https:\/\/www.google.com\/search?q=CertiK+gives+security+tips+after+BAYC%27s+third+hack+in+2022&rlz=1C1SQJL_enNG889NG889&oq=CertiK+gives+security+tips+after+BAYC%27s+third+hack+in+2022&aqs=chrome..69i57.1486j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noreferrer noopener\">BAYC community manager's Discord account<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a> and uploaded a message with a link to a bogus website, stealing about 142 Ether ($250,000) in NFTs.<\/p>\n\n\n\n<p>Users who connected their wallets, which were then emptied of NFTs, were offered a limited-time free NFT gift. Hackers broke into BAYC's Discord and Instagram pages on two previous occasions in April, stealing 91 NFTs valued at over $1.3 million on the second try, using a phishing link.<\/p>\n\n\n\n<p>According to blockchain security firm CertiK, hackers moved stolen funds to obfuscation platform <a href=\"https:\/\/coinscreed.com\/staging\/tornado-cash-sets-to-launch-on-ethereums-layer-two-network-arbitrum.html\" target=\"_blank\" rel=\"noreferrer noopener\">Tornado Cash<\/a>, making any subsequent flow of funds on the blockchain hard to track.<\/p>\n\n\n\n<p>According to officials at CertiK, &#8220;NFT holders should also be particularly wary of anyone purporting to deliver free assets, as these can often be phishing scams,&#8221; regardless of how credible the project appears. Furthermore, CeriK wrote:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\" id=\"h-in-the-case-of-the-june-4th-attack-the-malicious-carbon-copy-site-had-some-small-differences-firstly-there-were-no-links-to-social-media-sites-on-the-phishing-site-there-was-also-an-added-tab-titled-claim-free-land-and-specifically-targeted-popular-nft-projects\"><p>&#8220;In the case of the June 4th attack, the malicious carbon-copy site had some small differences. Firstly, there were no links to social media sites on the phishing site. There was also an added tab titled &#8220;claim free land&#8221; and specifically targeted popular <a href=\"https:\/\/coinscreed.com\/staging\/15-most-promising-new-nft-projects.html\" target=\"_blank\" rel=\"noreferrer noopener\">NFT projects<\/a>.&#8221;<\/p><\/blockquote>\n\n\n\n<p>Certik advised crypto aficionados to seek for small anomalies on such sites as a preventative measure, as they are typically an indicator of criminal activity.<\/p>\n\n\n\n<p>&#8220;At the very least, users participating in such giveaways should always check the integrity of the site by comparing it to a known and verified site and looking for any inconsistencies,&#8221; they concluded.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bored Ape Yacht Club (BAYC) was hacked for the third time this year on June 4th, leading to the loss of about $250,000 worth of NFTs. The sad event prompted Certik to give a few security tips. Hackers obtained access to a BAYC community manager&#8217;s Discord account and uploaded a message with a link to [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":29090,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[10415],"class_list":["post-29032","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-certik-2"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/06\/image-39.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/29032","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=29032"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/29032\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/29090"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=29032"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=29032"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=29032"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}