An anonymous hacker obtained access to the official Discord server intended for members of Yuga Labs’ Bored Ape Yacht Club, Mutant Ape Yacht Club, and Mutant Ape Kennel Club. In the Mutant Ape Yacht Club channel, the hacker successfully posted a fake link. It was concealed as a stealth NFT mint which was used to steal Mutant Ape Yacht Club #8662 from one user, according to security company PeckShield.
#PeckShieldAlert @BoredApeYC Discord compromised, MutantApeYachtClub #8662 has been stolen.https://t.co/bMQrBgxreU
https://mintboredapeyc[.com]/ is #phishing site. Do *NOT* fall prey to it. https://t.co/NLMiIzKsR6 pic.twitter.com/mUlAkImvRY— PeckShieldAlert (@PeckShieldAlert) April 1, 2022
The BAYC team stated in a tweet that it had “found” the problem right away. Nonetheless, the team warned users not to mint any NFT using a link shared on its Discord and informed watchers that no April Fools’ stealth mints were planned. “STAY SAFE”. Kindly, do not mint anything from any Discord right now. A webhook in our Discord was temporarily hacked, BAYC said in a tweet. We caught it right away, but please know that we will not be performing any April Fools stealth mints/airdrops, etc. Other Discord servers are also being targeted at the moment.
STAY SAFE. Do not mint anything from any Discord right now. A webhook in our Discord was briefly compromised. We caught it immediately but please know: we are not doing any April Fools stealth mints / airdrops etc. Other Discords are also being attacked right now.
— Bored Ape Yacht Club (@BoredApeYC) April 1, 2022
According to reports, the hacker may have carried out the assault using Ticket Tool, a famous Discord bot that produces support tickets automatically.
THIS IS 100% CONFIRMED. AUDIT LOG FROM DOODLES & SHAMANZS
🚨 TICKET TOOL IS HACKED 🚨
REMOVE IT FROM YOUR SERVER. pic.twitter.com/KKHn5RHCVL
— Serpent (@SerpentAU) April 1, 2022
Twitter users have complained about a similar attack on the Doodles Discord channel, another famous NFT collection, but the Doodles company has yet to respond.
🚨🚨🚨 DOODLES DISCORD ALSO HACKED. NOT AN APRIL FOOLS JOKE, BE CAREFUL!!! 🚨🚨🚨
— Farokh.eth (🎙, 🎙) (@farokh) April 1, 2022
Hackers frequently use compromised Discord accounts to carry out phishing attacks on NFT collectors. Only a few weeks ago, the recently formed NFT collection, Rare Bears, announced that its members were victims of a similar crime and lost approximately $790,000.