September 26, 2023 2:57 pm

Scammers Steal $150K Worth of Crypto From NFT Project With Discord Hack

Facebook
Twitter
LinkedIn
Pinterest
WhatsApp
Telegram

URGENT: JUST 11 DAYS REMAIN TO HELP SAVE INDEPENDENT MEDIA & ANR, TO ENSURE WE ARE FULLY FUNDED FOR NEXT MONTH,SO LET'S CUT THE BS & GET TO THE POINT - WE WILL BE FORCED LAY OFF STAFF & REDUCE OPERATIONS UNLESS WE ARE FULLY FUNDED WITHIN THE NEXT 2 WEEKS - Sadly, less than 0.5% of readers currently donate or subscribe to us But YOU can easily change that. Imagine the impact we'd make if 3 in 10 readers supported us today. To start with we’d remove this annoying banner as we could fight for a full year...

Scammers Steal $150K Worth of Crypto From NFT Project With Discord Hack

By Corin Faife

Buyers hoping to get a limited-edition NFT from Fractal, a new marketplace for game item NFTs, were given an unpleasant and costly surprise on Tuesday morning when it was revealed that a link sent through the project’s official Discord channel was a scam set up to steal crypto.

Users who followed the link and connected their crypto wallets, expecting to receive an NFT, instead found that their holdings of Solana (SOL) cryptocurrency were emptied and transferred to the scammer’s account. An analysis posted on Medium by Tim Cotten, founder of another NFT gaming project, estimated the value of SOL stolen to be around $150,000.

Fractal is a startup project from Twitch co-founder Justin Kan specializing in the buying and selling of NFTs representing in-game assets. It was announced earlier in December and quickly amassed a following of more than 100,000 users through Discord — making it a target for the kind of scammers that have plagued NFT projects since the beginning.

News reached Twitter when a tweet from Kan informed followers that the announcements bot on Fractal’s Discord server had been hacked. Another tweet from the main Fractal Twitter account confirmed that a fraudulent link had been posted through the channel.

The attack took advantage of users hoping to mint NFTs, the term given to buying tokens at the moment when they are first created by a given project, rather than buying them on the secondary market at a later date.

Though the post from the Discord bot was fake, Fractal’s official Twitter account had posted a tweet just hours earlier hinting at an upcoming airdrop: a process where a crypto project distributes a number of tokens, usually to users who are early adopters. Since demand for token mints and airdrops is often very high, the pressure for users to move fast when snap announcements are made creates an attack vector that scammers are all too happy to exploit.

While the cryptography behind cryptocurrencies and NFTs is highly secure, the vast network of websites and applications that comprise the broader crypto ecosystem contains many possible vectors for attack.

A tweet from the official Fractal account suggested that the fraudulent message had been posted to Discord via a webhook. Webhooks are a feature of web application design that lets an application listen for a message sent to a particular URL and trigger an event in response — for example, posting to a certain Discord channel.

If a webhook is not secured with additional authentication measures, effectively anyone with the URL is able to post to the channel. It is not clear what, if any, precautions were taken by the team behind Fractal to prevent this from happening.

In the wake of the hack, a blog post from Fractal announced that victims who had lost money would be fully compensated. While apologizing briefly, the blog post also appeared to put some of the onus for security onto followers of the project, saying:

“If something doesn’t feel right in crypto, please don’t proceed, even if at first it looks legitimate. We must use our best judgement as there’s no ‘undo button’ in crypto.”

Fractal had not responded to a request for comment sent through the company’s official contact form at time of press.

Editor’s Note:

Start investing In cryptocurrency with Bitxchange www.bit-xchange.org. If you’re new to the world of crypto and figuring out how to buy cryptocurrencies, then cryptocurrency exchanges like Bitxchange can help you to easily buy and sell crypto.

Opinion pieces don’t necessarily reflect the position of our news site but of our Opinion writers.

Support the ANR from as little as $8 – it only takes a minute. If you can, please consider supporting us with a regular amount each month. Thank you.

Related News

Subscribe for free to our ANR news emails and access 2 free ebooks plus Reports to share with family and friends about Covid fraud and the danger of the vaccines.

Australian National Review is Australia’s first real free and independent press, one with no editorial control by the elite, but a publication that can generate critical thinkers and critical debate and hold those spreading mistruths and deliberate propaganda in mainstream media to account.

News with a difference that will be educational, compelling and create a platform for political and social change in this country and address the real issues facing this country and the world.

Watch Full Documentary

URGENT: JUST 3 DAYS REMAIN TO HELP SAVE INDEPENDENT MEDIA & ANR, SO LET'S CUT THE BS & GET TO THE POINT - WE WILL BE FORCED TO LAY OFF STAFF & REDUCE OPERATIONS UNLESS WE ARE FULLY FUNDED WITHIN THE NEXT 2 WEEKS

Sadly, less than 0.5% of readers currently donate or subscribe to us But YOU can easily change that. Imagine the impact we'd make if 3 in 10 readers supported us today. To start with we’d remove this annoying banner as we could fight for a full year...

Get access to TruthMed- how to save your family and friends that have been vaxx with vaccine detox, & how the Unvaxxed can prevent spike protein infection from the jabbed.

Free with ANR Subscription from $8

Download the Full PDF - THE COVID-19 FRAUD & WAR ON HUMANITY