Our Discord servers were briefly exploited today. The team caught and addressed it quickly. About 200 ETH worth of NFTs appear to have been impacted. We are still investigating, but if you were impacted, email us at discord@yugalabs.io.
-
Show this thread
-
Replying to @BoredApeYC
Let me get this straight - your server got 'exploited' once, you locked it down ensuring all your mods had 2FA, and then it got 'exploited' again? Something doesn't feel right here
29 replies 13 retweets 353 likes -
Replying to @FatManTerra @BoredApeYC
2FA doesn't help against most of the current attack vectors
1 reply 0 retweets 5 likes -
Replying to @RichPunksNFT @BoredApeYC
I see. Malicious bots, then? Sorry, not up to date with Discord attack vectors - but it feels like most of them can/should be mitigated using custom bots for any semi-serious server with this much risk/value - I'd love to learn more if you're willing to elaborate! Thank you
4 replies 0 retweets 16 likes -
Replying to @FatManTerra @BoredApeYC
There is a plethora of attack vectors, but it often boils down to social engineering a human target that has elevated permissions. Zero day exploits, fake Collab requests, etc. The gist is they somehow get to access the discord access token of the target; allows to act as target
2 replies 0 retweets 6 likes
Oh, interesting
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.