Crypto users report new wave of Discord NFT scams

Share This Post

Scammers have reportedly found a new way to compromise users’ Discord accounts — including those on servers related to cryptocurrencies and non fungible-tokens (NFTs) — by hijacking QR codes used for logging in.

According to pseudonymous crypto enthusiast Serpent, malicious actors — disguised as Discord’s verified bot called Wick—are now reaching out to users to offer a collaboration, potential employment, or some other enticing opportunities. But there’s a catch — to continue the discussion, scammers ask users to verify via a QR code.

This is because Discord has an option to log in using a special QR, bypassing two-factor authentication. In reality, however, “scammers are using Chrome drivers to open the login page, get the QR code image, then send it to the Discord bot, asking people to verify themselves,” Serpent explained.

If a user scans such a code, bad actors can instantly log into their account and snatch their Discord token, a unique series of numbers and letters that is created when people connect to the app. If this happens, users need to reset their passwords as soon as possible.

Why is it dangerous?

While access to a Discord account won’t directly endanger someone’s crypto or NFTs, such security breaches are still dangerous and can enable to all manner of cyberattack vectors.

For example, malicious QR codes can be used to add new—and potentially suspicious—contacts to users’ lists. Further, such codes also allow to connect victims’ devices to the hacker’s network, automatically initiate phone calls as well draft emails and send text messages. Not to mention that such QR codes can reveal users’ locations and initiate fraudulent payments.

As CryptoSlate reported, cyberattacks have been picking up steam on Discord lately. Notably, not only regular users but major crypto companies are being hacked as well.

On April 1, for example, the Discord server of the famous Bored Ape Yacht Club NFT collection was compromised by hackers.

At the time, the hacker gained access to the Discord server that hosts Bored Ape Yacht Club, Mutant Ape Yacht Club, and Mutant Ape Kennel Club—all three NFT collections from Yuga Labs.

Apart from Yuga Labs, Discord servers of other NFT projects, such as Nyoki Club and Shamanzs NFT, were also hacked that day.

The post Crypto users report new wave of Discord NFT scams appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Dogecoin And Shiba Inu Social Dominance At 5-Month High — Can FOMO Stall Price Growth?

Over the past week, blue-chip assets like Bitcoin (BTC) and Ethereum (ETH), have been major topics of discussion in the cryptocurrency space — and rightfully so — after a strong positive

Litecoin Achieves New Milestone, Completes 4 Billion Transaction In 24 Hours!

The post Litecoin Achieves New Milestone, Completes 4 Billion Transaction In 24 Hours! appeared first on Coinpedia Fintech News Over the past few days, Litecoin has witnessed a sharp increase in

Weekly Crypto Hack Report: $50 Million Lost in Radiant Capital’s Latest Breach!

The post Weekly Crypto Hack Report: $50 Million Lost in Radiant Capital’s Latest Breach! appeared first on Coinpedia Fintech News Crypto security this week has been the definition of chaos as some

Bitcoin ETF Records 6 Days Of Consecutive Inflows, Adds Over $273 Million!

The post Bitcoin ETF Records 6 Days Of Consecutive Inflows, Adds Over $273 Million! appeared first on Coinpedia Fintech News In 24 hours, no BTC ETF has recorded a negative flow Moreover, ARK’s

70% Of Ethereum Institutional Investors Engaged In ETH Staking

The post 70% Of Ethereum Institutional Investors Engaged In ETH Staking appeared first on Coinpedia Fintech News Reportedly, almost 70% of institutional investors in Ethereum (ETH) are now

Crypto Scam Alert: EigenLayer’s X Account Hijacked To Promote Fraudulent Airdrop

In the early hours of Friday, the official X (formerly Twitter) account of EigenLayer, a prominent restaking protocol, was compromised and used to promote a fraudulent airdrop, according to a