The official Discord channel of the NFT marketplace OpenSea was recently infiltrated by cybercriminals who used it to distribute a phishing link.
According to The Verge, a bot in the channel made a fake announcement that the NFT marketplace was partnering with YouTube and that users should click on a “YouTube Genesis Mint Pass” in order to get one of 100 free NFTs before they’re gone forever.
Just like cybercriminals often do in phishing emails, this message instilled a sense of urgency to get users to click on a link to a site that that blockchain security company PeckShield has now flagged as a phishing site.
At the same time, as the NFT space tends to move rather quickly, users knew from past experience that they only had a limited time to claim one of the free NFTs and likely didn’t want to miss out.
Stolen NFTs
Although the malicious messages have been removed from OpenSea’s Discord channel and the phishing site has also been taken down, one user said they lost NFTs in the incident and pointed to an address on the blockchain that belonged to the cybercriminals responsible.
Viewing the address on Etherscan.io or on competing NFT marketplace Rarible shows that 13 NFTs were actually transferred to it from five users around the time of the attack and based on their prices when last sold, all five NFTs appear to be worth just over $18k.
While OpenSea hasn’t yet explained how its Discord channel was hacked, one possible explanation is that the cybercriminals leveraged the webhook functionality that organizations utilize to control bots which make posts on their channels.
In a statement to The Verge, OpenSea spokesperson Allie Mack provided further details on how the company responded to the incident, saying:
“Last night, an attacker was able to post malicious links in several of our Discord channels. We noticed the malicious links soon after they were posted and took immediate steps to remedy the situation, including removing the malicious bots and accounts.
We also alerted our community via our Twitter support channel to not click any links in our Discord. Our preliminary analysis indicates that the attack had limited impact. We are currently aware of fewer than 10 impacted wallets and stolen items amounting to less than 10 ETH.”
Whether you’re on Discord or Telegram, you should avoid clicking on suspicious links especially in messages that try to instill a sense of urgency to prevent falling victim to phishing attacks.

More Remote Working Apps:
https://quintexcapital.com/?ref=arminham Quintex Capital
https://www.genesis-mining.com/a/2535466 Genesis Mining
http://www.bevtraders.com/?ref=arminham BevTraders
https://www.litefinance.com/?uid=929237543 LiteTrading
https://jvz8.com/c/202927/369164 prime stocks
https://jvz3.com/c/202927/361015 content gorilla
https://jvz8.com/c/202927/366443 stock rush
https://jvz1.com/c/202927/373449 forrk
https://jvz3.com/c/202927/194909 keysearch
https://jvz4.com/c/202927/296191 gluten free
https://jvz1.com/c/202927/286851 diet fitness diabetes
https://jvz8.com/c/202927/213027 writing job
https://jvz6.com/c/202927/108695 postradamus
https://jvz1.com/c/202927/372094 stoodaio
https://jvz4.com/c/202927/358049 profile mate
https://jvz6.com/c/202927/279944 senuke
https://jvz8.com/c/202927/54245 asin
https://jvz8.com/c/202927/370227 appimize
https://jvz8.com/c/202927/376524 super backdrop
https://jvz6.com/c/202927/302715 audiencetoolkit
https://jvz1.com/c/202927/375487 4brandcommercial
https://jvz2.com/c/202927/375358 talkingfaces
https://jvz6.com/c/202927/375706 socifeed
https://jvz2.com/c/202927/184902 gaming jobs
https://jvz6.com/c/202927/88118 backlink indexer https://jvz1.com/c/202927/376361 powrsuite
https://jvz3.com/c/202927/370472 tubeserp
https://jvz4.com/c/202927/343405 PR Rage
https://jvz6.com/c/202927/371547 design beast
https://jvz3.com/c/202927/376879 commission smasher
https://jvz2.com/c/202927/376925 MT4Code System
https://jvz6.com/c/202927/375959 viral dash
https://jvz1.com/c/202927/376527 coursova
https://jvz4.com/c/202927/144349 fanpage
https://jvz1.com/c/202927/376877 forex expert
https://jvz6.com/c/202927/374258 appointomatic
https://jvz2.com/c/202927/377003 woocommerce
https://jvz6.com/c/202927/377005 domainname
https://jvz8.com/c/202927/376842 maxslides
https://jvz8.com/c/202927/376381 ada leadz
https://jvz2.com/c/202927/333637 eyeslick
https://jvz1.com/c/202927/376986 creaitecontentcreator
https://jvz4.com/c/202927/376095 vidcentric
https://jvz1.com/c/202927/374965 studioninja
https://jvz6.com/c/202927/374934 marketingblocks https://jvz3.com/c/202927/372682 clipsreel
https://jvz2.com/c/202927/372916 VideoEnginePro
https://jvz1.com/c/202927/144577 BarclaysForexExpert
https://jvz8.com/c/202927/370806 Clientfinda
https://jvz3.com/c/202927/375550 Talkingfaces
https://jvz1.com/c/202927/370769 IMSyndicator
https://jvz6.com/c/202927/283867 SqribbleEbook
https://jvz8.com/c/202927/376524 superbackdrop
https://jvz8.com/c/202927/376849 VirtualReel
https://jvz2.com/c/202927/369837 MarketPresso
https://jvz1.com/c/202927/342854 voiceBuddy
https://jvz6.com/c/202927/377211 tubeTargeter
https://jvz6.com/c/202927/377557 InstantWebsiteBundle
https://jvz6.com/c/202927/368736 soronity
https://jvz2.com/c/202927/337292 DFY Suite 3.0 Agency+ information
https://jvz8.com/c/202927/291061 VideoRobot Enterprise
https://jvz8.com/c/202927/327447 Klippyo Kreators
https://jvz8.com/c/202927/324615 ChatterPal Commercial
https://jvz8.com/c/202927/299907 WP GDPR Fix Elite Unltd Sites
https://jvz8.com/c/202927/328172 EngagerMate
https://jvz3.com/c/202927/342585 VidSnatcher Commercial
https://jvz3.com/c/202927/292919 myMailIt
https://jvz3.com/c/202927/320972 Storymate Luxury Edition
https://jvz2.com/c/202927/320466 iTraffic X – Platinum Edition
https://jvz2.com/c/202927/330783 Content Gorilla One-time
https://jvz2.com/c/202927/301402 Push Button Traffic 3.0 – Brand New
https://jvz2.com/c/202927/321987 SociCake Commercial https://jvz2.com/c/202927/289944 The Internet Marketing
https://jvz2.com/c/202927/297271 Designa Suite License
https://jvz2.com/c/202927/310335 XFUNNELS FE Commercial
https://jvz2.com/c/202927/291955 ShopABot
https://jvz2.com/c/202927/312692 Inboxr
https://jvz2.com/c/202927/343635 MediaCloudPro 2.0 – Agency
https://jvz2.com/c/202927/353558 MyTrafficJacker 2.0 Pro+
https://jvz2.com/c/202927/365061 AIWA Commercial
https://jvz2.com/c/202927/357201 Toon Video Maker Premium
https://jvz2.com/c/202927/351754 Steven Alvey’s Signature Series
https://jvz2.com/c/202927/344541 Fade To Black
https://jvz2.com/c/202927/290487 Adsense Machine
https://jvz2.com/c/202927/315596 Diddly Pay’s DLCM DFY Club
https://jvz2.com/c/202927/355249 CourseReel Professional
https://jvz2.com/c/202927/309649 SociJam System
https://jvz2.com/c/202927/263380 360Apps Certification
https://jvz2.com/c/202927/359468 LocalAgencyBox
https://jvz2.com/c/202927/377557 Instant Website Bundle
https://jvz2.com/c/202927/377194 GMB Magic Content
https://jvz2.com/c/202927/376962 PlayerNeos VR