Social Engineering Strikes Again As $1M+ Bored Ape Collection Stolen

News • 2022/12/18 • by
remitano

Key Takeaways

  • In the social engineering scheme, the hacker pretended to be a casting director at a LA-based studio looking to license an NFT for a substantial sum. The hacker was able to immediately liquidate the NFTs for about 850 ETH, or slightly over $1M.

  • The shocking levels of social engineering serve as a sobering reminder to the community that these days, being conscientious and detail-oriented isn't enough to protect your assets.

Social Engineering Strikes Again As $1M+ Bored Ape Collection Stolen

Bored Ape Yacht Club NFTs have become the singular entity within the crypto culture. Because of its growing and palpable collections in the NFT ecosystem, it has become the main target of scammers, cyber theft, and other uninviting players. The higher the NFT ecosystem grows in might and technology, there has been concomitant increase in the number of hacks and exploitations it has suffered from. On the weekend, this took full fledge as an innovative scheme led to the theft of a substantial Bored Ape collection.

Read:Congress members were informed by the new CEO of FTX that SBF's family "definitely received payments" from the firm

Exploits and hacks that target users of Bored Ape are nothing new. Case studies surrounding the collection go back well over a year; we've seen many effective BAYC exploit attempts, from exploits involving the Discord server to vulnerabilities affecting Hollywood actor Seth Green.

These exploits continue to highlight how vital wallet security is for the well-known NFT collection owners, although Yuga Labs is not at fault. Furthermore, most of the main "blue chip" NFT collections contain these kinds of exploits; therefore, Bored Ape Yacht Club is by no means the only collection that includes them.

The most recent instance of all of this occurred over the weekend. It involved extraordinary levels of social engineering, serving as a sobering reminder to the community that these days, being diligent and detail-oriented is insufficient to secure your assets

Buy Crypto Now!

Breaking the barriers

In the most recent breach, 14 Bored Ape Yacht Club NFTs were taken from a single owner using a complex plan that includes advanced social engineering. The most recent hacks show how much effort and attention to detail today's exploiters are ready to put in. In this instance, the hacker could rapidly sell the NFTs for slightly over $1M, or around 850 ETH.

Popular web3 security expert @Serpent puts down the story succinctly and in great detail in a thread.

The hacker pretended to be a casting director at an LA-based studio looking to license an NFT in exchange for a sizeable payment in the social engineering plan; In contrast, the studio exists, but the pseudonym the hacker used does not. However, hours of calls, phony partnership proposals, false email domains, and other factors were driving this theft.

The plan had been developed for at least a few months. Another illustration of why cold storage is the safest solution for high-value NFTs and why contract signing or interaction can be extremely risky unless thoroughly checked beforehand. As Serpent concluded in his thread, using several wallets, verifying identities, and refraining from signing random signatures or transactions are crucial guidelines for NFT holders.

Comments (0)
Guest

Our newsletter

The latest cryptocurrency market news, technologies, and help resources.
[Error] You have exceeded number of allowed requests for this action