4 ms·
This appears to be highly coordinated. From the article, it sounds like their Discord server has a channel (announcements) that should only be writable by admin
by godot 5y ago
This appears to be highly coordinated. From the article, it sounds like their Discord server has a channel (announcements) that should only be writable by admins, but some type of API keys were leaked before (could've been obtained a long time ago) and the attackers held on to it until now to post a phishing link around the time when minting was supposed to open. It seems like the attacker even made a precaution move of DDOS'ing the real web site to make sure people can't go to the real one which adds credibility. This is a pretty high level effort attack.
The weakest link here seems to be that Discord is the trusted source of truth of communication from the project (not unlike emails are the trusted channel to verify identity for individual users on many web services). What's not yet known is whether some Discord-side security is compromised or the project admins had previously been phished/social-engineered to expose their API keys in the past.
- tomp 5y agoSo you're implying that the money got stolen, not lost as the title of the post claims?
- numbsafari 5y agoCould have been an inside job by the admins, too.
- secondcoming 5y agoThat was my first thought
- projct 5y agoThe key leak could just as easily be incompetence. Accidentally committed to git, or in their travis setup in such a way as to be easily obtainable, or a bunch of other options. High effort for high reward like this is not surprising but it could all start with incompetence.