ScareddyKat (@scareddyk) 's Twitter Profile
ScareddyKat

@scareddyk

Sharing my journey
🌈 Ions Follow Ions

ID: 1457412421266862081

calendar_today07-11-2021 18:20:03

1,1K Tweet

218 Takipçi

930 Takip Edilen

okHOTSHOT (@nftherder) 's Twitter Profile Photo

🚨 Finished my analysis of how scammers exploited 9 Discord servers today including Bored Ape Yacht Club 🍌 & doodles! Below are the facts & my conclusion 🚨 RT to spread awareness Read on ...

okHOTSHOT (@nftherder) 's Twitter Profile Photo

2) Normally this occurs via a form of social engineering through Direct Messages (DM) and gaining admin access so the scammers can post fake messages using web hooks. That is how a 140+ Discords got breached this year so far ...

2) Normally this occurs via a form of social engineering through Direct Messages (DM) and gaining admin access so the scammers can post fake messages using web hooks. That is how a 140+ Discords got breached this year so far ...
okHOTSHOT (@nftherder) 's Twitter Profile Photo

3) Today something different happened: the majority of the servers listed got breached through a verified Discord bot named Ticket Tool. A bot most Discords use to avoid the risk of DM scams ...

3) Today something different happened: the majority of the servers listed got breached through a verified Discord bot named Ticket Tool. A bot most Discords use to avoid the risk of DM scams ...
okHOTSHOT (@nftherder) 's Twitter Profile Photo

4) However their latest version had a bug that allowed $add and $remove commands to bypass perms they shouldn't have, granting normal users the ability to assign web hooks to users ...

4) However their latest version had a bug that allowed $add and $remove commands to bypass perms they shouldn't have, granting normal users the ability to assign web hooks to users ...
okHOTSHOT (@nftherder) 's Twitter Profile Photo

5) These web hooks were then abused to push scam announcements to the servers with the intention of luring collectors to fake minting sites. Which then steal your eth and valuable #NFTs ...

okHOTSHOT (@nftherder) 's Twitter Profile Photo

6) Here you can see the attacks were most likely coordinated, similar web design, and obfuscating their JavaScript for the BAYC and Doodle sites ...

6) Here you can see the attacks were most likely coordinated, similar web design, and obfuscating their JavaScript for the BAYC and Doodle sites ...
okHOTSHOT (@nftherder) 's Twitter Profile Photo

7) To avoid security issues you can disable all commands in Ticket Tool: Navigation -> Command config -> Uncheck commands Or limit the perms to Allowed Roles only. See the following screenshots for details

7) To avoid security issues you can disable all commands in Ticket Tool:

Navigation -> Command config -> Uncheck commands

Or limit the perms to Allowed Roles only. See the following screenshots for details
okHOTSHOT (@nftherder) 's Twitter Profile Photo

8) Ticket Tool has stated they've reverted to the previous uncompromised version that doesn't have the bug. And they've also regenerated their Discord token just in case. However, if you don't feel comfortable there are alternatives you can use ...

8) Ticket Tool has stated they've reverted to the previous uncompromised version that doesn't have the bug. And they've also regenerated their Discord token just in case. However, if you don't feel comfortable there are alternatives you can use ...
ScareddyKat (@scareddyk) 's Twitter Profile Photo

When you're happy you got WL in a game, but figure out it's going to be a slow rug pull Disinterested members. Alarmingly low discord group count No activity, some of the old moderators have pulled out. A week before mint date, giving away WL for invites No doxx.

Imaginary Ones | $BUBBLE 🫧🫧🫧 (@imaginary_ones) 's Twitter Profile Photo

[1/2] Congratulations to the winners! We will group dm you shortly Cryptocr*** ruion*** Living*** GGr*** krazyj*** JamilaFrazi*** Patrici19325*** DeFiJer*** varuna*** sliklov*** djthedj*** ShaikRas***