Avalanche and ZkSync Discord Servers Have Been Taken Over
This past weekend, the Discord servers of several high-profile blockchain projects were subject to a similar series of attacks. These attacks created a major security issue by sharing malicious links that directed users to fake token distribution schemes.
The official Discord servers of Layer-1 network Avalanche and Layer-2 blockchain ZKsync faced similar attacks just 48 hours after Polygon’s Discord server was taken over.
Specifically, a post on Avalanche’s official X account on August 25 stated that the Discord server had been taken over and users should not click on any links or interact. This statement was made to protect users from possible harmful links.
According to screenshots shared by the Avalanche Discord community on X, the attackers shared several links leading to fake “distribution” plans for Avalanche tokens.
These links claimed that token holders and community members could receive free AVAX. An hour later, Avalanche’s community leader Ben Well stated that the team had “found” the issue and fixed it.
He also stated that the team continues to work on restoring the server to normal. However, just an hour after the Avalanche attack, ZkSync’s official Discord server was reported to have been similarly compromised.
In the ZkSync attack, hackers again shared malicious links and offered a fake “second round airdrop” scheme promising users free ZK tokens. These types of scams often aim to steal users’ personal information or crypto assets by offering them fake deals.
Although ZkSync has not yet made a statement regarding this attack, some members of the ZkSync team stated that they noticed the situation via Discord.
The attacks on Avalanche and ZkSync occurred less than 48 hours after Polygon’s official Discord server was compromised. On Polygon’s Discord server, hackers shared malicious links throughout the server.
Mudit Gupta, Polygon’s chief information security officer, confirmed this breach and warned users to avoid clicking on links shared in the Discord channel until the situation is fully remedied.
A user who interacted with what appeared to be an official announcement on Polygon’s Discord channel reported losing $150,000 worth of Ether. Such incidents can have a wide impact within crypto communities and seriously compromise the security of users.
These recent attacks indicate an increase in the number of similar exploits on Discord. On March 25, 2023, blockchain security firm CertiK uncovered a phishing scam circulating on Arbitrum’s Discord server.
This scam was edited through a hacked developer account and involved a fake announcement containing a malicious link. The Arbitrum attack showed that users should be wary of similar scams that compromise their personal information and crypto assets.
A similar situation occurred on May 5, 2023; The Gnus.AI artificial intelligence network suffered an exploit on Discord and lost approximately $1.27 million. Such attacks pose a constant threat to cryptocurrency communities and require users to pay more attention to security measures.
The frequency and impact of the attacks suggest that blockchain projects should review their security protocols and encourage users to be more wary of similar scams.
These incidents highlight the need for ongoing monitoring and proactive security measures to ensure the security of cryptocurrency communities. It is important for users to pay attention to announcements, especially from official channels, and to avoid harmful links.
Additionally, blockchain projects must develop effective strategies to educate users and minimize potential vulnerabilities.