bored-ape-yacht-club-and-otherside-metaverse-discord-servers-have-reportedly-been-hacked
In early June 2022, the Discord servers of both the Bored Ape Yacht Club (BAYC) and its associated metaverse project Otherside were compromised, leading to substantial losses for users. (Fortune)
According to reports, the attack started when the Discord account of BAYC’s community manager, Boris Vagner, was hijacked. Through that compromised account, the attacker posted phishing links in the official server channels of BAYC and Otherside, directing users to a fraudulent “reward” site that requested wallet signatures, ultimately draining NFTs and tokens. (Coin68)
Estimates of the damage vary: one source reported about 200 ETH worth of NFTs and assets stolen (~US$360,000) from the incident. (Investopedia) Other accounts reported some 145 ETH (≈US$260,000) plus the theft of ~32 NFTs across BAYC, its companion collections, and Otherside “Otherdeed” items. (Báo Thanh Niên)
The incident highlights a crucial vulnerability in Web3‑community infrastructure: while blockchain assets may be secured, the front‑end community platforms (like Discord) remain high‑risk vectors. As one commentary put it, “Our Discord servers were briefly exploited today… about 200 ETH worth of NFTs appear to have been impacted.” (Fortune)
For users and projects in the NFT/metaverse space, the lessons are clear:
- Always treat external links with extreme caution, especially when coming from “official” channels — verify via trusted squad announcements.
- Never sign transactions unless you know exactly what you are doing; hackers rely on social engineering to prompt users to authorize malicious transfers.
- Projects should harden access controls for community‑manager accounts, enable stricter supervision of announcements, and consider safer platforms or layered authentication beyond standard Discord procedures.
In short: even flagship projects like BAYC and Otherside are not immune to phishing and social‑engineering attacks. Vigilance remains essential in the Web3 community.
