RTFKT Discord Breach: Difference between revisions
No edit summary |
(Beosin provided an alert about the MEE6 bot being compromised and listed the affected projects as @mypethooligan, @TheApiens, @CyberConnectHQ, @proof_xyz, @RTFKT, @Moonbirds, @memeland, and @AxieInfinity.) |
||
| Line 4: | Line 4: | ||
[[File:Rtfkt.jpg|thumb|RTFKT]]NFT platform RTFKT used MEE6, a widely implemented Discord bot which assists with ranking and moderation functions. MEE6 had administrative level access to a wide range of Discord servers where it was set up. One of the MEE6 employee accounts was compromised, and the attackers used that to run widespread phishing attacks on multiple NFT communities, including RTFKT. The NFT space often has time-sensitive opportunities. It's unclear exactly how many users were affected, and it seems that no funds have been recovered. MEE6 has apparently not published further details about what happened. RTFKT doesn't appear to have made a public announcement, much less any reimbursement, however they did provide a later educational session along with Ledger via Discord. | [[File:Rtfkt.jpg|thumb|RTFKT]]NFT platform RTFKT used MEE6, a widely implemented Discord bot which assists with ranking and moderation functions. MEE6 had administrative level access to a wide range of Discord servers where it was set up. One of the MEE6 employee accounts was compromised, and the attackers used that to run widespread phishing attacks on multiple NFT communities, including RTFKT. The NFT space often has time-sensitive opportunities. It's unclear exactly how many users were affected, and it seems that no funds have been recovered. MEE6 has apparently not published further details about what happened. RTFKT doesn't appear to have made a public announcement, much less any reimbursement, however they did provide a later educational session along with Ledger via Discord. | ||
This is a global/international case not involving a specific country. | This is a global/international case not involving a specific country.<ref name="chox3twitter-9746" /><ref name="mekamrantwitter-9730" /><ref name="trickynftstwitter-9731" /><ref name="ryukdevtwitter-9732" /><ref name="lukenamoptwitter-9733" /><ref name="zeneca33twitter-9734" /><ref name="nftherdertwitter-9717" /><ref name="nftherdertwitter-9747" /><ref name="nftherdertwitter-9748" /><ref name="peckshieldalerttwitter-9750" /><ref name="vice-9714" /><ref name="crastbiz-9776" /><ref name="cpomagazine-9761" /><ref name="vpnoverview-9777" /> | ||
== About RTFKT == | == About RTFKT == | ||
<ref name="rtfkt-9735" /><ref name="rtfkt-9736" /> | |||
"The Future is Now" "Formed by three friends at the beginning of the COVID pandemic in Jan 2020, RTFKT was born in the metaverse, and this has defined us to this day." "RTFKT is an eclectic, future-focused, creator-led organization. We use the latest in game engines, NFTs, blockchain authentication and augmented reality, combined with design and manufacturing expertise to create unique experiences with phygital fashion, sneakers, and digital artifacts." | "The Future is Now" "Formed by three friends at the beginning of the COVID pandemic in Jan 2020, RTFKT was born in the metaverse, and this has defined us to this day." "RTFKT is an eclectic, future-focused, creator-led organization. We use the latest in game engines, NFTs, blockchain authentication and augmented reality, combined with design and manufacturing expertise to create unique experiences with phygital fashion, sneakers, and digital artifacts." | ||
"We are known to create viral sneaker designs, collectible exclusives, 3D & AR wearables, unique avatars and original art. RTFKT has maintained a reputation of being more than a little ahead of the latest cutting-edge technology, a rep that has many mystified, as RTFKT would appear to lack the resources and manpower to rival giants in terms of research and development in the birth of digital fashion." | "We are known to create viral sneaker designs, collectible exclusives, 3D & AR wearables, unique avatars and original art. RTFKT has maintained a reputation of being more than a little ahead of the latest cutting-edge technology, a rep that has many mystified, as RTFKT would appear to lack the resources and manpower to rival giants in terms of research and development in the birth of digital fashion." | ||
== About MEE6 == | |||
<ref name="mee6-9715" /><ref name="discords-9716" /> | |||
"MEE6 is a 2-year-old Discord bot known for Levels, Auto-moderation, and its' paid music/record features. We also offer Reddit/Twitch/YouTube notifications, timers, custom commands, and other moderation features." "The best Discord Bot for your server." "Configure moderation, leveling, Twitch alerts, and much more with the most easy-to-use dashboard!" "Take advantage of the welcome message to inform newcomers about your server rules, topic, or ongoing events. You can design your own welcome card or keep it simple." | "MEE6 is a 2-year-old Discord bot known for Levels, Auto-moderation, and its' paid music/record features. We also offer Reddit/Twitch/YouTube notifications, timers, custom commands, and other moderation features." "The best Discord Bot for your server." "Configure moderation, leveling, Twitch alerts, and much more with the most easy-to-use dashboard!" "Take advantage of the welcome message to inform newcomers about your server rules, topic, or ongoing events. You can design your own welcome card or keep it simple." | ||
| Line 49: | Line 54: | ||
== The Reality == | == The Reality == | ||
Discord vulnerabilities. <ref name="threatpost-9693" /> | |||
This sections is included if a case involved deception or information that was unknown at the time. Examples include: | This sections is included if a case involved deception or information that was unknown at the time. Examples include: | ||
| Line 63: | Line 70: | ||
!Event | !Event | ||
!Description | !Description | ||
|- | |||
|April 11th, 2022 3:06:00 AM MDT | |||
|MEE6 NFT Bullishness | |||
|Twitter user eggbomb.eth posts that he's bullish about the MEE6 NFT because "projects like CyberKongz, Doodles, Cool Cats, Veefriends, RTFKT and many more are using MEE6 Bot within their server"<ref name="eggb0mbtwitter-97452">[https://twitter.com/eggb0mb_/status/1513443469406183425 eggb0mb_ - "projects like CyberKongz, Doodles, Cool Cats, Veefriends, RTFKT and many more are using MEE6 Bot within their server" - Twitter] (Nov 24, 2022)</ref>. | |||
|- | |- | ||
|May 17th, 2022 7:29:00 PM MDT | |May 17th, 2022 7:29:00 PM MDT | ||
| | |Warning By WIMPZ | ||
| | |Twitter user WIMPZ warns that "[i]f using MEE6 in your Discord, it has been compromised/hacked - per sources. RTFKT and Moonbirds/Proof may have been hit."<ref name="wlmpztwitter-9742" /> | ||
|- | |||
|May 17th, 2022 7:45:00 PM MDT | |||
|Warning By Mina | |||
|Twitter user Mina Gameel warns that the "Mee6 bot is hacked[, w]hich is used in alot of NFT Discord". She mentions that Memeland, RTFKT, and Proof servers have all been hacked, and warns to "[b]e [c]autious" and not to "click any links" or "connect your wallet"<ref name="minagamilazertwitter-97412">[https://twitter.com/MinaGamilAzer/status/1526740733633343489 MinaGamilAzer - "Mee6 bot is hacked Which is used in alot of NFT Discord Memeland, Rtfkt & Proof servers got hacked" - Twitter] (Nov 24, 2022)</ref>. | |||
|- | |||
|May 17th, 2022 10:02:00 PM MDT | |||
|Jake H Twitter Analysis | |||
|Jake H publishes a detailed thread explaining what he calls the "New Account Hacking Method". They outlined how administrators of projects would be approached with collaboration offers, and fake verification bots would be used to gain credentials to the Discord account of the administrator, which could then be used through webhooks to post the messages<ref name="777skitstwitter-97372">[https://twitter.com/777Skits/status/1526775285164691457 Jake H - "The recent discord hacks utilizing MEE6 and compromised admin accounts: New account hacking method below" - Twitter] (Nov 23, 2022)</ref>. | |||
|- | |||
|May 18th, 2022 12:45:00 AM MDT | |||
|Beosin Alert Tweet | |||
|Beosin provided an alert about the MEE6 bot being compromised and listed the affected projects as @mypethooligan, @TheApiens, @CyberConnectHQ, @proof_xyz, @RTFKT, @Moonbirds, @memeland, and @AxieInfinity<ref name="beosinalerttwitter-9727" />. | |||
|- | |||
|May 18th, 2022 3:50:10 AM MDT | |||
|Vauld Insights Article | |||
|Vauld Insights publishes an article on the situation. They cover over the attack and note that "Memeland, RTFKT, CLONEX, PXN, and Moonbird were compromised along with the NFT video game Axie Infinity". According to the article, MEE6 was denying the hacking claim at this time<ref name="vauld-97392">[https://www.vauld.com/insights/nft-discord-hack-mee6-discord-bot-hack-triggers-a-domino-effect/ NFT Discord Hack: Mee6 Discord Bot Hack Triggers A Domino Effect - Vauld Insights] (Nov 23, 2022)</ref>. | |||
|- | |||
|May 18th, 2022 6:23:00 AM MDT | |||
|MEE6 Twitter Acknowledgement | |||
|The MEE6 Twitter account publicly acknowledges the attack. They report it was due to one of their employee's accounts getting compromised, and they've taken "all the steps" to make sure it never happens again<ref name="mee6bottwitter-97182">[https://twitter.com/mee6bot/status/1526901242521432065 mee6bot - "Some servers have reported MEE6 being used to post unwanted messages." - Twitter] (Nov 23, 2022)</ref><ref name="nftherdertwitter-97192">[https://twitter.com/NFTherder/status/1526946239769628676 NFTherder - "Turns out there was some truth about the MEE6 compromise: MEE6 wasn't hacked itself however an employee of their company had their account breached" - Twitter] (Nov 23, 2022)</ref>. | |||
|- | |||
|May 18th, 2022 11:28:00 AM MDT | |||
|RyanCAD Summary Published | |||
|Twitter user RyanCAD publishes a "thread summarizing the recent Discord attacks of several high-profile servers including @CoolCats, @RTFKT, @projectPXN, @moonbirds and more". This includes a summary of how the bot behaved as well as the particular actions which were taken along with a log file from RTFKT. His recommendation is to change your password frequently<ref name="web3specialisttwitter-9744" />. | |||
|- | |- | ||
| | |May 18th, 2022 10:12:00 PM MDT | ||
| | |NFTherder Request For Reimbursement | ||
| | |NFTherder requests reimbursement from MEE6 on Twitter, warning that they'll "lose all credibility in the nft space" if they don't<ref name="nftherdertwitter-97222">[https://twitter.com/NFTherder/status/1527139992706945024 NFTherder - "If MEE6 won’t offer any reimbursement you’ll lose all credibility in the nft space imo." - Twitter] (Nov 23, 2022)</ref>. | ||
|- | |||
|May 19th, 2022 10:52:00 AM MDT | |||
|RTFKT Ledger Office Hours | |||
|The RTFKT team works with Ledger and announces a live show to cover "[b]lind signing vs clear signing", "Ledger connect", and "Discord bots / fake links"<ref name="rtfkttwitter-9740" />. | |||
|- | |||
|May 31st, 2022 11:08:16 AM MDT | |||
|NFTEvening Negligence Article | |||
|The NFTEvening news site publishes an article originally titled "NFT Twitter Accuses Discord Bot MEE6 of Negligence"<ref>[https://web.archive.org/web/20220531170816/https://nftevening.com/nft-twitter-accuses-discord-bot-mee6-of-negligence/ NFT Twitter Accuses Discord Bot MEE6 of Negligence - NFTEvening] (Apr 13, 2023)</ref> and later retitled "MEE6 Discord Bot Accused of Negligence"<ref name="nftevening-97212">[https://nftevening.com/nft-twitter-accuses-discord-bot-mee6-of-negligence/ MEE6 Discord Bot Accused of Negligence - NFTEvening] (Nov 23, 2022)</ref>. TBD read more detail. | |||
|- | |||
|June 7th, 2022 6:41:00 AM MDT | |||
|NFTherder Again Requests Reimbursement | |||
|NFTherder again publicly requests reimbursement and acknowledgement from the MEE6 team, in response to the launch of their NFT project<ref name="nftherdertwitter-97232">[https://twitter.com/NFTherder/status/1534153621084033026 NFTherder - "what would be even cooler? Addressing the fact that because of your MEE6 over 200 eth was stolen and you've been dodging communication ever since." - Twitter] (Nov 23, 2022)</ref>. | |||
|- | |||
|June 8th, 2022 3:53:00 AM MDT | |||
|NFTherder Public Criticism | |||
|NFTherder posts at "3 weeks" later that it's "[t]ime to stop using MEE6" because there are "[n]o official report or refunds" and shares the NFTEvening article<ref name="nftherdertwitter-97202">[https://twitter.com/NFTherder/status/1534473652166660097 NFTherder - "3 weeks since between 200/300E was stolen cause a @mee6bot employee had remote admin access to nft servers he wasn't supposed to have. No official report or refunds." Twitter] (Nov 23, 2022)</ref>. | |||
|- | |||
|June 8th, 2022 5:41:00 AM MDT | |||
|NFTherder Reaching Out To Other Servers | |||
|NFTherder reaches out to affected servers and confirms that "MEE6 hasn't shared a detailed report or offered reimbursements of misappropriated nfts/eth"<ref name="nftherdertwitter-97252">[https://twitter.com/NFTherder/status/1534500963951595520 NFTherder - "I've reached out to affected servers as well and they confirmed MEE6 hasn't shared a detailed report or offered reimbursements of misappropriated nfts/eth." - Twitter] (Nov 23, 2022)</ref>. | |||
|- | |||
|June 9th, 2022 6:06:00 PM MDT | |||
|NFTherder Stops Using MEE6 Bot | |||
|NFTherder posts on Twitter that they will "stop using MEE6 on all future servers", citing "no intention to refund", "they won't release a public statement", and "employees can still remote access any server"<ref name="nftherdertwitter-97382">[https://twitter.com/NFTherder/status/1535050682914328576 NFTherder - "no intentions to refund...employees can still remote access any server" - Twitter] (Nov 23, 2022)</ref>. He expands that "[right now] anything is preferred over mee6"<ref name="nftherdertwitter-97242">[https://twitter.com/NFTherder/status/1535051685227560970 NFTherder - "rn anything is preferred over mee6" - Twitter] (Nov 23, 2022)</ref>. | |||
|- | |||
|June 10th, 2022 3:59:00 PM MDT | |||
|Jack Tracante Information | |||
|Jack Tracante has some additional information on how servers are managed. "The channel with these logs can only be seen by a few people so we know exactly what happened. When RTFKT had their hack they were able to see the MEE6 bot was the culprit for example."<ref name="jacktracantetwitter-9743" /> | |||
|} | |} | ||
| Line 111: | Line 174: | ||
== References == | == References == | ||
<references><ref name="threatpost-9693">[https://threatpost.com/scammers-target-nft-discord-channel/179827/ Scammers Target NFT Discord Channel | Threatpost] (Jul 17, 2022)</ref> | <references> | ||
<ref name="threatpost-9693">[https://threatpost.com/scammers-target-nft-discord-channel/179827/ Scammers Target NFT Discord Channel | Threatpost] (Jul 17, 2022)</ref> | |||
<ref name="rtfkt-9735">[https://rtfkt.com/ RTFKT] (Nov 17, 2022)</ref> | <ref name="rtfkt-9735">[https://rtfkt.com/ RTFKT] (Nov 17, 2022)</ref> | ||
<ref name="rtfkt-9736">[https://rtfkt.com/wtf RTFKT] (Nov 18, 2022)</ref> | <ref name="rtfkt-9736">[https://rtfkt.com/wtf RTFKT] (Nov 18, 2022)</ref> | ||
<ref name="mee6-9715">[https://mee6.xyz/en/ Discord Bot | MEE6] (Nov 23, 2022)</ref> | <ref name="mee6-9715">[https://mee6.xyz/en/ Discord Bot | MEE6] (Nov 23, 2022)</ref> | ||
<ref name="discords-9716">[https://discords.com/bots/bot/mee6 MEE6 | Discord Bots | Discords.com] (Nov 23, 2022)</ref> | <ref name="discords-9716">[https://discords.com/bots/bot/mee6 MEE6 | Discord Bots | Discords.com] (Nov 23, 2022)</ref> | ||
<ref name="mee6bottwitter-9718">[https://twitter.com/mee6bot/status/1526901242521432065 @mee6bot Twitter] (Nov 23, 2022)</ref> | <ref name="mee6bottwitter-9718">[https://twitter.com/mee6bot/status/1526901242521432065 @mee6bot Twitter] (Nov 23, 2022)</ref> | ||
<ref name="777skitstwitter-9737">[https://twitter.com/777Skits/status/1526775285164691457 @777Skits Twitter] (Nov 23, 2022)</ref> | <ref name="777skitstwitter-9737">[https://twitter.com/777Skits/status/1526775285164691457 @777Skits Twitter] (Nov 23, 2022)</ref> | ||
<ref name="nftherdertwitter-9719">[https://twitter.com/NFTherder/status/1526946239769628676 @NFTherder Twitter] (Nov 23, 2022)</ref> | <ref name="nftherdertwitter-9719">[https://twitter.com/NFTherder/status/1526946239769628676 @NFTherder Twitter] (Nov 23, 2022)</ref> | ||
<ref name="nftherdertwitter-9738">[https://twitter.com/NFTherder/status/1535050682914328576 @NFTherder Twitter] (Nov 23, 2022)</ref> | <ref name="nftherdertwitter-9738">[https://twitter.com/NFTherder/status/1535050682914328576 @NFTherder Twitter] (Nov 23, 2022)</ref> | ||
<ref name="nftherdertwitter-9720">[https://twitter.com/NFTherder/status/1534473652166660097 @NFTherder Twitter] (Nov 23, 2022)</ref> | <ref name="nftherdertwitter-9720">[https://twitter.com/NFTherder/status/1534473652166660097 @NFTherder Twitter] (Nov 23, 2022)</ref> | ||
<ref name="nftevening-9721">[https://nftevening.com/nft-twitter-accuses-discord-bot-mee6-of-negligence/ MEE6 Discord Bot Accused of Negligence] (Nov 23, 2022)</ref> | <ref name="nftevening-9721">[https://nftevening.com/nft-twitter-accuses-discord-bot-mee6-of-negligence/ MEE6 Discord Bot Accused of Negligence] (Nov 23, 2022)</ref> | ||
<ref name="nftherdertwitter-9722">[https://twitter.com/NFTherder/status/1527139992706945024 @NFTherder Twitter] (Nov 23, 2022)</ref> | <ref name="nftherdertwitter-9722">[https://twitter.com/NFTherder/status/1527139992706945024 @NFTherder Twitter] (Nov 23, 2022)</ref> | ||
<ref name="nftherdertwitter-9723">[https://twitter.com/NFTherder/status/1534153621084033026 @NFTherder Twitter] (Nov 23, 2022)</ref> | <ref name="nftherdertwitter-9723">[https://twitter.com/NFTherder/status/1534153621084033026 @NFTherder Twitter] (Nov 23, 2022)</ref> | ||
<ref name="nftherdertwitter-9724">[https://twitter.com/NFTherder/status/1535051685227560970 @NFTherder Twitter] (Nov 23, 2022)</ref> | <ref name="nftherdertwitter-9724">[https://twitter.com/NFTherder/status/1535051685227560970 @NFTherder Twitter] (Nov 23, 2022)</ref> | ||
<ref name="nftherdertwitter-9725">[https://twitter.com/NFTherder/status/1534500963951595520 @NFTherder Twitter] (Nov 23, 2022)</ref> | <ref name="nftherdertwitter-9725">[https://twitter.com/NFTherder/status/1534500963951595520 @NFTherder Twitter] (Nov 23, 2022)</ref> | ||
<ref name="vauld-9739">[https://www.vauld.com/insights/nft-discord-hack-mee6-discord-bot-hack-triggers-a-domino-effect/ NFT Discord Hack: Mee6 Discord Bot Hack Triggers A Domino Effect - Vauld Insights] (Nov 23, 2022)</ref> | <ref name="vauld-9739">[https://www.vauld.com/insights/nft-discord-hack-mee6-discord-bot-hack-triggers-a-domino-effect/ NFT Discord Hack: Mee6 Discord Bot Hack Triggers A Domino Effect - Vauld Insights] (Nov 23, 2022)</ref> | ||
<ref name="rtfkttwitter-9740">[https://twitter.com/RTFKT/status/1527331247143280651 RTFKT - "In 10 min we go live again with @Ledger office hours in our discord." - Twitter] (Nov 24, 2022)</ref> | |||
<ref name="rtfkttwitter-9740">[https://twitter.com/RTFKT/status/1527331247143280651 @ | <ref name="minagamilazertwitter-9741">[https://twitter.com/MinaGamilAzer/status/1526740733633343489 MinaGamilAzer - "Mee6 bot is hacked Which is used in alot of NFT Discord Memeland, Rtfkt & Proof servers got hacked" - Twitter] (Nov 24, 2022)</ref> | ||
<ref name="wlmpztwitter-9742">[https://twitter.com/WlMPZ_/status/1526736810474450944 WlMPZ_ - "If using MEE6 in your Discord, it has been compromised/hacked - per sources. RTFKT and Moonbirds/Proof may have been hit." - Twitter] (Nov 24, 2022)</ref> | |||
<ref name="minagamilazertwitter-9741">[https://twitter.com/MinaGamilAzer/status/1526740733633343489 | <ref name="jacktracantetwitter-9743">[https://twitter.com/JackTracante/status/1535381151325782016 JackTracante - "The channel with these logs can only be seen by a few people so we know exactly what happened. When RTFKT had their hack they were able to see the MEE6 bot was the culprit for example." - Twitter] (Nov 24, 2022)</ref> | ||
<ref name="web3specialisttwitter-9744">[https://twitter.com/web3specialist/status/1526978159509286912 web3specialist - "A thread summarizing the recent Discord attacks of several high-profile servers including @CoolCats, @RTFKT, @projectPXN, @moonbirds and more" - Twitter] (Nov 24, 2022)</ref> | |||
<ref name="wlmpztwitter-9742">[https://twitter.com/WlMPZ_/status/1526736810474450944 | |||
<ref name="jacktracantetwitter-9743">[https://twitter.com/JackTracante/status/1535381151325782016 | |||
<ref name="web3specialisttwitter-9744">[https://twitter.com/web3specialist/status/1526978159509286912 @ | |||
<ref name="eggb0mbtwitter-9745">[https://twitter.com/eggb0mb_/status/1513443469406183425 @eggb0mb_ Twitter] (Nov 24, 2022)</ref> | <ref name="eggb0mbtwitter-9745">[https://twitter.com/eggb0mb_/status/1513443469406183425 @eggb0mb_ Twitter] (Nov 24, 2022)</ref> | ||
<ref name="beosinalerttwitter-9727">[https://twitter.com/BeosinAlert/status/1526816268724350976 BeosinAlert - "mee6 bot is compromised and have affected multiple Discord servers" - Twitter] (Nov 24, 2022)</ref> | |||
<ref name="beosinalerttwitter-9727">[https://twitter.com/BeosinAlert/status/1526816268724350976 | |||
<ref name="chox3twitter-9746">[https://twitter.com/CHOX3__/status/1519240898437328898 @CHOX3__ Twitter] (Nov 24, 2022)</ref> | <ref name="chox3twitter-9746">[https://twitter.com/CHOX3__/status/1519240898437328898 @CHOX3__ Twitter] (Nov 24, 2022)</ref> | ||
<ref name="mekamrantwitter-9730">[https://twitter.com/mekamran/status/1514010785776812041 @mekamran Twitter] (Nov 24, 2022)</ref> | <ref name="mekamrantwitter-9730">[https://twitter.com/mekamran/status/1514010785776812041 @mekamran Twitter] (Nov 24, 2022)</ref> | ||
<ref name="trickynftstwitter-9731">[https://twitter.com/Tricky_NFTs/status/1526849651546144769 @Tricky_NFTs Twitter] (Nov 24, 2022)</ref> | <ref name="trickynftstwitter-9731">[https://twitter.com/Tricky_NFTs/status/1526849651546144769 @Tricky_NFTs Twitter] (Nov 24, 2022)</ref> | ||
<ref name="ryukdevtwitter-9732">[https://twitter.com/ryuk_dev/status/1526771791959453696 @ryuk_dev Twitter] (Nov 24, 2022)</ref> | <ref name="ryukdevtwitter-9732">[https://twitter.com/ryuk_dev/status/1526771791959453696 @ryuk_dev Twitter] (Nov 24, 2022)</ref> | ||
<ref name="lukenamoptwitter-9733">[https://twitter.com/lukenamop/status/1526855835527303171 @lukenamop Twitter] (Nov 24, 2022)</ref> | <ref name="lukenamoptwitter-9733">[https://twitter.com/lukenamop/status/1526855835527303171 @lukenamop Twitter] (Nov 24, 2022)</ref> | ||
<ref name="zeneca33twitter-9734">[https://twitter.com/Zeneca_33/status/1526752181122224129 @Zeneca_33 Twitter] (Nov 24, 2022)</ref> | <ref name="zeneca33twitter-9734">[https://twitter.com/Zeneca_33/status/1526752181122224129 @Zeneca_33 Twitter] (Nov 24, 2022)</ref> | ||
<ref name="nftherdertwitter-9717">[https://twitter.com/NFTherder/status/1526758429636931585 @NFTherder Twitter] (Nov 23, 2022)</ref> | <ref name="nftherdertwitter-9717">[https://twitter.com/NFTherder/status/1526758429636931585 @NFTherder Twitter] (Nov 23, 2022)</ref> | ||
<ref name="nftherdertwitter-9747">[https://twitter.com/NFTherder/status/1526950199767314432 @NFTherder Twitter] (Nov 24, 2022)</ref> | <ref name="nftherdertwitter-9747">[https://twitter.com/NFTherder/status/1526950199767314432 @NFTherder Twitter] (Nov 24, 2022)</ref> | ||
<ref name="nftherdertwitter-9748">[https://twitter.com/NFTherder/status/1531307520366632964 @NFTherder Twitter] (Nov 24, 2022)</ref> | <ref name="nftherdertwitter-9748">[https://twitter.com/NFTherder/status/1531307520366632964 @NFTherder Twitter] (Nov 24, 2022)</ref> | ||
<ref name="peckshieldalerttwitter-9750">[https://twitter.com/PeckShieldAlert/status/1526748738068156417 @PeckShieldAlert Twitter] (Nov 24, 2022)</ref> | <ref name="peckshieldalerttwitter-9750">[https://twitter.com/PeckShieldAlert/status/1526748738068156417 @PeckShieldAlert Twitter] (Nov 24, 2022)</ref> | ||
<ref name="vice-9714">[https://www.vice.com/en/article/k7wmpy/hackers-compromise-a-string-of-nft-discord-channels Hackers Compromise a String of NFT Discord Channels] (Nov 23, 2022)</ref> | <ref name="vice-9714">[https://www.vice.com/en/article/k7wmpy/hackers-compromise-a-string-of-nft-discord-channels Hackers Compromise a String of NFT Discord Channels] (Nov 23, 2022)</ref> | ||
<ref name="crastbiz-9776">[https://biz.crast.net/nft-twitter-accuses-discord-bot-mee6-of-negligence/ NFT Twitter accuses discord bot MEE6 of negligence - Business News] (Nov 24, 2022)</ref> | <ref name="crastbiz-9776">[https://biz.crast.net/nft-twitter-accuses-discord-bot-mee6-of-negligence/ NFT Twitter accuses discord bot MEE6 of negligence - Business News] (Nov 24, 2022)</ref> | ||
<ref name="cpomagazine-9761">[https://www.cpomagazine.com/cyber-security/multiple-nft-projects-attacked-after-commonly-used-mee6-discord-bot-hacked/ Multiple NFT Projects Attacked After Commonly-Used "Mee6" Discord Bot Hacked - CPO Magazine] (Nov 23, 2022)</ref> | <ref name="cpomagazine-9761">[https://www.cpomagazine.com/cyber-security/multiple-nft-projects-attacked-after-commonly-used-mee6-discord-bot-hacked/ Multiple NFT Projects Attacked After Commonly-Used "Mee6" Discord Bot Hacked - CPO Magazine] (Nov 23, 2022)</ref> | ||
<ref name="vpnoverview-9777">[https://vpnoverview.com/news/hackers-use-discord-bot-to-infiltrate-nft-channels-in-phishing-attack/ Hackers Use Discord Bot to Infiltrate NFT Channels in Phishing Attack] (Nov 24, 2022)</ref> | |||
<ref name="vpnoverview-9777">[https://vpnoverview.com/news/hackers-use-discord-bot-to-infiltrate-nft-channels-in-phishing-attack/ Hackers Use Discord Bot to Infiltrate NFT Channels in Phishing Attack] (Nov 24, 2022)</ref></references> | </references> | ||
Revision as of 13:57, 17 April 2023
Notice: This page is a freshly imported case study from the original repository. The original content was in a different format, and may not have relevant information for all sections. Please help restructure the content by moving information from the 'About' and 'General Prevention' sections to other sections, and add any missing information or sources you can find. If you are new here, please read General Tutorial on Wikis or Anatomy of a Case Study for help getting started.
Notice: This page contains sources which are not attributed to any text. The unattributed sources follow the initial description. Please assist by visiting each source, reviewing the content, and placing that reference next to any text it can be used to support. Feel free to add any information that you come across which isn't present already. Sources which don't contain any relevant information can be removed. Broken links can be replaced with versions from the Internet Archive. See General Tutorial on Wikis, Anatomy of a Case Study, and/or Citing Your Sources Guide for additional information. Thanks for your help!
NFT platform RTFKT used MEE6, a widely implemented Discord bot which assists with ranking and moderation functions. MEE6 had administrative level access to a wide range of Discord servers where it was set up. One of the MEE6 employee accounts was compromised, and the attackers used that to run widespread phishing attacks on multiple NFT communities, including RTFKT. The NFT space often has time-sensitive opportunities. It's unclear exactly how many users were affected, and it seems that no funds have been recovered. MEE6 has apparently not published further details about what happened. RTFKT doesn't appear to have made a public announcement, much less any reimbursement, however they did provide a later educational session along with Ledger via Discord.
This is a global/international case not involving a specific country.[1][2][3][4][5][6][7][8][9][10][11][12][13][14]
About RTFKT
"The Future is Now" "Formed by three friends at the beginning of the COVID pandemic in Jan 2020, RTFKT was born in the metaverse, and this has defined us to this day." "RTFKT is an eclectic, future-focused, creator-led organization. We use the latest in game engines, NFTs, blockchain authentication and augmented reality, combined with design and manufacturing expertise to create unique experiences with phygital fashion, sneakers, and digital artifacts."
"We are known to create viral sneaker designs, collectible exclusives, 3D & AR wearables, unique avatars and original art. RTFKT has maintained a reputation of being more than a little ahead of the latest cutting-edge technology, a rep that has many mystified, as RTFKT would appear to lack the resources and manpower to rival giants in terms of research and development in the birth of digital fashion."
About MEE6
"MEE6 is a 2-year-old Discord bot known for Levels, Auto-moderation, and its' paid music/record features. We also offer Reddit/Twitch/YouTube notifications, timers, custom commands, and other moderation features." "The best Discord Bot for your server." "Configure moderation, leveling, Twitch alerts, and much more with the most easy-to-use dashboard!" "Take advantage of the welcome message to inform newcomers about your server rules, topic, or ongoing events. You can design your own welcome card or keep it simple."
"MEE6 gives you full control to create the command of your dreams! Create commands that automatically give and remove roles and send messages in the current channels or in user's DM." "Notify your server when you or your favorite content creators begin to stream, upload, and post content." "MEE6, the Discord Bot trusted by 19+ million servers." As of April 2022, "Mekaverse, Doodles, CyberKongz, VeeFriends, CoolCats, and RTFKT all use MEE6 everyday to manage their Discord server. More than 60,000 NFT & crypto Discord servers setup MEE6 every month, and that number is growing fast."
In a single week in mid-May "alone, [at least] 5 NFT discord hacks were observed. Discord servers of NFT projects including the Memeland, RTFKT, CLONEX, PXN, and Moonbird were compromised along with the NFT video game Axie Infinity, after Mee6 bot was hacked." "Another tweet was shared by PeckShield, a blockchain cybersecurity firm, warning users about compromised NFT Discord Server of Memeland, RTFKT, PROOF/Moonbirds and infrastructure company Cyberconnect."
"A team member of [similarly hacked] Memeland noted, “a discord bot (mee6) seems to be compromised across various high profile servers.” The mee6 bot is used by the server owners to automate welcome messages and inform about the server rules, events and topics." "Once you interact with these fake bots they will snag your discord token, giving them instant access to your account without 2FA or your password."
"With lots of high-profile crypto projects using Discord, this leakage of information can reveal “not-yet-announced partnerships, upcoming product launches, exchange listings, and coordinate multi-sig signers,” as reported by Fraser." "When RTFKT had their hack they were able to see the MEE6 bot was the culprit."
"MEE6's employee account was breached & scammers used that account to execute the scams and steal eth. MEE6 support denied it for hours yesterday [before later admitting what happened]."
MEE6 released a statement after the event: "Some servers have reported MEE6 being used to post unwanted messages. There is no technical breach in our systems. This was due to one of our employee's account getting compromised. The issue is now fixed and we've taken all the steps to make sure it never happens again. We take security very seriously, and will always be committed not only to keep our systems safe but also add extra measures to protect servers from accounts being compromised."
NFTHerder reports he "reached out to affected servers as well and they confirmed MEE6 hasn't shared a detailed report or offered reimbursements of misappropriated nfts/eth." "MEE6 has yet to release a detailed report." "[N]o intentions to refund. [T]hey won’t release a public statement cause scared of fud. [E]mployees can still remote access any server."
"In 10 min we go live again with @Ledger office hours in our discord. Topics: (1) Blind signing vs clear signing. (2) Ledger connect. (3) Discord bots / fake links."
This is a global/international case not involving a specific country.
The background of the exchange platform, service, or individuals involved, as it would have been seen or understood at the time of the events.
Include:
- Known history of when and how the service was started.
- What problems does the company or service claim to solve?
- What marketing materials were used by the firm or business?
- Audits performed, and excerpts that may have been included.
- Business registration documents shown (fake or legitimate).
- How were people recruited to participate?
- Public warnings and announcements prior to the event.
Don't Include:
- Any wording which directly states or implies that the business is/was illegitimate, or that a vulnerability existed.
- Anything that wasn't reasonably knowable at the time of the event.
There could be more than one section here. If the same platform is involved with multiple incidents, then it can be linked to a main article page.
The Reality
Discord vulnerabilities. [19]
This sections is included if a case involved deception or information that was unknown at the time. Examples include:
- When the service was actually started (if different than the "official story").
- Who actually ran a service and their own personal history.
- How the service was structured behind the scenes. (For example, there was no "trading bot".)
- Details of what audits reported and how vulnerabilities were missed during auditing.
What Happened
The specific events of the loss and how it came about. What actually happened to cause the loss and some of the events leading up to it.
| Date | Event | Description |
|---|---|---|
| April 11th, 2022 3:06:00 AM MDT | MEE6 NFT Bullishness | Twitter user eggbomb.eth posts that he's bullish about the MEE6 NFT because "projects like CyberKongz, Doodles, Cool Cats, Veefriends, RTFKT and many more are using MEE6 Bot within their server"[20]. |
| May 17th, 2022 7:29:00 PM MDT | Warning By WIMPZ | Twitter user WIMPZ warns that "[i]f using MEE6 in your Discord, it has been compromised/hacked - per sources. RTFKT and Moonbirds/Proof may have been hit."[21] |
| May 17th, 2022 7:45:00 PM MDT | Warning By Mina | Twitter user Mina Gameel warns that the "Mee6 bot is hacked[, w]hich is used in alot of NFT Discord". She mentions that Memeland, RTFKT, and Proof servers have all been hacked, and warns to "[b]e [c]autious" and not to "click any links" or "connect your wallet"[22]. |
| May 17th, 2022 10:02:00 PM MDT | Jake H Twitter Analysis | Jake H publishes a detailed thread explaining what he calls the "New Account Hacking Method". They outlined how administrators of projects would be approached with collaboration offers, and fake verification bots would be used to gain credentials to the Discord account of the administrator, which could then be used through webhooks to post the messages[23]. |
| May 18th, 2022 12:45:00 AM MDT | Beosin Alert Tweet | Beosin provided an alert about the MEE6 bot being compromised and listed the affected projects as @mypethooligan, @TheApiens, @CyberConnectHQ, @proof_xyz, @RTFKT, @Moonbirds, @memeland, and @AxieInfinity[24]. |
| May 18th, 2022 3:50:10 AM MDT | Vauld Insights Article | Vauld Insights publishes an article on the situation. They cover over the attack and note that "Memeland, RTFKT, CLONEX, PXN, and Moonbird were compromised along with the NFT video game Axie Infinity". According to the article, MEE6 was denying the hacking claim at this time[25]. |
| May 18th, 2022 6:23:00 AM MDT | MEE6 Twitter Acknowledgement | The MEE6 Twitter account publicly acknowledges the attack. They report it was due to one of their employee's accounts getting compromised, and they've taken "all the steps" to make sure it never happens again[26][27]. |
| May 18th, 2022 11:28:00 AM MDT | RyanCAD Summary Published | Twitter user RyanCAD publishes a "thread summarizing the recent Discord attacks of several high-profile servers including @CoolCats, @RTFKT, @projectPXN, @moonbirds and more". This includes a summary of how the bot behaved as well as the particular actions which were taken along with a log file from RTFKT. His recommendation is to change your password frequently[28]. |
| May 18th, 2022 10:12:00 PM MDT | NFTherder Request For Reimbursement | NFTherder requests reimbursement from MEE6 on Twitter, warning that they'll "lose all credibility in the nft space" if they don't[29]. |
| May 19th, 2022 10:52:00 AM MDT | RTFKT Ledger Office Hours | The RTFKT team works with Ledger and announces a live show to cover "[b]lind signing vs clear signing", "Ledger connect", and "Discord bots / fake links"[30]. |
| May 31st, 2022 11:08:16 AM MDT | NFTEvening Negligence Article | The NFTEvening news site publishes an article originally titled "NFT Twitter Accuses Discord Bot MEE6 of Negligence"[31] and later retitled "MEE6 Discord Bot Accused of Negligence"[32]. TBD read more detail. |
| June 7th, 2022 6:41:00 AM MDT | NFTherder Again Requests Reimbursement | NFTherder again publicly requests reimbursement and acknowledgement from the MEE6 team, in response to the launch of their NFT project[33]. |
| June 8th, 2022 3:53:00 AM MDT | NFTherder Public Criticism | NFTherder posts at "3 weeks" later that it's "[t]ime to stop using MEE6" because there are "[n]o official report or refunds" and shares the NFTEvening article[34]. |
| June 8th, 2022 5:41:00 AM MDT | NFTherder Reaching Out To Other Servers | NFTherder reaches out to affected servers and confirms that "MEE6 hasn't shared a detailed report or offered reimbursements of misappropriated nfts/eth"[35]. |
| June 9th, 2022 6:06:00 PM MDT | NFTherder Stops Using MEE6 Bot | NFTherder posts on Twitter that they will "stop using MEE6 on all future servers", citing "no intention to refund", "they won't release a public statement", and "employees can still remote access any server"[36]. He expands that "[right now] anything is preferred over mee6"[37]. |
| June 10th, 2022 3:59:00 PM MDT | Jack Tracante Information | Jack Tracante has some additional information on how servers are managed. "The channel with these logs can only be seen by a few people so we know exactly what happened. When RTFKT had their hack they were able to see the MEE6 bot was the culprit for example."[38] |
Total Amount Lost
The total amount lost is unknown.
How much was lost and how was it calculated? If there are conflicting reports, which are accurate and where does the discrepancy lie?
Immediate Reactions
How did the various parties involved (firm, platform, management, and/or affected individual(s)) deal with the events? Were services shut down? Were announcements made? Were groups formed?
Ultimate Outcome
What was the end result? Was any investigation done? Were any individuals prosecuted? Was there a lawsuit? Was any tracing done?
Total Amount Recovered
There do not appear to have been any funds recovered in this case.
What funds were recovered? What funds were reimbursed for those affected users?
Ongoing Developments
What parts of this case are still remaining to be concluded?
General Prevention Policies
The primary issue was related to the security of the Discord server, which granted additional unnecessary permissions to the MEE6 bot. The widespread bot access should not fall under the control of a single employee or system, which may form a fundamental design limitation of Discord or the MEE6 bot system.
NFT traders can avoid falling victim to such fraud by not making rushed decisions, double checking any promotions against multiple sources, and avoiding any mints that seem to be too good to be true.
Individual Prevention Policies
No specific policies for individual prevention have yet been identified in this case.
For the full list of how to protect your funds as an individual, check our Prevention Policies for Individuals guide.
Platform Prevention Policies
Policies for platforms to take to prevent this situation have not yet been selected in this case.
For the full list of how to protect your funds as a financial service, check our Prevention Policies for Platforms guide.
Regulatory Prevention Policies
No specific regulatory policies have yet been identified in this case.
For the full list of regulatory policies that can prevent loss, check our Prevention Policies for Regulators guide.
References
- ↑ @CHOX3__ Twitter (Nov 24, 2022)
- ↑ @mekamran Twitter (Nov 24, 2022)
- ↑ @Tricky_NFTs Twitter (Nov 24, 2022)
- ↑ @ryuk_dev Twitter (Nov 24, 2022)
- ↑ @lukenamop Twitter (Nov 24, 2022)
- ↑ @Zeneca_33 Twitter (Nov 24, 2022)
- ↑ @NFTherder Twitter (Nov 23, 2022)
- ↑ @NFTherder Twitter (Nov 24, 2022)
- ↑ @NFTherder Twitter (Nov 24, 2022)
- ↑ @PeckShieldAlert Twitter (Nov 24, 2022)
- ↑ Hackers Compromise a String of NFT Discord Channels (Nov 23, 2022)
- ↑ NFT Twitter accuses discord bot MEE6 of negligence - Business News (Nov 24, 2022)
- ↑ Multiple NFT Projects Attacked After Commonly-Used "Mee6" Discord Bot Hacked - CPO Magazine (Nov 23, 2022)
- ↑ Hackers Use Discord Bot to Infiltrate NFT Channels in Phishing Attack (Nov 24, 2022)
- ↑ RTFKT (Nov 17, 2022)
- ↑ RTFKT (Nov 18, 2022)
- ↑ Discord Bot | MEE6 (Nov 23, 2022)
- ↑ MEE6 | Discord Bots | Discords.com (Nov 23, 2022)
- ↑ Scammers Target NFT Discord Channel | Threatpost (Jul 17, 2022)
- ↑ eggb0mb_ - "projects like CyberKongz, Doodles, Cool Cats, Veefriends, RTFKT and many more are using MEE6 Bot within their server" - Twitter (Nov 24, 2022)
- ↑ WlMPZ_ - "If using MEE6 in your Discord, it has been compromised/hacked - per sources. RTFKT and Moonbirds/Proof may have been hit." - Twitter (Nov 24, 2022)
- ↑ MinaGamilAzer - "Mee6 bot is hacked Which is used in alot of NFT Discord Memeland, Rtfkt & Proof servers got hacked" - Twitter (Nov 24, 2022)
- ↑ Jake H - "The recent discord hacks utilizing MEE6 and compromised admin accounts: New account hacking method below" - Twitter (Nov 23, 2022)
- ↑ BeosinAlert - "mee6 bot is compromised and have affected multiple Discord servers" - Twitter (Nov 24, 2022)
- ↑ NFT Discord Hack: Mee6 Discord Bot Hack Triggers A Domino Effect - Vauld Insights (Nov 23, 2022)
- ↑ mee6bot - "Some servers have reported MEE6 being used to post unwanted messages." - Twitter (Nov 23, 2022)
- ↑ NFTherder - "Turns out there was some truth about the MEE6 compromise: MEE6 wasn't hacked itself however an employee of their company had their account breached" - Twitter (Nov 23, 2022)
- ↑ web3specialist - "A thread summarizing the recent Discord attacks of several high-profile servers including @CoolCats, @RTFKT, @projectPXN, @moonbirds and more" - Twitter (Nov 24, 2022)
- ↑ NFTherder - "If MEE6 won’t offer any reimbursement you’ll lose all credibility in the nft space imo." - Twitter (Nov 23, 2022)
- ↑ RTFKT - "In 10 min we go live again with @Ledger office hours in our discord." - Twitter (Nov 24, 2022)
- ↑ NFT Twitter Accuses Discord Bot MEE6 of Negligence - NFTEvening (Apr 13, 2023)
- ↑ MEE6 Discord Bot Accused of Negligence - NFTEvening (Nov 23, 2022)
- ↑ NFTherder - "what would be even cooler? Addressing the fact that because of your MEE6 over 200 eth was stolen and you've been dodging communication ever since." - Twitter (Nov 23, 2022)
- ↑ NFTherder - "3 weeks since between 200/300E was stolen cause a @mee6bot employee had remote admin access to nft servers he wasn't supposed to have. No official report or refunds." Twitter (Nov 23, 2022)
- ↑ NFTherder - "I've reached out to affected servers as well and they confirmed MEE6 hasn't shared a detailed report or offered reimbursements of misappropriated nfts/eth." - Twitter (Nov 23, 2022)
- ↑ NFTherder - "no intentions to refund...employees can still remote access any server" - Twitter (Nov 23, 2022)
- ↑ NFTherder - "rn anything is preferred over mee6" - Twitter (Nov 23, 2022)
- ↑ JackTracante - "The channel with these logs can only be seen by a few people so we know exactly what happened. When RTFKT had their hack they were able to see the MEE6 bot was the culprit for example." - Twitter (Nov 24, 2022)
Cite error: <ref> tag with name "mee6bottwitter-9718" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "777skitstwitter-9737" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "nftherdertwitter-9719" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "nftherdertwitter-9738" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "nftherdertwitter-9720" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "nftevening-9721" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "nftherdertwitter-9722" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "nftherdertwitter-9723" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "nftherdertwitter-9724" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "nftherdertwitter-9725" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "vauld-9739" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "minagamilazertwitter-9741" defined in <references> is not used in prior text.
Cite error: <ref> tag with name "eggb0mbtwitter-9745" defined in <references> is not used in prior text.