{"id":58920,"date":"2022-03-18T11:39:54","date_gmt":"2022-03-18T09:39:54","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=58920"},"modified":"2025-09-04T19:15:20","modified_gmt":"2025-09-04T16:15:20","slug":"hacker-steals-790000-from-rare-bears-nft-holders","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/hacker-steals-790000-from-rare-bears-nft-holders\/","title":{"rendered":"Hacker steals $790,000 from Rare Bears NFT holders"},"content":{"rendered":"<p>On March 16, an unknown actor, in a phishing attack on the Discord of the Rare Bears NFT project, gained access to the 179 tokens belonging to holders. The damage amounted to 286 ETH (about $790,000).<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">\ud83d\udea8 Warning \ud83d\udea8<a href=\\\"https:\/\/twitter.com\/BearsRare?ref_src=twsrc%5Etfw\\\">@BearsRare<\/a><br \/> Discord has unfortunately been compromised. Please DO NOT click any links, connect your wallet and block all incoming DMs in our discord. Our team are working on the situation as we speak \ud83d\ude4f\ud83c\udffc<\/p>\n<p>\u2014 Rare Bears (@BearsRare) <a href=\\\"https:\/\/twitter.com\/BearsRare\/status\/1504293859467350019?ref_src=twsrc%5Etfw\\\">March 17, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<p>Project representatives said the project&#8217;s Discords were compromised. They advised not to click links, not to connect wallets, and to block all incoming messages until the situation is fixed.<\/p>\n<p>After an audit by a specialist under the handle @pandez_, the project returned to normal operation. Details of the hack will be published soon.<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">Exciting news Bears \u2014 our Discord has been audited by <a href=\\\"https:\/\/twitter.com\/pandez_?ref_src=twsrc%5Etfw\\\">@pandez_<\/a> We&#8217;re secure and now open! \ud83d\udc3b\ud83c\udf89 We can&#8217;t wait to see you all again! We will release the details of the hack today to outline what happened for full transparency. Welcome back BearFam:<a href=\\\"https:\/\/t.co\/gCL8PFIGsm\\\">https:\/\/t.co\/gCL8PFIGsm<\/a><\/p>\n<p>\u2014 Rare Bears (@BearsRare) <a href=\\\"https:\/\/twitter.com\/BearsRare\/status\/1504598641251876864?ref_src=twsrc%5Etfw\\\">March 17, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<p>The 2,400 bears minted by digital artist Enox on Ethereum <a href=\\\"https:\/\/twitter.com\/BearsRare\/status\/1502672262297944066\\\">\u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f<\/a> on March 12.<\/p>\n<p>After the breach, the hacker took on the role of the project\u2019s official community moderator. He posted a phishing link, through which users could acquire 1,000 rare NFTs from the collection at 0.1 ETH ($280).<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">Thats y I minted 2 bears! All because It is shown in your discord announcement, it is not from direct message that i minted. We want Reimburse. <a href=\\\"https:\/\/t.co\/dDJ4HACoYK\\\">pic.twitter.com\/dDJ4HACoYK<\/a><\/p>\n<p>\u2014 steldes (\ud83d\ude80,\ud83d\ude80) (@steldes) <a href=\\\"https:\/\/twitter.com\/steldes\/status\/1504301285457088516?ref_src=twsrc%5Etfw\\\">March 17, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<p>According to PeckShield specialists, using a malicious smart contract directing to victims\u2019 wallets, the hacker stole 179 NFTs. Among the stolen tokens were not only Rare Bears, but also collectibles from CloneX, Azuki, mfer, 3landers and Sandbox.<\/p>\n<blockquote class=\\\"twitter-tweet\\\">\n<p lang=\\\"en\\\" dir=\\\"ltr\\\">PeckShieldAlert <a href=\\\"https:\/\/twitter.com\/hashtag\/Phishing?src=hash&#038;ref_src=twsrc%5Etfw\\\">#Phishing<\/a> ~179 <a href=\\\"https:\/\/twitter.com\/hashtag\/NFTs?src=hash&#038;ref_src=twsrc%5Etfw\\\">#NFTs<\/a> transferred to <a href=\\\"https:\/\/twitter.com\/BearsRare?ref_src=twsrc%5Etfw\\\">@BearsRare<\/a> exploiters, including ~4 Clone Xs <a href=\\\"https:\/\/twitter.com\/hashtag\/CloneX?src=hash&#038;ref_src=twsrc%5Etfw\\\">#CloneX<\/a>, ~4 <a href=\\\"https:\/\/twitter.com\/search?q=%24Azuki&#038;src=ctag&#038;ref_src=twsrc%5Etfw\\\">$Azuki<\/a> <a href=\\\"https:\/\/twitter.com\/AzukiZen?ref_src=twsrc%5Etfw\\\">@AzukiZen<\/a>, ~1 <a href=\\\"https:\/\/twitter.com\/hashtag\/mfer?src=hash&#038;ref_src=twsrc%5Etfw\\\">#mfer<\/a> <a href=\\\"https:\/\/twitter.com\/sartoshi_nft?ref_src=twsrc%5Etfw\\\">@sartoshi_nft<\/a>, ~2 <a href=\\\"https:\/\/twitter.com\/hashtag\/3landers?src=hash&#038;ref_src=twsrc%5Etfw\\\">#3landers<\/a> <a href=\\\"https:\/\/twitter.com\/3landersNFT?ref_src=twsrc%5Etfw\\\">@3landersNFT<\/a>, ~6 <a href=\\\"https:\/\/twitter.com\/search?q=%24LAND&#038;src=ctag&#038;ref_src=twsrc%5Etfw\\\">$LAND<\/a> <a href=\\\"https:\/\/twitter.com\/TheSandboxGame?ref_src=twsrc%5Etfw\\\">@TheSandboxGame<\/a> <a href=\\\"https:\/\/twitter.com\/hashtag\/TheSandbox?src=hash&#038;ref_src=twsrc%5Etfw\\\">#TheSandbox<\/a> <a href=\\\"https:\/\/twitter.com\/hashtag\/Metaverse?src=hash&#038;ref_src=twsrc%5Etfw\\\">#Metaverse<\/a> <a href=\\\"https:\/\/twitter.com\/hashtag\/NFTs?src=hash&#038;ref_src=twsrc%5Etfw\\\">#NFTs<\/a> <a href=\\\"https:\/\/t.co\/rtAVYTWIJr\\\">https:\/\/t.co\/rtAVYTWIJr<\/a> <a href=\\\"https:\/\/t.co\/TyMLPfmlz4\\\">https:\/\/t.co\/TyMLPfmlz4<\/a> <a href=\\\"https:\/\/t.co\/x15KK4Lkp7\\\">pic.twitter.com\/x15KK4Lkp7<\/a><\/p>\n<p>\u2014 PeckShieldAlert (@PeckShieldAlert) <a href=\\\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1504340385673654273?ref_src=twsrc%5Etfw\\\">March 17, 2022<\/a><\/p><\/blockquote>\n<p> <script async src=\\\"https:\/\/platform.twitter.com\/widgets.js\\\" charset=\\\"utf-8\\\"><\/script><\/p>\n<p>Of the 286 ETH proceeds, the hacker moved 213 ETH via Tornado Cash, with the remainder withdrawn to three separate wallets.<\/p>\n<p>Back in December, the attackers <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-stole-1-3-million-from-users-of-the-monkey-kingdom-nft-project\">hacked<\/a> the Discord account of the administrator of the Monkey Kingdom NFT project. The loss amounted to 7056 SOL (~$1.3m).<\/p>\n<p>Follow ForkLog on <a href=\\\"https:\/\/www.youtube.com\/channel\/UCC9FnXTC8_ENzaNSO5cHQ6g\\\" target=\\\"_blank\\\" rel=\\\"nofollow noopener\\\"> YouTube<\/a>!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On March 16, an unknown actor, in a phishing attack on the Discord of the Rare Bears NFT project, gained access to the 179 tokens belonging to holders. The damage amounted to 286 ETH (about $790,000).<\/p>\n","protected":false},"author":1,"featured_media":58921,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1154,1213],"class_list":["post-58920","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-crimes","tag-nft"],"aioseo_notices":[],"amp_enabled":true,"views":"48","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/58920","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=58920"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/58920\/revisions"}],"predecessor-version":[{"id":58922,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/58920\/revisions\/58922"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/58921"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=58920"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=58920"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=58920"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}