In light of the another discord scam - where hackers get access to moderator account and announce a fake mint to steal ETH -
I'm breaking down a few of their tactics and the red flags🚩so that you don't fall victim to this
By and large, this is social engineering more so than a technical hack.
It involves hijacking a moderators account at the very least, or getting a mod to grant admin permissions to an attackers account and post fake announcements
Remember, their goal is to override your logical mind with your FOMO brain.
Even though it feels like a scam, you might still go through it, because... what if it's not?
Red flag #1🚩- You'll feel pressured to rush and mint without thinking
2/ Once a moderators account is compromised, an announcement is made of a surprise mint, pointing to a fake site.
Red flag #2🚩- the site is never the original domain name of the project.
Often, it'll use a different domain ending (for example, instead of .com, it's .live).
🚩Red flag #3 - at the same time the fake mint site is posted, discord channels are muted by the attacker (thanks to admin permissions)
The goal is to prevent anybody from calling out what it is: a scam
Muting keeps the scam going on for as long as possible so more people mint
🚩Red flag #4 - The fake mods will be urging, (begging?) you to mint.
They will be trying *really* hard to get you to mint. Often, borderline spamming you to do so.
If you spend time in any discord, you know that is not normal behaviour by a mod, ever. Red flag!
5/ if you didn't pick up on any of the previous red flags, you still have one last chance before your ETH is gone forever.
You're on the fake site, connected with it, and clicked mint.
Metamask pops up, the gas is surprisingly low... too good to be true? Yes it is
That's🚩Red flag #5 - The gas is low for a mint because you're not executing the mint function. You're getting scammed for your eth.
Disconnect your wallet and run!
Scams are no fun and hurt the community we're all trying to help build.
The more we can inform everyone to stay safe and know the markers of the discord scam, the less likely scams like this will work.
If the scam stops working, the attacks will stop trying.
One more🚩- this is a discord specific hack. Check the projects twitter page to see if there is actually a surprise mint.
If it's fake, you won't see anything on twitter.
• • •
Missing some Tweet in this thread? You can try to
force a refresh