Hack on Bored Ape Yacht Club NFTs leads to $3m simian oblivion

Latest mass theft of digital art assets is carried out by phishing post on Instagram

Yuga Labs, the multibillion-dollar collective behind the infamous Bored Ape Yacht Club non-fungible tokens, has been targeted by another hacking attack, leading to the theft of millions of dollars worth of the simian NFTs.

BAYC’s series of algorithmically generated cartoon ape profile pictures is one of the best-known collections of NFTs – a digital asset or artwork whose ownership is stored on a blockchain, a decentralised ledger of transactions like those used by cryptocurrencies.

The attacker seized control of the BAYC Instagram account and sent a phishing post that many followers were fooled into clicking on, connecting their crypto wallets to the hacker’s “smart contract” – a mechanism for implementing a crypto transaction. That enabled the attacker to steal the assets held in the wallets, seizing control of four Bored Apes, as well as a host of other NFTs with an estimated total value of $3m.

“Instagram attacks are nothing new but often take an element of social engineering,” said Jake Moore, global cybersecurity adviser at the security firm ESET. “Unfortunately, however, this takeover has had a huge consequence and resulted in a mass robbery of digital assets. Similar to when physical art is stolen, there will be questions over how they would now be able to sell on these assets, but the problems in NFTs still prevail and users must remain extremely cautious of this still very new technology.”

As one of the most prominent NFT collections, with celebrity owners including Eminem, Gwyneth Paltrow and Madonna, BAYC holders are often targeted for attacks, with greater or lesser technical significance.

In early April, for instance, one pseudonymous owner, “s27”, lost a $500,000 ape collection after being tricked into swapping it for, effectively, counterfeits: the scammer created new NFTs that were visually identical to BAYC pictures except they had a green tick over them – mimicking the “verified” icon of the platform used for the trade.

In December, another Ape holder, the New York art dealer Todd Kramer, disclosed his own $2.2m loss with the tweet, “I been hacked. All my apes gone. This just sold please help me.” Kramer, who had fallen prey to a similar phishing scam, managed to recover a portion of his stolen Apes with the help of the NFT trading platform OpenSea – but not before the phrase “all my apes gone” was widely mocked online among those who doubt the substance of the NFT fad.

The BAYC creators said in a statement: “Yuga Labs and Instagram are currently investigating how the hacker was able to gain access to the account. Two-factor authentication was enabled and the security practices surrounding the IG account were tight.”

Sign up to the daily Business Today email or follow Guardian Business on Twitter at @BusinessDesk

Hacking and theft are rife in the crypto sector. Transactions are irreversible once made, and it can take a high degree of skill to read the contents of a smart contract and determine whether it is malicious or valid before giving it access to an account. Last week, a “stablecoin” project called Beanstalk lost $180m to a “governance” attack, where the attacker used an instant loan to buy control of the project, transfer its reserves to their account, and then repay the loan in just 13 seconds.

And earlier this month, a North Korean hacking outfit named Lazarus stole more than half a billion dollars-worth of crypto tokens from the video game Axie Infinity. Despite the hack being recorded on the blockchain, which keeps all transactions public, the state-sponsored hackers appear to have successfully laundered nearly $100m of the stolen funds already, largely by using a decentralised money-laundering service called Tornado Cash.

Contributor

Alex Hern UK technology editor

The GuardianTramp

Related Content

Article image
The Bored Ape NFT craze is all about ego and money, not art
Eminem has just joined the exclusive club of celebrity investors willing to pay heaps of cryptocurrency for NFTs that are nothing more than derivative monkey cartoons

Jonathan Jones

04, Jan, 2022 @4:16 PM

Article image
Art, amulets and cryptokitties: the new frontier of cryptocurrencies
‘Non-fungible tokens’ are unique images, clips or poems traded online for increasingly large sums

Alex Hern UK technology editor

26, Feb, 2021 @7:00 AM

Article image
What is cryptoart, how much does it cost and can you hang it on your wall?
When is a meme worth $600,000? When technology has created a ‘unique’ version that can’t be owned by anyone else

Patrick Lum and Lucy Clark

04, Mar, 2021 @7:36 PM

Article image
Can anyone become an NFT collector? I tried it to find out
This year non-fungible tokens burst into the mainstream after several digital images and animations sold for absurd amounts – so I entered the world of NFTs myself

Oscar Schwartz

23, Mar, 2021 @9:00 AM

Article image
NFT trader OpenSea bans insider trading after employee rakes in profit
Executive was found to be buying artworks shortly before they were promoted on site’s front page

Alex Hern

16, Sep, 2021 @1:10 PM

Article image
NFTs are helping artists solve a vital problem: who owns digital artwork?
Digital art can be easily and endlessly duplicated, but non-fungible tokens allow buyers to confirm ownership

Kari Paul

03, Apr, 2021 @10:00 AM

Article image
Cryptoart! What is it and can you eat it? | First Dog on the Moon
The only good thing about all of this is getting to say fungible a lot it is a funny word. What does it even mean?

First Dog on the Moon

12, Mar, 2021 @4:59 AM

Article image
Royal Ballet dancer to auction world’s first ballet NFTs
Natalia Osipova hopes to ‘broaden appeal’ of ballet by selling unique digital copies of performances

Harriet Sherwood Arts and culture correspondent

29, Nov, 2021 @12:00 PM

Article image
Dangerous game? Football clubs look to mine fans’ cash with crypto offerings
Digital tokens seen as new wealth stream as TV rights and sponsorship level off but not everyone is happy at the new signings

Rob Davies

22, Jan, 2022 @7:00 AM

Article image
What were NFTs? An understandable internet fad, and the next one is just around the corner | Joel Golby
We only loved non-fungible tokens in a pandemic peak of online loneliness, says the writer and author Joel Golby

Joel Golby

27, Sep, 2023 @9:30 AM