UNKNOWN

MAY 2022

GLOBAL

CYBERCONNECT

DESCRIPTION OF EVENTS

"CyberConnect is a decentralized social graph protocol that helps Web3 applications bootstrap network effects. It empowers users to truly own their social identities, contents, and connections in a social network and provides developers with a rich set of tools to build applications with meaningful social experiences." "One of the promises made by web3 entrepreneurs is putting data back in the hands of owners through decentralization. Palo Alto-based CyberConnect is among a handful of blockchain startups working to fulfill this vision."

 

“In web2, companies with the largest social network own users’ social graphs and build walls around them to stem competition and advance corporate interests,” says CyberConnect CEO and co-founder Wilson Wei.

 

"As such, Wei and his team are building a social graph “protocol,” the underlying rules that allow data to be shared between computers, for applications, and in web3’s case, without a centralized agent like Facebook. The end goal is that users can travel across web3 platforms with their followings and followers."

 

"Developers can build social dApp with CyberConnect protocol to store and manage users’ social data such as profiles, posts, and content in a decentralized manner. Also, users can publish their data in NFT format on a chosen blockchain for monetization purposes. For example, the content creator can publish 100 editions for their blog with a price of 14 $CYBER tokens per edition and only allow their subscriber to collect such content NFT."

 

"Utilizing airdrops and tokens to attract early adopters, convert them to contributors and retain them through rewards like badges is a popular and proven practice among top Web3 projects. The protocol enables communities to build large audiences with social data that lives on CyberConnect as ERC-721 NFTs. Community tooling applications use CyberConnect to power community profiles and reward members to participate in activities with badges issued through the protocol."

 

"Developers can utilize CyberConnect to get interesting recommendation data when they build their social dApp. For example, the protocol can generate a list of recommended people to follow based on users’ relationships and social data from both off-chain and on-chain sources. Also, a list of recommended tokens to purchase can be generated based on modeling trading behavior & holdings relative to other addresses (i.e. collaborative filtering model)."

 

"An app experience powered by CyberConnect will look like this: Users connect their crypto wallet — which has become a universal gateway to any web3 app — to a social platform, upon which they will be shown all their existing connections. They will get recommended user addresses to follow, which is based on CyberConnect’s indexing. Once they follow someone, that piece of information will be added to CyberConnect’s network and become “portable and self-sovereign.”"

 

"Probably Nothing... Buckle up and get ready for this gorgeous NFT! More details coming in a bit." "What a year! frens Now looking back, we just feel so grateful for everyone coming along. Join us to unwrap #My2021Web3Journey and take a moment to thank all your favorite projects. Get your unique NFT to mint this remarkable year of yours in time." "The “Verified Web3 Dwellers” NFT is finally here to reward participants of #LetsCyberConnect. Shout-out to @ProjectGalaxyHQ and @0xPolygon for making this happen. What's even better? We're covering the minting costs."

 

"MEE6 is a 2-year-old Discord bot known for Levels, Auto-moderation, and its' paid music/record features. We also offer Reddit/Twitch/YouTube notifications, timers, custom commands, and other moderation features." "The best Discord Bot for your server." "Configure moderation, leveling, Twitch alerts, and much more with the most easy-to-use dashboard!" "Take advantage of the welcome message to inform newcomers about your server rules, topic, or ongoing events. You can design your own welcome card or keep it simple."

 

"MEE6 gives you full control to create the command of your dreams! Create commands that automatically give and remove roles and send messages in the current channels or in user's DM." "Notify your server when you or your favorite content creators begin to stream, upload, and post content." "MEE6, the Discord Bot trusted by 19+ million servers." As of April 2022, "Mekaverse, Doodles, CyberKongz, VeeFriends, CoolCats, and RTFKT all use MEE6 everyday to manage their Discord server. More than 60,000 NFT & crypto Discord servers setup MEE6 every month, and that number is growing fast."

 

"On May 18th, 2022 at approximately 01:32 AM UTC the CyberConnect Discord server was compromised, along with a number of other popular Web3 servers including Axie Infinity, Moonbirds, and RTFKT. The hack occurred as a result of the popular Discord moderation bot called MEE6 being compromised. After taking control of the CyberConnect moderation bot, bad actors posted a phishing link encouraging community members to claim an airdrop."

 

"It has been determined that a MEE6 employee’s account was compromised, allowing a group of bad actors to target prominent Discord servers such as CyberConnect. They were able to achieve this by manipulating the MEE6 bot to create a server admin reaction role, which would then be used to grant admin access to the hacker’s account. After this, they set up a new bot that posted the phishing link and kicked all mods from the server."

 

"We also have reason to believe that one of our server admins had their account previously compromised. This may have been a contributing factor to what happened in the CyberConnect server."

 

"In this particular case, one of our server admins was approached by a bad actor disguised as a community member with a partnership offer and asked to join the team’s server to discuss further. Upon joining the server, the admin was presented with a fake verification bot. By interacting with the fake bot, the admin’s Discord token was stolen. This enabled the hackers to bypass the admin’s password and 2FA helping them gain control of the account. This is possible due to Discord’s unsafe practice of storing user tokens in the local storage."

 

"Such cases of deception are growing at a rapid pace. You can read more about how social engineering is being used in a malicious manner and how to protect yourself."

 

"Another tweet was shared by PeckShield, a blockchain cybersecurity firm, warning users about compromised NFT Discord Server of Memeland, RTFKT, PROOF/Moonbirds and infrastructure company Cyberconnect."

 

"HEADS UP! PLEASE, DON'T CLICK ON ANY LINK! WE WILL NEVER ASK FOR YOUR PRIVATE KEY ON DISCORD! Our team is working to solve the situation with the bot's security in our server!"

 

"Community members who clicked that link, approved the contract, and attempted to claim token airdrop, unknowingly gave the hackers control of their wallets leading to, in many cases, a loss of funds and NFTs. While our team was able to take back control of the server within 14 minutes, a number of community members had already been affected."

 

"A team member of [similarly hacked] Memeland noted, “a discord bot (mee6) seems to be compromised across various high profile servers.” The mee6 bot is used by the server owners to automate welcome messages and inform about the server rules, events and topics."

 

"Cyberconnect and Memeland confirmed the hack on their Twitter feeds and warned users to avoid clicking on any link on Discord. Cyberconnect caution that the project will never ask for their private keys. Similarly, Memeland alerted customers about the “fake links” in a message." "Once you interact with these fake bots they will snag your discord token, giving them instant access to your account without 2FA or your password."

 

"With lots of high-profile crypto projects using Discord, this leakage of information can reveal “not-yet-announced partnerships, upcoming product launches, exchange listings, and coordinate multi-sig signers,” as reported by Fraser."

 

"The Web3 infrastructure of CyberConnect, a social graph protocol, was also reportedly compromised via a Discord bot that began to pass malware links to users."

 

"Please help! My 383 ens was stolen! [H]elp!" "[W]hat should I do!!! I clicked and transferred assets!!!! [W]ill they get control of my wallet?" "Metoo! Admin what should [I] do now???????"

 

"MEE6's employee account was breached & scammers used that account to execute the scams and steal eth. MEE6 support denied it for hours yesterday [before later admitting what happened]."

 

MEE6 released a statement after the event: "Some servers have reported MEE6 being used to post unwanted messages. There is no technical breach in our systems. This was due to one of our employee's account getting compromised. The issue is now fixed and we've taken all the steps to make sure it never happens again. We take security very seriously, and will always be committed not only to keep our systems safe but also add extra measures to protect servers from accounts being compromised."

 

NFTHerder reports he "reached out to affected servers as well and they confirmed MEE6 hasn't shared a detailed report or offered reimbursements of misappropriated nfts/eth." "MEE6 has yet to release a detailed report." "[N]o intentions to refund. [T]hey won’t release a public statement cause scared of fud. [E]mployees can still remote access any server."

 

"As many of you know, our @discord server was compromised yesterday; our team has conducted an in-depth [and] thorough investigation into the incident, and we have created an in-depth report." "We appreciate your patience and continued feedback; as of today, we have implemented additional security measures to prevent a similar breach from ever occurring again."

 

"Yesterday’s incident was extremely unfortunate and we want to make sure we do everything possible to avoid it from happening again. Below are some of the steps we are taking to improve server security. We’re [now] using a ‘cold admin’ account to protect against phishing attacks on moderators and CyberConnect employees. All unnecessary bots have been removed to reduce the chance of any of them being compromised. Moderators will neither have the ability to grant admin rights to other members, nor will they be able to make significant changes to the server. This way, compromised accounts will pose a significantly lower risk to community members. We are in the process of conducting a Discord security audit by a trusted third-party."

 

"To those who were affected by the hack, know that we are actively working on a restitution plan; please fill out this form so we can fully understand the impact of this hack." "If you were one of the community members who interacted with the phishing bot during the attack, approved any smart contracts, or attempted to mint the NFT, we strongly advise you to move valuable assets out of the affected wallet and into a new one. Furthermore, we encourage you to check for any unsolicited transactions that may have taken place."

 

"We value our community and are pained to learn that some of you have been financially impacted by the hack. If you are a victim of this Discord hack, please fill out [a form] so we can investigate and fully understand the impact this has had on our community. We are working on a restitution plan with the goal of making all affected users whole again."

CyberConnect is developing a decentralized social media platform. As a promotion at the end of 2021, they launched an NFT with free minting. Their Discord sever was set up using MEE6, a widely implemented Discord bot which assists with ranking and moderation functions. MEE6 had administrative level access to a wide range of Discord servers where it was set up. One of the MEE6 employee accounts was compromised, and the attackers used that to run widespread phishing attacks on multiple NFT communities, including CyberConnect. CyberConnect had previously announced an NFT with free minting, and the NFT space often has a wide range of time-sensitive opportunities. It's unclear exactly how many users were affected, however there are at least 3 reports visible on Twitter. MEE6 has apparently not published further details about what happened, however CyberConnect has provided a detailed document reporting their understanding of the situation. CyberConnect has also started collecting information on affected users, which they were claiming was to be used for "restitution", however no further update appears on their Twitter or Mirror announcing any further plan.

HOW COULD THIS HAVE BEEN PREVENTED?

The primary issue was related to the security of the Discord server, which granted additional unnecessary permissions to the MEE6 bot. The widespread bot access should not fall under the control of a single employee or system, which may form a fundamental design limitation of Discord or the MEE6 bot system.

 

NFT traders can avoid falling victim to such fraud by not making rushed decisions, double checking any promotions against multiple sources, and avoiding any mints that seem to be too good to be true.

 

Check Our Framework For Safe Secure Exchange Platforms

Scammers Target NFT Discord Channel | Threatpost (Jul 17)
CyberConnect | Connect Everyone on Web3 (Nov 18)
Discord Bot | MEE6 (Nov 23)
MEE6 | Discord Bots | Discords.com  (Nov 23)
@mee6bot Twitter (Nov 23)
@777Skits Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
MEE6 Discord Bot Accused of Negligence (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
Multiple NFT Projects Attacked After Commonly-Used "Mee6" Discord Bot Hacked - CPO Magazine (Nov 23)
Hackers Compromise a String of NFT Discord Channels (Nov 23)
@interlockweb3 Twitter (Nov 24)
@eggb0mb_ Twitter (Nov 24)
@BeosinAlert Twitter (Nov 24)
@CHOX3__ Twitter (Nov 24)
@mekamran Twitter (Nov 24)
@NFTherder Twitter (Nov 24)
@NFTherder Twitter (Nov 24)
@PeckShieldAlert Twitter (Nov 24)
@CyberConnectHQ Twitter (Nov 24)
@CyberConnectHQ Twitter (Nov 24)
@CyberConnectHQ Twitter (Nov 24)
@CyberConnectHQ Twitter (Nov 24)
@CyberConnectHQ Twitter (Nov 24)
Welcome | CyberConnect Dev Center (Nov 24)
CyberConnect raises $15M Series A to put data back in the hands of users • TechCrunch (Nov 24)
@CyberConnectHQ Twitter (Nov 24)
Notion – The all-in-one workspace for your notes, tasks, wikis, and databases. (Nov 24)
@fccview Twitter (Nov 24)
#LetsCyberConnect - Claim your NFT with Project Galaxy — CyberConnect (Nov 24)
https://opensea.io/collection/cyberconnect (Nov 24)
CyberConnect NFT statistics (Nov 24)
NFT Twitter accuses discord bot MEE6 of negligence - Business News (Nov 24)
NFT Discord Hack: Mee6 Discord Bot Hack Triggers A Domino Effect - Vauld Insights (Nov 23)
Hackers Use Discord Bot to Infiltrate NFT Channels in Phishing Attack (Nov 24)

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.