UNKNOWN

MAY 2022

GLOBAL

MOONBIRDS

DESCRIPTION OF EVENTS

"Proof Collective, the organization behind the Moonbirds, is a group of 1000 NFT collectors. The Proof Collective is an NFT gated membership platform, where members share investment opportunities and receive access to some of the most desirable whitelists. Proof launched via dutch auction in December 2021 and rose from $5.000 to $375.000 today."

 

"Moonbirds is a new NFT project that skyrocketed from $7.500 to over $90.000 in one week, thus beating the performance of most other bluechip NFT projects such as Bored Ape Yacht Club or Crypto Punks. Moonbirds brought in so far $60m upon launch and a total trading volume of $238m."

 

"A very experienced team led by Kevin Rose, one of the most prolific US Tech investors and entrepreneurs, which is part of the excitement around Proof. The team’s experience translates for example in the communication around the projects, which is consistent (regular town halls and updates) as well as transparent (before the launch of the Moonbirds, the team for example asked input from the whole collective about some key decisions such as pricing). They also share their reasoning behind why they have made certain decisions for everyone to understand. Also the communication around the departure of their COO was swift and transparent."

 

"MEE6 is a 2-year-old Discord bot known for Levels, Auto-moderation, and its' paid music/record features. We also offer Reddit/Twitch/YouTube notifications, timers, custom commands, and other moderation features." "The best Discord Bot for your server." "Configure moderation, leveling, Twitch alerts, and much more with the most easy-to-use dashboard!" "Take advantage of the welcome message to inform newcomers about your server rules, topic, or ongoing events. You can design your own welcome card or keep it simple."

 

"MEE6 gives you full control to create the command of your dreams! Create commands that automatically give and remove roles and send messages in the current channels or in user's DM." "Notify your server when you or your favorite content creators begin to stream, upload, and post content." "MEE6, the Discord Bot trusted by 19+ million servers." As of April 2022, "Mekaverse, Doodles, CyberKongz, VeeFriends, CoolCats, and RTFKT all use MEE6 everyday to manage their Discord server. More than 60,000 NFT & crypto Discord servers setup MEE6 every month, and that number is growing fast."

 

"Another tweet was shared by PeckShield, a blockchain cybersecurity firm, warning users about compromised NFT Discord Server of Memeland, RTFKT, PROOF/Moonbirds and infrastructure company Cyberconnect."

 

"A team member of [similarly hacked] Memeland noted, “a discord bot (mee6) seems to be compromised across various high profile servers.” The mee6 bot is used by the server owners to automate welcome messages and inform about the server rules, events and topics." "Once you interact with these fake bots they will snag your discord token, giving them instant access to your account without 2FA or your password."

 

"With lots of high-profile crypto projects using Discord, this leakage of information can reveal “not-yet-announced partnerships, upcoming product launches, exchange listings, and coordinate multi-sig signers,” as reported by Fraser."

 

"MEE6's employee account was breached & scammers used that account to execute the scams and steal eth. MEE6 support denied it for hours yesterday [before later admitting what happened]."

 

MEE6 released a statement after the event: "Some servers have reported MEE6 being used to post unwanted messages. There is no technical breach in our systems. This was due to one of our employee's account getting compromised. The issue is now fixed and we've taken all the steps to make sure it never happens again. We take security very seriously, and will always be committed not only to keep our systems safe but also add extra measures to protect servers from accounts being compromised."

 

NFTHerder reports he "reached out to affected servers as well and they confirmed MEE6 hasn't shared a detailed report or offered reimbursements of misappropriated nfts/eth." "MEE6 has yet to release a detailed report." "[N]o intentions to refund. [T]hey won’t release a public statement cause scared of fud. [E]mployees can still remote access any server."

Proof_XYZ, the team behind the Moonbirds NFT set, used MEE6, a widely implemented Discord bot which assists with ranking and moderation functions. MEE6 had administrative level access to a wide range of Discord servers where it was set up. One of the MEE6 employee accounts was compromised, and the attackers used that to run widespread phishing attacks on multiple NFT communities, including Moonbirds. The NFT space often has a wide range of time-sensitive opportunities. It's unclear exactly how many users were affected, and it seems that no funds have been recovered. MEE6 has apparently not published further details about what happened. It doesn't appear that Moonbirds or Proof_XYZ made any announcement about the breach on their Twitter.

HOW COULD THIS HAVE BEEN PREVENTED?

The primary issue was related to the security of the Discord server, which granted additional unnecessary permissions to the MEE6 bot. The widespread bot access should not fall under the control of a single employee or system, which may form a fundamental design limitation of Discord or the MEE6 bot system.

 

NFT traders can avoid falling victim to such fraud by not making rushed decisions, double checking any promotions against multiple sources, and avoiding any mints that seem to be too good to be true.

 

Check Our Framework For Safe Secure Exchange Platforms

Scammers Target NFT Discord Channel | Threatpost (Jul 17)
Moonbirds and Proof collective — 5 Learnings from hottest thing in NFTs (from a Proof member) | by Raffaela Rein | Medium (Nov 18)
Discord Bot | MEE6 (Nov 23)
MEE6 | Discord Bots | Discords.com  (Nov 23)
@mee6bot Twitter (Nov 23)
@777Skits Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
MEE6 Discord Bot Accused of Negligence (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
@NFTherder Twitter (Nov 23)
NFT Discord Hack: Mee6 Discord Bot Hack Triggers A Domino Effect - Vauld Insights (Nov 23)
@NFTherder Twitter (Nov 23)
Hackers Compromise a String of NFT Discord Channels (Nov 23)
@eggb0mb_ Twitter (Nov 24)
@BeosinAlert Twitter (Nov 24)
@CHOX3__ Twitter (Nov 24)
@mekamran Twitter (Nov 24)
@Tricky_NFTs Twitter (Nov 24)
@ryuk_dev Twitter (Nov 24)
@WlMPZ_ Twitter (Nov 24)
@lukenamop Twitter (Nov 24)
@Zeneca_33 Twitter (Nov 24)
@NFTherder Twitter (Nov 24)
@NFTherder Twitter (Nov 24)
@PeckShieldAlert Twitter (Nov 24)
@UnusualEss Twitter (Nov 24)
What is Proof Collective & Moonbirds? (Nov 24)
@search Twitter (Nov 24)
@search Twitter (Nov 24)
https://opensea.io/collection/proof-moonbirds (Nov 24)
Moonbirds: The official PROOF PFP (Aug 23)
NFT Twitter accuses discord bot MEE6 of negligence - Business News (Nov 24)
Multiple NFT Projects Attacked After Commonly-Used "Mee6" Discord Bot Hacked - CPO Magazine (Nov 23)
Hackers Use Discord Bot to Infiltrate NFT Channels in Phishing Attack (Nov 24)

Sources And Further Reading

 For questions or enquiries, email info@quadrigainitiative.com.

Get Social

  • email
  • reddit
  • telegram
  • Twitter

© 2021 Quadriga Initiative. Your use of this site/service accepts the Terms of Use and Privacy Policy. This site is not associated with Ernst & Young, Miller Thompson, or the Official Committee of Affected Users. Hosted in Canada by HosterBox.