Aug 2024 - Starknet Discord Account Compromise Phishing - $0k (Global)

"Starknet is the secure scaling technology bringing Ethereum’s benefits to the world."
"Starknet is a permissionless Validity-Rollup, also known as a zero-knowledge rollup (ZK rollup) for Ethereum. As a Layer 2 (L2) blockchain, Starknet enables any dApp to achieve massive computation scale without compromising on Ethereum’s composability and security.
Starknet aims to achieve secure, low-cost transactions and high performance by using the STARK cryptographic proof system. Starknet contracts and the Starknet OS are written in Cairo, a custom-built and specialized programming language."
"Starknet utilizes the power of STARK technology to ensure computational integrity. By validating off-chain transactions with advanced math and cryptography, Starknet overcomes Ethereum’s scalability limitations. Starknet is a Validity Rollup that provides unlimited scale while retaining Ethereum’s security and decentralization."
"Starknet offers efficient and user-friendly experiences by employing Native Account Abstraction. All accounts are smart accounts: their behavior is determined by their developers rather than at the protocol level. This means unparalleled flexibility in account management. Developers can customize their applications beyond protocol constraints to elevate user experience and security."
"Starknet is home to the fastest-growing Layer 2 (L2) developer community due to its novel approach to scaling Ethereum and making it economically feasible to build even the most complex dApps. The Developer Hub provides a variety of manuals and resources for builders, by builders, on how to get started on Starknet."
"Did you miss our first Starknet Provisions Airdrop? Don't worry - There's still more! Starting from today, we will be releasing 10% of our remaining $STRK tokens to the community with a Claimdrop. Check eligibility and claim your allocation below."
"Did you miss our first Starknet Provisions Airdrop? Don't worry - There's still more! Starting from today, we will be releasing 10% of our remaining $STRK tokens to the community with a Claimdrop. Check eligibility and claim your allocation below."
Reportedly none.
"Our Discord is currently compromised. Please do not interact with the server, click any links, or respond to any messages until further notice. We are working to resolve the issue and will provide updates through official channels. Stay vigilant and protect your information."
"On Thursday evening the Starknet Discord came under attack. While the attackers were able to temporarily take over the server and post malicious links, we were able to quickly regain control.
The attacker’s goal was to scam users through these links, but through the quick work of StarkWare & SNF security teams and wallet partners we were able to prevent any harm to the community from the attack.
We have rebuilt all of the channels, and the server is now live again with enhanced security features and improved channel organization. We are also conducting a security audit and welcome your feedback on the updated channel layout."
Further Analysis
Starknet aims to create a more secure layer 2 Ethereum scaling solution with a custom programming language for users. Through undisclosed means, the Discord channel of Starknet was compromised and phishing links were posted for hours, promising users an airdrop of Starknet tokens if they approved a malicious transaction. It appears that there were no victims in this case, and no funds were lost from users.
How Could This Have Been Prevented?
More Cryptocurrency Exchange Hacks/Scams/Frauds
Ronin Network Initialization Failure White Hack > > < < Convergence Finance Reward Distributor Minting Exploit
Sources/Further Reading
SlowMist Hacked - SlowMist Zone (Dec 31)
@Starknet Twitter (Dec 31)
Starknet | Secure Scaling Technology Bringing Ethereum’s Benefits Worldwide (Dec 31)
Overview :: Starknet documentation (Dec 31)
@_Miki777 Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@Starknet_ZH Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@kingsleyueze Twitter (Dec 31)
@Crypto6717 Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@Fricoben Twitter (Dec 31)
@andriypaska Twitter (Dec 31)
@infinityhedge07 Twitter (Dec 31)
@ParamatikHaber Twitter (Dec 31)
@Metaversenews01 Twitter (Dec 31)
@alt_coiners Twitter (Dec 31)
@masteroncrypto Twitter (Dec 31)
@Jon_Kripto Twitter (Dec 31)
@LauriPelto Twitter (Dec 31)
@paceking1 Twitter (Dec 31)
@0xKodawari Twitter (Dec 31)
@akashbitcoins Twitter (Dec 31)
@arizonyaa Twitter (Dec 31)
@islakwcterlii Twitter (Dec 31)
@crypto_gurkha Twitter (Dec 31)
@spreekaway Twitter (Dec 31)
@MIIXCapital_CN Twitter (Dec 31)
@TrendsGem Twitter (Dec 31)
@GoPlusSecWareX Twitter (Dec 31)
t.me/QuadrigaInitiative
|
/r/QuadrigaInitiative
|
@QuadrigaInit
|
info@quadrigainitiative.com
|
t.me/QuadrigaInitiative
/r/QuadrigaInitiative
@QuadrigaInit
info@quadrigainitiative.com