Discord Servers of Avalanche and zkSync Targeted by Hackers

Discord Servers of Avalanche and zkSync Targeted by Hackers
avax2 8

In Brief

Hackers have recently attacked the official Discord servers of Avalanche and zkSync within 48 hours of a similar breach involving Polygon. These attacks involved posting fake distribution schemes and malicious links that promised free tokens to unsuspecting users. The incidents underscore increasing vulnerabilities in the Discord servers of blockchain networks.

Attack on Discord Pages

On August 25, Avalanche’s official Discord server was compromised, with hackers posting fraudulent links for AVAX token distribution. The attackers claimed that both owners and community members could claim free AVAX tokens. Avalanche’s community leader, Ben Well, confirmed that the issue was identified and resolved within an hour. The team is working to restore the server to its normal state.

Shortly after the Avalanche attack, zkSync’s official Discord page was also reported to be compromised. Hackers shared malicious links for a fake second-round airdrop plan, promising users free ZK tokens. Although zkSync did not address the breach publicly, several team members noticed the vulnerability and took action.

These attacks occurred less than 48 hours after a similar breach on Polygon’s Discord page, where hackers shared malicious links throughout the server.

Details on the Matter

Polygon’s Chief Information Security Officer, Mudit Gupta, confirmed the breach and advised users to avoid clicking on any links shared in the Discord channel until the situation was resolved. A user named ValidatorK reported losing $150,000 worth of Ethereum after interacting with a malicious link that appeared to be an official announcement on Polygon’s Discord channel.

These recent breaches add to a growing list of Discord-related vulnerabilities. For instance:

  • On March 25, 2023, blockchain security firm CertiK discovered a phishing scam in the Arbitrum Discord server, involving a fake announcement with a malicious link.
  • On May 5, the Gnus.AI artificial intelligence network fell victim to a Discord-related vulnerability, resulting in a loss of approximately $1.27 million.