A hacker stole millions of dollars' worth of NFTs via a phishing attack compromising Bored Ape Yacht Club's Instagram and promoting a malicious “mint” link
Earlier April coverage documented fake-mint phishing through compromised BAYC Discord servers. The Instagram compromise extends the same social-engineering playbook to another official-facing channel, making channel authenticity central to the project’s community operations.
Subsequent reporting on another Yuga Labs-run account impersonation and on hacked accounts used with NFT drainers shows this was part of a recurring distribution method rather than an isolated Discord-specific failure.
First-order effects
BAYC holders who followed the malicious mint prompt lose NFTs, while the compromised Instagram account becomes an immediate vehicle for reaching a trusted audience.
Yuga Labs and BAYC must restore confidence in their official communications after a channel used to announce project activity was used to direct users to a fraudulent transaction.
Second-order effects
Repeated compromises across BAYC’s Discord and Instagram channels force community members to treat mint announcements as independently verifiable, reducing the value of a single official social post as proof of authenticity.
Attackers gain a repeatable route to NFT theft by compromising or impersonating high-trust community accounts, a pattern later associated with hacked social accounts and NFT drainers.
Third-order effects
If official community channels remain a recurring entry point, NFT projects’ security posture shifts from protecting wallets alone to protecting the social accounts that direct wallet actions.
The pattern favors ecosystem norms that separate announcements from transaction authorization, because a compromised promotional account can otherwise convert audience trust directly into asset loss.
The trend: NFT phishing is evolving into account-compromise attacks that exploit trusted project communications to trigger on-chain transactions.
This morning, the official BAYC Instagram account was hacked. The hacker posted a fraudulent link to a copycat of the BAYC website with a fake Airdrop, where users were prompted to sign a ‘safeTransferFrom’ transaction. This transferred their assets to the scammer's wallet.
The IG hack resulted in 4 Apes, 6 Mutants, 3 Kennels, and some other assorted valuable NFTs being lost. We will be in contact with the users affected and will post a full post mortem on the attack when we can. For now I would like to stress that 2FA was enabled on the account. ht…
Interesting BAYC saying they had 2fa enabled on the Instagram account that got hacked, surely that means a compromised BAYC device? https://twitter.com/...
crypto - that much vaunted safer alternative to money - seems to be constantly firefighting a host of rudimentary phishing schemes, but I'm convinced https://twitter.com/...