/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A hacker stole millions of dollars' worth of NFTs via a phishing attack compromising Bored Ape Yacht Club's Instagram and promoting a malicious “mint” link

Osato Avan-Nomayo / The Block :

The Block Osato Avan-Nomayo

Context & Ripple Effects

Earlier April coverage documented fake-mint phishing through compromised BAYC Discord servers. The Instagram compromise extends the same social-engineering playbook to another official-facing channel, making channel authenticity central to the project’s community operations.

Subsequent reporting on another Yuga Labs-run account impersonation and on hacked accounts used with NFT drainers shows this was part of a recurring distribution method rather than an isolated Discord-specific failure.

First-order effects

  • BAYC holders who followed the malicious mint prompt lose NFTs, while the compromised Instagram account becomes an immediate vehicle for reaching a trusted audience.
  • Yuga Labs and BAYC must restore confidence in their official communications after a channel used to announce project activity was used to direct users to a fraudulent transaction.

Second-order effects

  • Repeated compromises across BAYC’s Discord and Instagram channels force community members to treat mint announcements as independently verifiable, reducing the value of a single official social post as proof of authenticity.
  • Attackers gain a repeatable route to NFT theft by compromising or impersonating high-trust community accounts, a pattern later associated with hacked social accounts and NFT drainers.

Third-order effects

  • If official community channels remain a recurring entry point, NFT projects’ security posture shifts from protecting wallets alone to protecting the social accounts that direct wallet actions.
  • The pattern favors ecosystem norms that separate announcements from transaction authorization, because a compromised promotional account can otherwise convert audience trust directly into asset loss.

The trend: NFT phishing is evolving into account-compromise attacks that exploit trusted project communications to trigger on-chain transactions.

Discussion

  • @boredapeyc Bored Ape Yacht Club on x
    🚨There is no mint going on today. It looks like BAYC Instagram was hacked. Do not mint anything, click links, or link your wallet to anything.
  • @boredapeyc Bored Ape Yacht Club on x
    This morning, the official BAYC Instagram account was hacked. The hacker posted a fraudulent link to a copycat of the BAYC website with a fake Airdrop, where users were prompted to sign a ‘safeTransferFrom’ transaction. This transferred their assets to the scammer's wallet.
  • @zachxbt @zachxbt on x
    Damn the BAYC Instagram hacker stole 4 BAYC, 7 MAYC, 3 BAKC, 1 CloneX, & more ( 91 NFTs in total) Hacker Address: https://etherscan.io/... https://twitter.com/...
  • @cryptogarga @cryptogarga on x
    The IG hack resulted in 4 Apes, 6 Mutants, 3 Kennels, and some other assorted valuable NFTs being lost. We will be in contact with the users affected and will post a full post mortem on the attack when we can. For now I would like to stress that 2FA was enabled on the account. ht…
  • @cryptogarga @cryptogarga on x
    The security practices surrounding the IG account were tight on Yuga's end. Nothing important will ever get posted on Instagram again.
  • @ediggs Eze Vidra on x
    Security remains one of the biggest challenges in web3 https://twitter.com/...
  • @deg3n @deg3n on x
    Interesting BAYC saying they had 2fa enabled on the Instagram account that got hacked, surely that means a compromised BAYC device? https://twitter.com/...
  • @thetoddwilliams Todd ‘Papi’ Carlos on x
    *reaching into my nearly empty pockets* alls I have are a few tiny monkey sketches remaining... https://www.techmeme.com/...
  • @inversebrah @inversebrah on x
    #NFTweets https://twitter.com/...
  • @yokomson @yokomson on x
    Sooo assuming 2fa was sms and they got sim swapped? Even more embarrassing tbh lmao https://twitter.com/...
  • @cryptogarga @cryptogarga on x
    @inversebrah 2FA was enabled and it was 6 mutants, and 4 apes, 3 kennels. We will be sharing more asap.
  • @tristandross @tristandross on x
    crypto - that much vaunted safer alternative to money - seems to be constantly firefighting a host of rudimentary phishing schemes, but I'm convinced https://twitter.com/...