Hackers just stole millions of dollars' worth of Bored Ape Yacht Club NFTs

Bored Ape Yacht Club
(Image credit: Yuga Labs)

An Instagram phishing attack has resulted in the theft of 91 Bored Ape Yacht Club NFTs, worth around $2.8 million.

BAYC, as its known in NFT circles, is run by Yuga Labs, one of the most mysterious NFT collectives in the space, which recently raised $450 million at a $4.5 billion valuation. 

The exploit allowed the attackers to steal BAYC NFTs from wallets that were fooled into accepting a fake airdrop, which is usually a method for distributing free NFTs or other digital assets.

BAYC's Instagram account was used to promote the LAND fake airdrop, according to The Block, which ties into the organization's broader plans to release NFT-based games.

The attackers' wallet received 91 NFTs from the saga, including four Bored Apes, six Mutant Apes and three Bored Ape Kennel Club NFTs, according to BAYC co-founder Garga. The attacker also stole various other digital assets. 

Garga said the security practices on BAYC's Instagram were "tight" and "nothing important will ever get posted on Instagram again."

Another worrying Web3 exploit 

Whether you think Web3 is the future or not, one thing everyone can agree on is there are a lot of scams in the nascent space. Nearly every week people lose crypto assets worth something, from the recent $600 million Axie Infinity hack on downwards.

This is predominantly down to the extremely everyone-for-themselves nature of Web3 as it stands, often sitting outside any clear oversight. NFT owners must take extreme measures to protect their assets, including casting a sceptical eye over real-seeming airdrops. 

Even a well-funded and notable institution like BAYC isn't immune, as the latest example proves. Back on April 1, BAYC also suffered a hack to its Discord server, for similar purposes.

The fact that a startup with $450 million – plus the proceeds from selling its NFTs – can't keep itself safe from hacks shows how far the Web3 industry has to go. 

Max Slater-Robins has been writing about technology for nearly a decade at various outlets, covering the rise of the technology giants, trends in enterprise and SaaS companies, and much more besides. Originally from Suffolk, he currently lives in London and likes a good night out and walks in the countryside.

Read more
Ethereum
Hackers steal over $1bn in one of the biggest crypto thefts ever
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
North Korean flag with a hooded hacker
FBI says North Korean Lazarus hackers were behind $1.5 billion Bybit crypto hack
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
Data leak
Top collectibles site leaks personal data of nearly a million users
Latest in Security
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Latest in News
A phone showing a ChatGPT app error message
ChatGPT is down for many – here's what's going on
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
US flags
US government IT contracts set to be centralized in new Trump order
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping