The “Discord Webhook” Exploit
Target: NFT Traders & Community Members
⚠️ The Incident: Admins of several large Discord servers reported a compromise today. Hackers didn’t hack the admins—they hacked the “Collab.Land” verification bot clones.
☠️ The Attack:
- The Message: You get a DM from a bot that looks like the server’s official verification tool.
- The Demand: “Your role has expired. Please re-verify to avoid being kicked.”
- The Link: It leads to a fake “verification” page that asks for a signature.
Result: Signing it allows the hacker to steal your NFTs.
🛡️ ShieldGuard Rule:
- Turn off DMs. Real verification bots (like Collab.Land) almost never DM you first.
- The “Kick” Bluff: If a bot threatens to kick you immediately, it is lying. Real admins give warnings.