Layer-1 network Avalanche and Layer-2 blockchain network zkSync’s official Discord servers were attacked less than 48 hours after the Polygon page was compromised. On August 25, Avalanche’s official account posted on X that their Discord server was compromised and urged users not to interact with any links.
Attack on Discord Pages
According to screenshots shared by Avalanche Discord members on X, attackers posted several links containing fake distribution schemes for AVAX and claimed that owners and community members could claim free AVAX. An hour later, Avalanche’s community leader Ben Well wrote that the Avalanche team had identified and resolved the issue. He added that the team was working to restore the server to normal.
However, only an hour after the Avalanche attacks, zkSync’s official Discord page was also reported to be compromised. Hackers once again shared malicious links for a fake second-round airdrop plan and promised users free ZK tokens. zkSync did not address the breach on X, but several members of the zkSync team noticed the vulnerability on the Discord page.
The attacks on Avalanche and zkSync occurred less than 48 hours after the official Discord page of Polygon was similarly compromised, with hackers sharing malicious links across the server.
Details on the Matter
Polygon’s Chief Information Security Officer Mudit Gupta confirmed the breach and warned users to avoid clicking on any links shared in the Discord channel until the situation was fully resolved. A user named ValidatorK reported losing $150,000 worth of Ethereum after interacting with something that appeared to be an official announcement on Polygon’s Discord channel.
The recent attacks add to the growing list of similar Discord vulnerabilities. On March 25, 2023, blockchain security firm CertiK uncovered a phishing scam circulating in the Arbitrum Discord server. The scam, believed to be orchestrated through a hacked developer account, involved a fake announcement with a malicious link. Similarly, on May 5, Gnus.AI’s artificial intelligence network fell victim to a Discord-related vulnerability, leading to a loss of approximately $1.27 million.