Sleepy

Posted on Feb 07, 2022Read on Mirror.xyz

Weirdo Ghost Gang 2月6日Discord黑客攻击事件回顾

北京时间2月6日,小幽灵的Discord遭到了黑客攻击,我们通过回溯Discord日志记录,与大家复盘一下这次频道被黑的全过程: On February 6th (Beijing time), our Discord was hacked. We reviewed the whole process of this channel hacking with you by backtracking the Discord log records:

11:00-黑客做了第一个小动作,在频道内创建了webhook的机器人,由于此举并未造成影响,所以我们没有察觉到;

11:00 - The hacker makes the first little move, creating a webhook bot within the channel. Since the move had no impact, we didn't notice it.

11:59-黑客率先删除了我们团队内部的办公频道,设法阻断我们团队内部的联系(但他失败了);与此同时小幽灵团队发现了异样并开始召集人手准备应对;

11:59 - The hacker tries to block the communication within our team by deleting the office channel inside our team first (but he fails). At the same time, the WGG team found something strange and began to prepare to deal with it.

12:00-黑客删除了小幽灵discord内所有能发言的公开频道;

12:00 - The hacker deleted all public channels in our discord.

12:05-黑客事先创建的webhook的机器人,在#announcement和#event频道开始不断发布假公告与假链接,链接中的网站页面相当粗糙,网站内的mint按钮显示为中文「薄荷」,并且所谓的「mint」其实是一笔转账,把受害者「mint」的ETH金额转到黑客的账户。也就是说大家的钱包并未被网站授权,十分安全;

12:05 - The webhook bot created by the hacker in advance starts posting fake announcements and fake links in the #announcement and #event channels. The website page in the link is quite rough. The mint button in the website is displayed as Chinese "薄荷", and the so-called "mint" is actually a transfer, which transfers the ETH amount of the victim "mint" to the hacker's account. That means your wallet is not authorized by the website and is still safe.

与此同时,小幽灵团队一边反击一边召开紧急线上电话会议。首先移除了被黑账户的所有权限,并在#announcement和#event抵御hacker假链接的攻击;

At the same time, the WGG team held an emergency online conference call while fighting against the hackers. First, we removed all permissions from hacked accounts and defended against fake links from hackers in #announcement and #event.

12:08-小幽灵官方推特发布了公告提醒大家不要点击黑客提供的虚假网站。随后我们从webhook删除了黑客的机器人,终止了他们对服务器的破坏和假链接的发送;

12:08 - WGG's official Twitter issued an announcement to remind everyone not to click on the fake website provided by hackers. We then removed the hacker's bot from the webhook, stopping them from compromising the server and sending fake links.

13:00-我们在Discord开设临时频道,向大家讲述事情经过,同时内部讨论解决方案;

13:00 - We set up a temporary channel on Discord to tell everyone what happened and discuss solutions internally.

14:25-举办社区电话会议,小幽灵团队与社区成员一起探讨后续相关补偿方案及未来建设相关内容;

14:25 - A community conference call will be held, and the WGG team will discuss the follow-up compensation plan and future construction related content with community members.

16:00-小幽灵的社区公开电话会议结束,社区重建进行中。

16:00 - The community conference call ends, and community rebuilding is in progress.

在这次服务器被黑中,黑客总共骗取了4.83个ETH,从链上可以看到总共是50笔交易:

In this Discord hack, the hackers defrauded a total of 4.83 ETH, and it can be seen from the blockchain that there are a total of 50 transactions:

https://etherscan.io/address/0x0ea17def7cd9c51c9d6ed0c47381bb7f0a2da1e3

我们已经向受害者发放了全额补偿,补偿金额共计4.891222544ETH(包括 gas)。 

We have issued full compensation to victims, totaling 4.891222544 ETH (including gas).

此次黑客攻击对社区造成的影响较小,所以我们的发售计划不变。

The impact of this hack on the community was minimal, so our sale plans remain unchanged.

团队内部自查,所有团队成员均开启了Discord的双重验证,黑客如今的新攻击手法需要所有社区提高警惕。

The team checked itself internally and all team members turned on 2FA for Discord. Hackers' new attack techniques today require all communities to be more vigilant.

经此一役,我们决定在未来与其他有过相同经历的社区,我们将共同出资成立反诈基金,为受害者提供力所能及的帮助,并共同传播网络安全与反诈知识,帮助大家了解最新的诈骗手段,防患于未然。

After this hack, we decided to join other communities who have had the same experience in the future, and we will jointly fund the establishment of an anti-fraud fund to help victims within our capacity. At the same time, we will jointly spread network security and anti-fraud knowledge to help everyone know the latest fraud methods and prevent related incidents from happening again.

感谢在推特、Discord、微信等渠道对我们进行提醒与帮助的朋友,也感谢在各个渠道警示更多人小幽灵Discord被黑的朋友,是你们的帮助让这一次危机带来的损害不会进一步扩大;也感谢社区朋友们对社区进行自发地维护,并依旧选择信任我们。小幽灵社区有你们,是我们的荣幸。

Thanks to the friends who reminded and helped us on Twitter, Discord, WeChat and other channels. At the same time, I would like to thank the friends who warned more people that WGG Discord was hacked in various channels. Your help keeps the damage from this crisis from spreading further. Community members maintain the community spontaneously and still choose to trust us. It is our honor to have you in the WGG community.

我们一直深爱我们的社区,并对我们的社区保持着充分的自信,相信在我们的共同努力下,一个不靠原有圈外IP流量加持的加密原生项目可以保持长期、健康的发展,并在世界舞台立足,我们都在期待着这个时刻,并一直努力着。

We love our community deeply and have full confidence in our community. It is believed that with our joint efforts, an encrypted native project that does not rely on the blessing of IP traffic outside the crypto world can maintain a long-term and healthy development and gain a foothold on the world stage. We are all looking forward to this moment and have been working hard.