scrobble.life
#discord

Explaining the MrBeast stupid messages on Discord πŸ˜₯

I had a bit of luck with this one, and it didn't cause more pain to everyone because of two important things:

  1. People reacted in several places, urging me to take action! - VERY IMPORTANT!
  2. I was luckily awake (and around) because I was troubleshooting something on my Hive API node, so I could take action and stop the idiot.

But first...

THANK YOU ALL! 😳😍

It's in these times that I really feel humbled by the huge Hive family we have around the world. Trying to help, protecting others, making sure the "hacker" does minimal damage.

In these situations, the best direction is always to protect first, investigate later. So, when these things happen, change your passwords, check that your MFA still works, log out of all sessions from everywhere (apps should have this flexibility; otherwise don't use them), and very importantly, review access to the logins/APIs/apps permissions to your account (I will go into detail about what happened below).

If you do this, you can at least stop whatever you might yet NOT understand why or how. And in this case, this is related to the Discord app, but it could have been related to any other app, for that matter. If needed, even disconnect from the internet, etc...

When and How I noticed?

Yesterday (for me) around 3:42 PM to 3:44 PM UTC, my Discord handle DMed a couple of people I had chats with, some MrBeast spam, and also set those DMs to "Ignore" and "Muted". This tactic ensured that even if I was around (which I was), I could not notice the process... because DMs that are muted can't notify me, and if they are ignored, I can't see them anymore on Discord (and it requires you to go check which ones you ignored in order to unignore).

Even the picture they sent is a scam

What the idiot forgot was that I have a ton of people interacting with me, and after a while I was finding it a bit weird having so much interactivity with me at that time of the night. And I decided to check... and found out!

What happened then?

After changing passwords and checking my sessions, I quickly tried checking if this was an account hack (or possible bug) but I had no suspicious sessions, so it didn't explain (although they could have stolen my fingerprint too), and then I decided to check all the Authorised Apps to my Discord and found two old ones (out of 3) that I haven't used for ages, which had write permissions to my account. And then I thought it could have been write permissions from the app that could have done this... one of them I know was hacked in the past, and this app had write permissions, hence my first suspicion.

But now, after reading and learning a bit more, Discord says it blocks this kind of ability... for explicit DMs etc... so either your cookie was stolen, and the hacker didn't manifest itself until sometime in the future (quite possible), or something else I don't yet quite understand. Either way, I can't even verify, so even if Discord says it can't happen via app permissions, I can't say otherwise because I don't have access to the code.

I had 3 apps that had write permissions, and 2 of them I was suspicious about (one of them because I know they got hacked).

I am now waiting for Discord to compile the logs for me to download them and see if I can trace things back more accurately, and if I find anything plausible, either going to create a report for the police, or going to just reach out to the app.

Moral of the story...

Maybe the best with web2 is to constantly change passwords/tokens, etc every week/month/year (whatever is deemed necessary)... because the level of crap that is out there becomes really hard for any of us to monitor 1000 things. And you will get compromised... I can tell you that! It's not if, it's when, so the more prepared you are, the better.

Check for things you might not recall doing... which often tells you something is already hacked. And that should tell you, go change the password NOW! If it was just amnesia, you don't lose much... if it's a signal of a compromised thing, then you can avoid it, hopefully in time.

Also check things you don't use anymore and uninstall them, deauthorise them, etc... this is probably the biggest fail of many, and hackers use these things to get either additional information or trigger situations that can make you expose secret stuff. And if you suspect something weird happened (which I think it might have been the case with me), and nothing happens immediately, change passwords just as a precaution. I failed to ignore something weird that happened on a Discord channel a while ago, and I suspect it was that... which tells me how much this hacker wants to deceive me (or just had me on the victims list for "one day").

Once I get the logs, maybe I will find out more.

Fricking idiots! 🀬

At the same time, of this...

Because yesterday I had a crash of my API node, it coincidentally made all my day really crap, hence why I was up in the middle of the night. But this was coincidental, as the server hung into a mode that could not even reboot, but it was powered on, and no console screen, nothing, and I had to force reboot it. First time this happened, so hopefully it's just "DUST", hence why yesterday it was a good moment to do a general cleanup.

Stay vigilant!

This is always very frustrating, and all it does is make you lose time... Not that I think someone is after me, but I am gathering more and more evidence that they know where I live and the attacks are on purpose in the middle of the night. Hopefully I am just delusional.

Comments Β· 16

  • @pizzabot(60)Β· 28d

    PIZZA!

    $PIZZA slices delivered: @savvytester(4/5) tipped @forykw

    Send $PIZZA tips in Discord via tip.cc!

  • @commentrewarder(75)Β· 36d

    Update: @forykw, I paid out 3.373 HIVE and 0.000 HBD to reward 11 comments in this discussion thread.

  • @calebmarvel24(70)Β· 40d

    I'm gonna check on it, thanks once more...

  • @steevc(80)Β· 40d

    I saw that spam on one channel, but am not aware of any coming from me. We have to be so careful with all these apps.

  • @forykw(71)Β· 40d

    @detlev, this post. Please do not click on any of those things... and I will never send these things to any user.

  • @josediccus(83)Β· 41d

    I saw the spam constantly too, they were always sending it in the TIPU discord account. I was robbed of almost a years earning in hacked wallets, so these hackers are getting smarter

  • @caspermoeller89(68)Β· 41d

    There are places where one can look up if accounts/mails/usernames etc has been compromised.

    I can't remember them from the top of my head though.

    Glad you got it sorted that quick. I didn't receive anything from you - I would have reacted too πŸ’ͺ🏼


    !BBH !ALIVE

  • @cositav(73)Β· 41d

    I'm glad everything was resolved in time, wow, that's worrying. Me imagino el momento incΓ³modo hace un tiempo pase por algo similar y es desesperante.

  • @angeluxx(74)Β· 41d

    It's good that you have everything under control and know what measures to take. And it's good that they alerted you. I hope it's just a bad moment and everything is alright.

  • @tibfox(74)Β· 42d

    Glad you got control back and that you acted this quickly! I hope you dont have any follow up issues because of that :) I also revoked almost all of my authorized apps just to be safe :P

  • @louis88(80)Β· 42d

    Interesting! I just revoked all third-partie Connections - i did not used them anyway - just a clean up - thanks and glad it made no damage.

  • @ph1102(79)Β· 42d

    Thanks for the heads-up and tips, and good to see you got your account under control! The worst thing is when it happens to a person who "knows these things", it hurts even more... I remember when the AI thing got into the 6th gear, my hosting server was hacked multiple times in a few weeks...

    As you said, it happens, and it will happen to everyone, sooner or later... Hopefully, just a silly, ridiculous thing like this one, and not something much more serious...

    Btw, the tactic of stealing some data and staying dormant for a few days or weeks before harming is a popular, recent strategy... So, maybe your data leaked a week ago, or more, and he executed the "attack" now...

    Interestingly, I got a DM from you too (okay, not you but hacker πŸ˜ƒ), and he/she sent a message into the group chat with Achim and me... lol... Sent the message, and left the chat room, so you had no idea it came out...

    image.png


    I have picked this post on behalf of the @OurPick project! Check out our Reading Suggestions Posts!

    Comment Footer.jpg Please consider voting for our Liotes HIVE Witness. Thank you!

  • @fonestreet(73)Β· 42d

    !LOL

  • @acidyo(84)Β· 42d

    Glad you got your account back!

  • @friendlymoose(77)Β· 42d

    Rhanks for this update! Good learning points. The advise of regularly changing your passwords is not promoted anymore by the big tech companies. Setting long, random and different passwords for your accounts still is a good practice. Configuring MFA and/or pass keys is also recommended.

    And as you mentioned already; checking permissions. It's also wise to review the rights you've given for any Hive apps to post on your behalf every now and then by the way.

  • @cwow2(73)Β· 42d

    Properly a good idea to check up on permissions xD