Curriculum·G704 Community Moderation·about 31 min
The server is the attack surface
By the end of this lesson you can
- →State what happened in the Bored Ape Discord compromise of June 2022, what was taken, and which account the message came from
- →Explain why a community server is an attack surface in its own right, and why a message from the right account in the right channel defeats every check members have been taught
- →Compute the value at risk in a community from its member count and holdings, and read what a single compromised moderator account is worth to an attacker
- →Inventory a community's surface: every account that can post as the project, every integration that can, and every channel members trust
Graduate · enrolled learners
This lesson opens with The Bored Ape Yacht Club Discord, 4 June 2022.
- What happened
- The Discord account of Yuga Labs' community manager, Boris Vagner, was compromised and used to post a phishing link in the official Bored Ape Yacht Club server and in the server of the related Otherside project. The post was dressed as an exclusive giveaway for holders of Bored Ape, Mutant Ape and Otherdeed tokens. Members who followed the link and signed were drained. Yuga Labs confirmed the compromise and reported that about 200 ETH of NFTs, roughly $360,000 at the time, was taken: 32 tokens including one Bored Ape, two Mutant Apes, five Otherdeeds and one Bored Ape Kennel Club token, traced to four wallets. A co-founder publicly criticized Discord's security model for web3 communities afterward.
- The decision point
- The message came from the right account, in the right channel, with the right role badge, from a person members had seen post for months. Every check a member had been taught, is this the official server, is this an admin, is this the kind of thing the project announces, passed. What failed was the assumption that the server's trust structure was the project's security, when it was one person's Discord login. A community server is a surface with as many entry points as it has privileged accounts and integrations, and the members' trust in it is exactly what makes a single compromised account worth the attacker's effort. A community leader who has not inventoried that surface is running the server in the autopsy.
- Recorded loss
- $360,000
What you will be able to answer
- →What happened in the BAYC Discord in June 2022?
- →Why did the right account defeat the members' checks?
- →What is on a community's attack surface?
- →What does restricting posting to admins do?
Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.
It is free. We do not sell the list and there is nothing to buy at the end of it.
Sources and review
- https://www.coindesk.com/business/2022/06/04/yuga-labs-confirms-discord-server-hack-200-eth-worth-of-nfts-stolen
- https://decrypt.co/102076/bored-apes-co-founder-blames-discord-after-200-ethereum-snatched-in-exploit
- https://www.artnews.com/art-news/news/yuga-labs-server-breach-phishing-attack-1234630785/
Confidence high·Volatility medium·Reviewed 2026-09-14·Owner unassigned
Contested
Loss figures for the incident vary between about 145 ETH and 200 ETH across reports, and the token count of 32 comes from on-chain tracing by independent parties rather than from Yuga Labs' own statement. The lesson uses the figure the company confirmed.
How the community manager's account was compromised was not publicly established. The lesson's claim does not depend on the method; it depends on the fact that a legitimate privileged account was the vector.
