TRM Labs published an analysis on July 24, 2022 linking a wave of Discord compromises targeting non-fungible-token communities. The blockchain-intelligence company estimated that the NFT community had lost $22 million since May through scams promoted from compromised Discord accounts.

TRM also reported that more than 100 Discord-channel hacks had been submitted during the preceding two months to Chainabuse, the community reporting platform it operated. Its dataset showed phishing attacks connected to fraudulent NFT mints increasing 55% in June compared with May.

Those figures described a security problem extending beyond any single collection. They did not constitute an independently audited census of every Discord compromise or victim loss. All three measurements—the $22 million estimate, the report count and the monthly increase—came from TRM or its own reporting platform.

Evidence of connections between incidents

TRM said it reviewed more than 15 notable compromises using on-chain transactions and off-chain information. It concluded that dozens of recent account compromises were likely related, including incidents affecting communities associated with Bored Ape Yacht Club, Parallel, Bubbleworld, KaijuKingz and other projects.

The company did not claim that one identified person or organization controlled every operation. It found recurring methods and overlapping financial infrastructure: compromised administrator accounts, fraudulent limited-mint announcements, malicious wallet prompts and proceeds moving through wallets with exposure to other attacks.

TRM’s strongest case study concerned the June 4 compromise of Discord servers connected to Yuga Labs. Contemporaneous reporting recorded Yuga confirming that its servers had been breached after a community manager’s account was compromised. The attacker then advertised a fraudulent giveaway to holders of Bored Ape Yacht Club, Mutant Ape Yacht Club and Otherside assets.

TRM traced NFTs removed from affected wallets into a consolidation wallet and then to a marketplace, where assets were sold for ether. It said most of the resulting proceeds moved through three wallets. One of those wallets sent funds to Tornado Cash and had direct exposure to wallets associated with other Discord compromises during May and June.

That transaction overlap supported a connection, but it was not proof of common control. Shared infrastructure can be used by one operator, multiple collaborators or unrelated customers of the same illicit service.

Social access became wallet access

The incidents illustrated how an off-chain account compromise could produce irreversible on-chain transfers. Attackers used trusted community channels to create urgency around supposedly scarce or free NFT mints. Victims who followed the links could be prompted to authorize contract calls granting an operator broad transfer rights over ERC-721 tokens.

Blockchain settlement did not authenticate the message that induced the approval. Once a victim signed the malicious authorization, the attacker could move specified assets through transactions that the network treated as valid. The security failure therefore crossed several layers: social-media administration, user-interface deception, wallet permissions and marketplace liquidity.

Chainabuse had launched in May 2022 as a community reporting service backed by several crypto organizations. Its more-than-100-report figure measured submissions, not necessarily 100 independently verified attacks. Multiple people could report one incident, some compromises might never be submitted, and reports could vary in evidentiary quality.

What the July 24 record established

TRM’s July 24 publication established that a specialist investigations team had found recurring behavior and interconnected fund flows across a substantial sample of NFT-community compromises. Independent reports about the Yuga incident corroborated the broader attack pattern and its use of a trusted Discord account to distribute phishing material.

The record did not establish a final victim count, a complete loss total or the identity and number of responsible groups. TRM expressly left open whether the activity reflected one group, several coordinated groups or scam-as-a-service infrastructure supplied to multiple operators.

No cryptocurrency-price or NFT-market-return claim is warranted from this evidence. The verified development was the emergence of a repeatable security pattern and an investigative indication that apparently separate community compromises shared financial connections—not a measured causal effect on ether, NFT floor prices or the wider digital-asset market.

Primary sourceTRM Labs — Analysis of Recent NFT Discord Hacks Shows Some Attacks Are Connected

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.