Urgent: Discord Security Alert for Biohackers

Join Community

Summary

The Biohacker Lounge - Josh Universe community has issued an urgent security alert regarding a widespread Discord account exploit that bypasses 2FA through session hijacking, allowing attackers to steal account cookies. This exploit is being used to send "Mr Beast giveaway" scams promising free cryptocurrency via DMs and server chats. Members are strongly advised to avoid suspicious links, enable strong 2FA, update systems, use password managers, and immediately log out of all devices if they su...

INTERNATIONAL BIOHACKING COMMUNITY OFFICIAL NOTICE - ONLINE SECURITY

It seems there is an exploit going around at scale, targeting user's Discord accounts. Once an attacker has control of a Discord account, they are sending scam messages in people's DMs and in server chats about a "Mr Beast giveaway"(how original) which prompts the user to go to a site and enter a code to get free USDT(a cryptocurrency).

I am aware of two users who have had their accounts hijacked due to this scam, one already got their account back.

The hijacker is likely using a session hijacking exploit, which BYPASSES 2FA by encouraging the user to provide remote access(willingly or unknowingly) to the user's machine where an account session cookie is taken from the user's browser. Your cookie is a literal plaintext file which contains a long string that verifies your session.

RECOMMENDED ACTION(S):
1. Do NOT engage in any messages in your DMs, email, or any other medium/form of communication promising free money/crypto/etc
2. Enable 2FA. The most secure 2FA method is a physical security key(Yubikey), then a TOTP app, then email and SMS being least secure.
3. Upgrade your operating systems and mobile devices(this can affect insecure versions of Android). If you are able to, switch to Linux or use MacOS. Note that MacOS and Linux are still prone to malware.
4. Utilize a password manager and generate secure passwords(minimum 32 characters, 64 recommended). KeepassXC and Bitwarden are great ones.

If you suspect you may have clicked on a bad link or otherwise think someone else might have access to your Discord do the following:
1. Go to Discord settings
2. Click "Devices"
3. Scroll all the way down
4. Click "Log out of All Known Devices"
5. Re-authenticate only on devices that are yours

Even if a message comes from a friend, still take caution as their account may be hijacked

The latest from The Biohacker Lounge - Josh Universe

Join The Biohacker Lounge Official Telegram!

@Ping: Announcements Join our Telegram community! https://t.me/biohackerlounge ## BIOHACKERS Official Telegram ![Embed Thumbnail](https://cdn1.telesco.pe/file/qADjYrEmhcfWJVSC7FYZjTPBBnpmeJ6H3zthaj9SE2iWxPmkV1NFBv8i8MYQNcdEdfx3utASRvP7fhXS6KM-eiQlTHEXD4Yn0VISR5oClV7AOUTEZwp_kPjqvzedZxQVTTw-9Y0zVfOTrZt2uu0Wrd9w0BDZMkx49AcCnpb7rXit47bPQ0f6BHSYmiMgSpPh6bgibcEPH-zxo_I6OM62GPzcv9YVzvmPUZuIM-akkPEBfixMG0BWrJRfP1FP576Rq_VVJ6JXmDCipRX6Rg0Tq1v2lIqxhOheY0Akv5YzuDrpZZMl6iohfTT6bFstvkQmKM55eQMU7HzsAGMiDwaCsw.jpg) Welcome to the Official Telegram of the International Biohacking Community — uniting …

Join The Biohacker Lounge Official Telegram Group

Join our Telegram group! https://t.me/biohackerlounge ## BIOHACKERS Official Telegram ![Embed Thumbnail](https://cdn1.telesco.pe/file/cW9pvqeWV3Vq1sT7OZd0GSIn9253mooQ4h51cpD9q0VslLLR8c-81iM2Qr3aMsaVbgXVrJZYWlPo9Wyc3U_XRpA_1UF4tOczR19WEY4GWtVlFf_siBqO7OKjeU0ki6LN_pNiafp7hJPwpPAsTz6CV_DW8da4WJfp-VP9Lji1qAPBZAHtOSxZD-WaEfQ2Ey8IbP0TuYP4M5kQDS5cb7vFA-52AsCEY6EVgGAs0yiqUdm0Hs19ljGP8cairCycurXWOPTifdIrXvW4E161bFh1DgrC58IjdZiT84n_6sa9bCIHJ5Ie7QJ6pNValnIQUzH3YW4gLs3r1K8TFd19q_6bmw.jpg) Welcome to the Official Telegram of the International Biohacking Community — uniting biohackers worldwide …

Customize Your Biohacker Lounge Experience Now!

|| @Biohacker @Ping: Announcements || **You can now fully configure your server experience in #👥・roles-settings !!** - Disable unwanted channels (guidelines, community-groups, invite-others, verify, member-perks, …

New Telegram: Research Peptide Lounge Launched

|| @Biohacker @Ping: Announcements || We have a Telegram for peptide-focused discussion now! You can join here: https://t.me/peptidelounge (This is only for research peptides) ## …

Quick-Add Invites for Gated Channels Now Live!

@Ping: Announcements @Ping: Technical Introducing **quick-add invites** - a way to quickly add your friends into a particular topic/language/media channel without the fuss of setting …