TLDR: A fake (but Twitter verified!) journalist account reached out to me on Twitter offering to write an article about CityDAO for The Block. They sent me a link that claimed to be a consent form, which I clicked, which ran Javascript and stole my Discord token.
Join this CityDAO Telegram group https://t.me/+3aydIqRFmRE5OTA5
Discord Support Tickets:
42626202
42606309
Been radio silence from Discord’s Trust and Safety team for 3 days. My account is still disabled and if anyone can help elevate these tickets, please let me know.
Here’s what happened:
What happened:
-
I was DM’d on Twitter by a verified account with lots of followers claiming to be a journalist for The Block here https://twitter.com/Yuazzi0x
-
I answered some questions about CityDAO, I’ve done this countless times for journalists, and responded.
-
They asked me to fill out a consent form on their fake website before publishing: https://theblock.fi/ (Insane that I fell for it in retrospect….journalists definitely don’t need consent to publish.)
-
When I pressed the button, it said to drag it to the bookmarks bar and press it to verify so it could grant me a verified role in Discord. I did it and it executed some Javascript that gave them my Discord token.
Will try to keep this thread updated with the latest, but for now, let’s move the conversation to Telegram:
https://t.me/+3aydIqRFmRE5OTA5