Tweet Threads

Discord Security Threads, Web3 Security Guides, NFT Information and Tutorials.
Below you'll find all my various threads, thoughts, videes and free resources.
If you enjoy them or learn something from them, please retweet the original thread, thank you!
Most Important Threads
Either really impactful free resources or extremely important practices to follow.
๐ข Free Discord Security Quiz ๐ข
— Jon_HQ (@Jon_HQ) August 21, 2022
Over 900 founders, mods, and general NFT folk have taken this free quiz already. It will test you on your Discord security knowledge.
Take it and see how well you do, explanations are given at the end for each question.https://t.co/AwBzFkX9eT
๐ฅถ Cold Admin v.3
— Jon_HQ (@Jon_HQ) December 6, 2022
Here is my most recent Cold Admin setup instructions.
What is a Cold Admin? It is a Discord account that is distinct and exclusively used on a separate device, such as an old phone or laptop.
Stay safe and keep your servers secure by using Cold Admins. pic.twitter.com/O2CmeAGPv9
ICYMI:
— Jon_HQ (@Jon_HQ) December 9, 2022
I recorded an hour long video discussing my free Discord server template.https://t.co/CjDAjA3sPy
This is a great resource for projects or even baby auditors to use.
Copying is easy, understanding why things are the way they are take time to learn and comprehend.
๐ซ ๐ค๐จ
— Jon_HQ (@Jon_HQ) August 17, 2022
Discord Security... and... Community Management?
Discord security is not just keeping things secure, it's also about keeping things useable.
So let's flip the script a bit and look at what CMs ๐ป๐ฒ๐ฒ๐ฑ to do inside a Discord community, and how we can do it securely.
Discord Security Threads
There are a couple core bots you need for a secured NFT Discord server.
— Jon_HQ (@Jon_HQ) December 13, 2022
Here they are, for free.
This is good alpha even as a collector, if you can't find a bot in the server, they probably haven't got audited or know what the hell they're doing. pic.twitter.com/OHNDaoLdcT
๐จ๐จ Discord Security Tip - Cold Admins ๐จ๐จ
— Jon_HQ (@Jon_HQ) May 11, 2022
I've spent the last month or so talking with NFT project owners and trying to explain cold admin accounts, how they work with a Discord... and at this point, I think I need to extrapolate even more.
Here is the Cold Admin Protocol.
NFT projects get compromised and lose ๐ข๐๐ก๐ก๐๐ค๐ฃ๐จ because they do not understand Discord permissions.
— Jon_HQ (@Jon_HQ) September 27, 2022
Can you name the most deadly ones?
5 minutes reading this thread could save your project from getting ๐ด๐ค๐ข๐ฎ๐ฎ๐ฆ๐ฅ.
Here are the 7 Deadly Discord permissions: pic.twitter.com/zb5lGrZQcW
๐จ What do you do if your Discord server is being hacked, a checklist. ๐จ
— Jon_HQ (@Jon_HQ) March 12, 2022
I'll post this both as a Twitter thread, and as an image attached to this tweet.
Download the image and save it to share with teams, or print it out! pic.twitter.com/lz89tmHsdd
๐จ Discord Security Tips ๐จ
— Jon_HQ (@Jon_HQ) September 20, 2022
In a bear market, NFT projects are quietly building, planning longer runways, and improving...
Due to the ๐งธ market, projects might not be able to afford a full Discord audit, so here are three tips you can implement ๐ฃ๐ค๐ฌ to protect your community.
๐จ Discord Security Tip ๐จ
— Jon_HQ (@Jon_HQ) May 14, 2022
If you're starting a new Discord for an NFT project and getting everything set up during this bear market, here are some broad strokes about what you should focus on during the setup.
๐จ Discord Bot Compromise Update ๐จ
— Jon_HQ (@Jon_HQ) April 1, 2022
What's next? How do we stop this in the future?
So - official little recap here - past the bot pushing a bad update, the bot asked for manage webhook perms, which it might need for some functionality... but there is no reason to grant it. 1/2 pic.twitter.com/qmB9FM4rXa
๐จ This could save your NFT's Discord from getting hacked ๐จ
— Jon_HQ (@Jon_HQ) February 13, 2022
What if you could identify that one of your moderators was compromised...
...and that attackers were preparing a fake mint announcement in your Discord...
Hours or days before it happened?
๐จ Know yall missed these Discord tips ๐จ
— Jon_HQ (@Jon_HQ) March 30, 2022
If you want to do a CLOSED Discord for marketing hype reasons or whatever, you can do it safely.
Read this๐งตto learn how... and the reason why a closed Discord using expiring invites is a bad idea...
๐จ Discord Tip: Protect the new frens ๐จ
— Jon_HQ (@Jon_HQ) March 31, 2022
Every Discord moderation bot has something called an Automessage
Enable this, smack it into #general, and send the message every 4-6 hours. Spam the newbs to save them
Use my template, tell me if you think there is anything else to add! pic.twitter.com/y7F15YTg45
๐จ Discord Security Alert ๐จ
— Jon_HQ (@Jon_HQ) August 29, 2022
Since the newest Discord phishing attack is a little hard to understand, I've made an image showing a valid oauth request on the left, and the scam oauth on the right.
ALWAYS check where you're being redirected to.
Please share for awareness. pic.twitter.com/wUKMVMforT
๐จ Discord Security Tip ๐จ
— Jon_HQ (@Jon_HQ) June 8, 2022
What to do when the worst happens and your Discord server does get compromised?
This thread will cover what you should do as an admin or a server owner during all stages of a Discord compromise and fake mint/airdrop phishing scam.
This Discord is using a VERIFIED bot renamed.
— Jon_HQ (@Jon_HQ) April 4, 2022
It is a fake Wick bot, requiring you to verify.
It asks you to scan a QR code to verify - this logs you in on a new client the attackers control.
The attackers are leveling up again, stay safe folks. This one is nasty. https://t.co/Sdrh4oYhA5
Were you aware that the average NFT Discord has over 12 users with Mod or Team level perms? An infographic thread ๐งต pic.twitter.com/mOYcYXMOrp
— Jon_HQ (@Jon_HQ) March 2, 2022
๐จ๐จ๐จ Discord Security Tip ๐จ๐จ๐จ
— Jon_HQ (@Jon_HQ) May 30, 2022
I've been thinking a lot about impersonation attacks the last few days.
It is common for phishers to pose as a team member to try to scam normal users.
Let's dig into it a little. h/t to @crystalgroves for alerting me to this impersonator: pic.twitter.com/kQ7GKb0OgK
๐จ๐จ๐จ Discord Security Alert ๐จ๐จ๐จ
— Jon_HQ (@Jon_HQ) May 25, 2022
As if moderators and admins getting phished weren't enough.
I now have multiple independent confirmations that attackers are straight up bribing any of your Discord staff with up to $100k...
What can you as a project owner do?
๐จ Discord Security Tip ๐จ
— Jon_HQ (@Jon_HQ) August 21, 2022
When a phishing method stops working as well, scammers don't stop. They evolve.
There have been rumors of attackers now impersonating project founders and replicating how their voice sounds using voice modulators.
How should teams react?
๐จ Discord Tip of the Day ๐จ
— Jon_HQ (@Jon_HQ) April 3, 2022
The last couple of weeks has seen a drastic shift in types of attacks against Discords...
I sat down and tried to create a risk matrix of both the severity and the impact of these different methods - let me know what you think! pic.twitter.com/BaijY20FrN
Discord Auditing
๐ง Discord Auditor Self Checklist ๐ง
— Jon_HQ (@Jon_HQ) December 27, 2022
It has been over a ๐ฎ๐๐๐ง since the pandemic of Discord Compromises started
The following reflect the best practices that have been developed in that time.
This checklist covers what your setup should have. Do you check all the boxes?
๐จThings to ask your Discord Auditor before hiring them (Feel free to add on things if you think I missed anything!)๐จ
— Jon_HQ (@Jon_HQ) March 10, 2022
A pretty short thread.
#1: Will they change things for you?
Some auditors will only do a call with you. This can take longer, and result in a worse audit.
๐จ Discord Security Tip ๐จ
— Jon_HQ (@Jon_HQ) June 10, 2022
I made a whole thread about how to pick a Discord auditor. I can actually condense it way down now.
In this threat environment, I can boil it down into one single thing to check.
Read on to figure out if your Discord auditor has swindled you.
๐ Discord Security Vocabulary Terms ๐
— Jon_HQ (@Jon_HQ) October 27, 2022
There are a lot of folks out there: Mods, CMs, Founders, and Auditors all working with Discord servers.
Keeping everyone on the same page is tough...
So here's an exhaustive guide listing common Discord security terms and what they mean!
Web3 Security Threads
๐จ Twitter Account Hack Alert ๐จ
— Jon_HQ (@Jon_HQ) June 29, 2022
This is how it has been reported to me that projects (JRNYclub, nounsdao, potentially others earlier this year) are having their Twitter accounts hacked...
And here is how you can protect yourself, your project, and your community.
A thread. pic.twitter.com/ZUp5sMsFTU
โ How immutable is your Blue Chip NFT โ
— Jon_HQ (@Jon_HQ) September 4, 2022
ERC721 contracts usually have an owner assigned and they can update things in the contract, such as the project's URI.
Even if your images are on IPFS, if the owner still has control of the contract, the link to those images can change.
The fake WL messages have gotten way too annoying.
— Jon_HQ (@Jon_HQ) October 9, 2022
I've caved and set my notifications to filter out the accounts sending them.
If you want to do the same, in your Twitter Settings go to Privacy and Safety, Mute and Block, Muted Notifications, and toggle the below settings: pic.twitter.com/iIeBn0sd0B
๐จ NFT Drainer Alert!!! ๐จ
— Jon_HQ (@Jon_HQ) September 22, 2022
What I posted about originally as being a scheme to get your Discord token has been used for more than that...
Attackers used the XSS attack with Everdome as a trusted site to also generate malicious OpenSea signature requests.
What you need to know:
๐จ NFT NYC Security Tips ๐จ
— Jon_HQ (@Jon_HQ) June 16, 2022
I've seen a couple posts about NFT NYC and keeping your digital assets secured while there... Honestly I don't think most of the posts or threads go nearly far enough.
You are a major target, and here is how you can protect yourself:
๐จ NFT Marketplace Listing Scams ๐จ
— Jon_HQ (@Jon_HQ) November 3, 2022
Marketplace @blur_io has an increased risk of buying the wrong listing and victims accidentally purchasing NFTs for 10x the price.
Let's look into why, how you can protect yourself if you use Blur, and why this scam works. pic.twitter.com/WuEsM9L0vX
You ๐๐๐ฃ still be making money if your NFT falls in price.
— Jon_HQ (@Jon_HQ) October 9, 2022
You can limit your exposure to a falling floor price, and X2Y2 has just made this much easier.
So let's look at how... and also talk about 1 super stupid degen play that could make someone in this space filthy rich.