Cyber Incident Victim: Azuki
Date:
Jan 2023
Location:
United States of America
Summary
The Azuki Twitter account was compromised, leading to unauthorized posts containing malicious links that directed followers to a fraudulent website impersonating the project's metaverse platform. The team swiftly regained control, removed the harmful content, and alerted the community through multiple channels while collaborating with Twitter to investigate the breach. Despite security measures including two-factor authentication, the attackers temporarily leveraged the account's bio link to persist the scam, prompting ongoing warnings to users about interacting with suspicious claims.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 27, 2023, the official Twitter account of the Azuki NFT project (@AzukiOfficial) was compromised during the morning Pacific Time hours. Attackers posted a series of unauthorized tweets containing a malicious link prompting followers to "claim land" in The Garden, Azuki's native metaverse platform. The breach occurred despite the account being secured with two-factor authentication (2FA) via an authentication app. Azuki's team detected the compromise and swiftly initiated response protocols, including direct contact with Twitter support and public warnings to their community. Community manager Emily Rose alerted followers via Twitter not to engage with suspicious links, while Discord moderators issued parallel warnings. The malicious tweets were deleted by the afternoon of the same day, though the account's bio link remained temporarily compromised, continuing to redirect to a scam site.

Azuki regained full control of the Twitter account on January 27 after collaborating with Twitter’s internal teams to resolve the breach. The project confirmed no other official communication channels (Discord, website) were compromised. Immediate impacts included the dissemination of phishing infrastructure targeting Azuki’s user base, with historical precedent noted—in April 2022, attackers had hijacked the India University Grant Commission’s Twitter account to promote fraudulent Azuki NFT airdrops. The January 2023 incident disrupted standard community communications, requiring coordinated mitigation across social platforms to limit exposure. Secondary market data indicated Azuki NFTs maintained a floor price of 14.76 ETH (~$23,600) at the time, with cumulative sales exceeding $4.4 million since launch. No financial losses or further technical compromises were disclosed in available reports. The team emphasized reliance on multi-channel verification for official announcements while continuing to investigate the Twitter-specific security failure.
