CSIDB logo
Incident

DeeKay Kwon

Incident posture

Attack window
Jul 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-18 00:00

Linked entities

Victim
DeeKay Kwon
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hacker compromised the Twitter account of NFT artist DeeKay Kwon, posting a fraudulent link to an exclusive NFT collection that redirected followers to a counterfeit website. Victims who approved transactions through the malicious link had their wallets drained, resulting in the theft of NFTs valued at approximately $150,000, including seven assets stolen from a self-identified former Coinbase engineer. The artist acknowledged that two-factor authentication might have been temporarily disabled on the account during the breach.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On or around July 14, 2022, attackers compromised the Twitter account of NFT artist and animator DeeKay Kwon, who had approximately 180,000 followers at the time. The hackers posted a fraudulent tweet promoting a fake "LetsWalk Collection Airdrop," falsely advertising an exclusive NFT release limited to 1,000 claimants. The tweet contained a link directing users to a counterfeit version of Kwon’s legitimate website. Followers who clicked the link were prompted to approve transactions that subsequently enabled the theft of NFTs from their digital wallets. The attack resulted in confirmed losses totaling $150,000 worth of NFTs across multiple victims. One identified victim, a self-described former Coinbase engineer, publicly disclosed the theft of seven NFTs from his wallet.

DeeKay Kwon addressed the incident through a series of tweets explaining the breach. He stated that while two-factor authentication (2FA) was typically enabled on his social media accounts, he suspected it might have been inactive during the intrusion window. The artist did not specify the exact method of initial account compromise but confirmed the attacker’s malicious link facilitated wallet drainer transactions. No technical details about the counterfeit website’s infrastructure or transaction approval mechanisms were disclosed. The incident exclusively impacted users who interacted with the fraudulent link, with no evidence suggesting broader system compromises beyond the Twitter account hijacking and subsequent NFT thefts. Kwon expressed no formal recovery efforts for stolen assets but commented on hoping for karmic consequences for the attacker.

Sources

Sources available to members: 1 source.

CSIDB