Monero’s community wallet loses all funds after attack

0

[ad_1]

A recent attack compromised Monero’s community crowdfunding wallet, wiping out its entire balance of 2,675.73 Monero (XMR), worth nearly $460,000.

The incident took place on Sept. 1 but was only disclosed on GitHub on Nov. 2 by Monero’s developer Luigi. According to him, the source of the breach has not been identified yet.

“The CCS Wallet was drained of 2,675.73 XMR (the entire balance) on September 1, 2023, just before midnight. The hot wallet, used for payments to contributors, is untouched; its balance is ~244 XMR. We have thus far not been able to ascertain the source of the breach.”

Monero’s Community Crowdfunding System (CCS) funds development proposals from its members. “This attack is unconscionable, as they’ve taken funds that a contributor might be relying on to pay their rent or buy food,” noted in the thread Monero’s developer Ricardo “Fluffypony” Spagni.

Luigi and Spagni were the only two people who had access to the wallet seed phrase. According to Luigi’s post, the CCS wallet was set up on an Ubuntu system in 2020, alongside a Monero node.

To make payments to community members, Luigi used a hot wallet that has been on a Windows 10 Pro desktop since 2017. As needed, the hot wallet was funded by the CCS wallet. On Sept. 1, however, the CCS wallet was swept in nine transactions. Monero’s core team is calling for the General Fund to cover its current liabilities.

“It’s entirely possible that it’s related to the ongoing attacks that we’ve seen since April, as they include a variety of compromised keys (including Bitcoin wallet.dats, seeds generated with all manner of hardware and software, Ethereum pre-sale wallets, etc.) and include XMR that’s been swept,” Spagni noted in the thread.

According to other developers, the breach could have originated from the wallet keys being available online on the Ubuntu server.

“I wouldn’t be surprised if Luigi’s Windows machine was already part of some undetected botnet and its operators performed this attack via SSH session details on that machine (by either stealing the SSH key or live using trojan’s remote desktop control capability while the victim was unaware). Compromised developers’ Windows machines resulting into big corporate breaches is not something uncommon,” noted pseudonymous developer Marcovelon.

Magazine: Slumdog billionaire — Incredible rags-to-riches tale of Polygon’s Sandeep Nailwal

[ad_2]

Source link

Leave A Reply

Your email address will not be published.

bitcoin
Bitcoin (BTC) $ 87,195.00
ethereum
Ethereum (ETH) $ 2,920.67
tether
Tether (USDT) $ 0.999529
bnb
BNB (BNB) $ 842.15
xrp
XRP (XRP) $ 1.89
usd-coin
USDC (USDC) $ 0.999725
solana
Solana (SOL) $ 123.09
tron
TRON (TRX) $ 0.282817
staked-ether
Lido Staked Ether (STETH) $ 2,918.36
dogecoin
Dogecoin (DOGE) $ 0.129342
figure-heloc
Figure Heloc (FIGR_HELOC) $ 1.04
cardano
Cardano (ADA) $ 0.361442
whitebit
WhiteBIT Coin (WBT) $ 56.84
bitcoin-cash
Bitcoin Cash (BCH) $ 576.31
wrapped-steth
Wrapped stETH (WSTETH) $ 3,572.79
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 87,009.00
wrapped-beacon-eth
Wrapped Beacon ETH (WBETH) $ 3,175.81
usds
USDS (USDS) $ 0.999787
wrapped-eeth
Wrapped eETH (WEETH) $ 3,169.45
binance-bridged-usdt-bnb-smart-chain
Binance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999261
chainlink
Chainlink (LINK) $ 12.25
monero
Monero (XMR) $ 442.48
leo-token
LEO Token (LEO) $ 8.03
weth
WETH (WETH) $ 2,923.96
stellar
Stellar (XLM) $ 0.216961
zcash
Zcash (ZEC) $ 415.96
coinbase-wrapped-btc
Coinbase Wrapped BTC (CBBTC) $ 87,227.00
ethena-usde
Ethena USDe (USDE) $ 0.998633
litecoin
Litecoin (LTC) $ 76.55
hyperliquid
Hyperliquid (HYPE) $ 23.89
sui
Sui (SUI) $ 1.43
avalanche-2
Avalanche (AVAX) $ 11.95
susds
sUSDS (SUSDS) $ 1.09
hedera-hashgraph
Hedera (HBAR) $ 0.109851
dai
Dai (DAI) $ 0.999491
usdt0
USDT0 (USDT0) $ 0.999486
shiba-inu
Shiba Inu (SHIB) $ 0.000007
paypal-usd
PayPal USD (PYUSD) $ 1.00
crypto-com-chain
Cronos (CRO) $ 0.094681
uniswap
Uniswap (UNI) $ 5.76
the-open-network
Toncoin (TON) $ 1.46
world-liberty-financial
World Liberty Financial (WLFI) $ 0.131272
ethena-staked-usde
Ethena Staked USDe (SUSDE) $ 1.21
mantle
Mantle (MNT) $ 1.05
canton-network
Canton (CC) $ 0.080766
polkadot
Polkadot (DOT) $ 1.75
usd1-wlfi
USD1 (USD1) $ 0.999077
rain
Rain (RAIN) $ 0.008021
bitget-token
Bitget Token (BGB) $ 3.45
memecore
MemeCore (M) $ 1.36
Shares