Monero’s community wallet loses all funds after attack

Share This Post

A security breach has resulted in the loss of 2,675.73 XMR from Monero’s community crowdfunding wallet. The cause and source of the breach remain unidentified.

A recent attack compromised Monero’s community crowdfunding wallet, wiping out its entire balance of 2,675.73 Monero (XMR), worth nearly $460,000.

The incident took place on Sept. 1 but was only disclosed on GitHub on Nov. 2 by Monero’s developer Luigi. According to him, the source of the breach has not been identified yet.

“The CCS Wallet was drained of 2,675.73 XMR (the entire balance) on September 1, 2023, just before midnight. The hot wallet, used for payments to contributors, is untouched; its balance is ~244 XMR. We have thus far not been able to ascertain the source of the breach.”

Monero’s Community Crowdfunding System (CCS) funds development proposals from its members. “This attack is unconscionable, as they’ve taken funds that a contributor might be relying on to pay their rent or buy food,” noted in the thread Monero’s developer Ricardo “Fluffypony” Spagni.

Luigi and Spagni were the only two people who had access to the wallet seed phrase. According to Luigi’s post, the CCS wallet was set up on an Ubuntu system in 2020, alongside a Monero node.

To make payments to community members, Luigi used a hot wallet that has been on a Windows 10 Pro desktop since 2017. As needed, the hot wallet was funded by the CCS wallet. On Sept. 1, however, the CCS wallet was swept in nine transactions. Monero’s core team is calling for the General Fund to cover its current liabilities.

“It’s entirely possible that it’s related to the ongoing attacks that we’ve seen since April, as they include a variety of compromised keys (including Bitcoin wallet.dats, seeds generated with all manner of hardware and software, Ethereum pre-sale wallets, etc.) and include XMR that’s been swept,” Spagni noted in the thread.

According to other developers, the breach could have originated from the wallet keys being available online on the Ubuntu server.

“I wouldn’t be surprised if Luigi’s Windows machine was already part of some undetected botnet and its operators performed this attack via SSH session details on that machine (by either stealing the SSH key or live using trojan’s remote desktop control capability while the victim was unaware). Compromised developers’ Windows machines resulting into big corporate breaches is not something uncommon,” noted pseudonymous developer Marcovelon.

Magazine: Slumdog billionaire — Incredible rags-to-riches tale of Polygon’s Sandeep Nailwal

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

$40 XRP? Analyst Reveals Key Insights Suggesting Major Uptrend Ahead

A crypto market analyst recently released a study that predicts a big rise in the price of XRP This study fits with the current excitement in the crypto community, especially since Elon Musk made his

What happens to Polymarket bets if result of US Election is contested?

The decentralized prediction market platform Polymarket has clear outlines for resolving bets on the 2024 US Presidential Election in the event of contested results The platform’s market,

QCP Capital Analysts Highlight Impact of US Elections on Crypto Markets

QCP Capital’s latest market update highlights the influence of the upcoming US elections on financial markets, with a particular focus on cryptocurrencies like bitcoin (BTC) Analysts predict

Bitcoin network’s all-time high hash rate pushing mining difficulty upward

Bitcoin mining difficulty has reached a record high, driven by an unprecedented surge in the network’s seven-day moving average hash rate On Oct 21, data from Blockchaincom revealed that

Bitfufu Expands to Africa: Acquires 80MW Bitcoin Mining Facility in Ethiopia

Nasdaq-listed cloud mining services company Bitfufu has announced an agreement to acquire a majority stake in an 80-megawatt (MW) Bitcoin mining facility in Ethiopia This strategic move marks a

Ripple’s Brad Garlinghouse joins crypto leaders in backing John Deaton over Elizabeth Warren

Ripple CEO Brad Garlinghouse has publicly endorsed pro-crypto lawyer John Deaton‘s campaign to unseat Senator Elizabeth Warren and become the next senator from Massachusetts On Oct 22,