Ultimate magazine theme for WordPress.

Community wallet Monero loses all of its balance after a hacker attack

A recent attack compromised the Monero community’s crowdfunding wallet, wiping out their entire balance of 2,675.73 Monero (XMR), worth nearly $460,000.

The incident occurred on September 1st, but Monero developer Luigi only announced it on GitHub on November 2nd. According to him, the origin of the violation has not yet been clarified.

“The CCS wallet was emptied of 2,675.73 XMR (full balance) on September 1, 2023, just before midnight. The online wallet used for payments to taxpayers is intact; his balance is approximately XMR. So far we have not succeeded.” Find out the origin of the violation.

Monero’s Community Crowdfunding System (CCS) funds development proposals from its members. “This attack is unimaginable as they stole funds that a taxpayer could expect to use to pay rent or buy groceries,” noted Monero developer Ricardo “Fluffypony” Spagni in the thread.

Luigi and Spagni were the only two people who had access to the wallet’s seed phrase. According to Luigi’s post, the CCS wallet was set up in 2020 on an Ubuntu system alongside a Monero node.

To make payments to community members, Luigi used an online wallet that has been on a Windows 10 Pro desktop computer since 2017. If necessary, the online wallet was funded by the CCS wallet. However, on September 1, the CCS wallet was deleted on nine transactions. Monero’s core team is relying on the General Fund to cover its current liabilities.

“It is quite possible that it is related to the ongoing attacks we have seen since April, as they involve a variety of compromised keys (including Bitcoin wallet.dats, seeds generated with all types of hardware and software, Ethereum presale wallets , etc.) and include XMR that was swept,” Spagni noted in the thread.

According to other developers, the breach could be due to the wallet keys being available online on the Ubuntu server.

“I wouldn’t be surprised if Luigi’s Windows machine was already part of an undetected botnet and its operators were carrying out this attack via the details of the SSH session on that machine (either by stealing the SSH key or by live remote control via the Desktop “It is not uncommon for Windows computers to be compromised by developers, resulting in serious corporate breaches,” said the developer, using the pseudonym Marcovelon.

Clarification: The information and/or opinions expressed in this article do not necessarily reflect the views or editorial policy of Cointelegraph. The information presented here should not be construed as financial advice or investment recommendations. All investments and commercial movements involve risks and it is each individual’s responsibility to conduct careful research before making any investment decision.

Investing in crypto assets is unregulated. They may not be suitable for retail investors and the entire amount invested may be lost. The services or products offered are not aimed at or accessible to investors in Spain.

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: