A security breach allowed a hacker to extract funds from the Monero community wallet, a protocol focused on transaction protection, resulting in a loss of 2,675.73 XRM, equivalent to almost $460,000.
According to a disclosure from a Monero developer via GitHub, the community crowdfunding system was attacked around midnight on September 1st. However, the information was not released until November 2nd while investigations were carried out to prevent further attacks. The developer identified as Luigi stated this The origin of the security hole is not yet known.
Monero’s so-called Community Crowdfunding System (CCS) is a hot (online) wallet used to fund protocol development projects. Aside from that, The hacked wallet is used to “occasionally” inject funds into the hot wallet, which is used for payments to the community of contributors was not injured and has a balance of 244 XMR.
“The attacker may not know what they stole. In this case, I would ask him to assume that he stole funds donated by individuals for specific things that Monero contributors are working on,” developer Ricardo noted in the thread. “Fluffypony » Spagni. And he added: “This attack is unimaginable as they have stolen funds that a taxpayer might expect to use to pay rent or buy groceries.”
The team at Moonstone Research, a company that uses tools to track Monero transactions, has presented detailed research based on the Monero team’s notes. Specifically, 11 transactions were carried out with the compromised wallet. “In particular, we were able to reliably trace three of the attacker’s transfers,” says the Moonstone Research document. In just 24 hours, they discovered that one of these transactions was sent to an exchange service, an exchange, or to “themselves” via the Monerujo wallet’s PocketChange feature. The other two may have been sent directly to exchanges.
According to Luigi’s post, only he and Spagni had access to the seed phrase of the CCS wallet, which was set up in 2020 along with a Monero node on an Ubuntu laptop. In 2021, Luigi transferred CCS funds to the project’s hot wallet in response to Spagni’s arrest, which CriptoNoticias reported; The operation was later reversed when it emerged that the reason for the arrest had nothing to do with Monero.
In May 2023, Luigi made the last CCS transfer to the hot wallet through which payments to taxpayers are made. On September 28th, Luigi logs into CCS to top up the wallet and I noticed that there is a transaction from September 2nd with a donation and that the rest of the money was “swept away” in 9 transactions.
As a result of these events, several contributors speculated about what might have happened and even suggested migrating the system to an open source (offline) hardware wallet like MoneroSigner and even using multisignatures to secure CCS funds. In this regard, Spagni noted that the implementation of this resource is difficult.
A number of transactions are identified as being involved in the theft. Source: SamsungGalaxyPlayer / GitHub
Regarding the nature of the hack, Spagni commented: “It is entirely possible that it is related to the ongoing attacks we have seen since April, as they involve a variety of compromised keys (including Bitcoin wallet.dats, seeds generated using all sorts of hardware ). and software, Ethereum presale wallets, etc.) and include XMR that has been cleaned. With these words, the developer alludes to the thefts of cryptocurrency wallets that would be a consequence of the hack of LastPass, a password manager that encrypts data in the cloud, as CriptoNoticias reports.
Other developers have suggested this The CCS violation could have originated from the Ubuntu server. because the keys could have been online at a certain time. Others asked whether the theft would affect Monero development: the answer was negative, as this fund “is not normally used for active development.”
Recently, CriptoNoticias reported on a security flaw that compromised Monero privacy for three years.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.