A recent attack compromised the Monero community finance wallet and drained the entire balance of 2,675.73 Monero (XMR), worth nearly $460,000.
The incident occurred on September 1st, but was only announced on GitHub by Monero developer Luigi on November 2nd. According to him, the source of the violation has not yet been identified.
“On September 1, 2023, just before midnight, the CCS wallet was emptied of 2,675.73 XMR (the total balance). The online wallet used for payments to taxpayers remained intact; its balance is approximately 244 XMR. To date, we have not been able to determine the source of the breach.”
The Monero Community Financing System (CCS) finances development proposals from its members. “This attack is unacceptable because they took funds that a taxpayer might have to use to pay rent or buy groceries,” noted Monero developer Ricardo “Fluffypony” Spagni in the thread.
Luigi and Spagni were the only two people who had access to the wallet’s seeds. According to Luigi’s post, the CCS wallet was set up in 2020 on an Ubuntu system along with a Monero node.
To make payments to community members, Luigi used an online wallet that had been on a Windows 10 Pro desktop since 2017. If necessary, the online wallet was funded by the CCS wallet. However, on September 1st, the CCS wallet was emptied in nine transactions. The Monero core team is asking the General Fund to cover its current liabilities.
“It is entirely possible that this is related to the ongoing attacks we have seen since April, as they involve a variety of compromised keys (including Bitcoin.dats wallets, seeds generated using all types of hardware and software, Ethereum presales wallets etc.). ) and include XMR that has been drained,” Spagni noted in the thread.
According to other developers, the breach could be due to the wallet keys being available online on the Ubuntu server.
“I wouldn’t be surprised if Luigi’s Windows machine was already part of an undetected botnet and its operators were carrying out this attack via SSH session details on that machine (stealing the SSH key or using the Trojan’s remote control feature while the victim has nothing to do with it knew). “Compromised developer Windows machines that result in serious corporate breaches are not uncommon,” noted pseudonymous developer Marcovelon.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers