• Bitcoin(BTC)$63,849.00
  • Ethereum(ETH)$3,129.69
  • Tether(USDT)$1.00
  • BNB(BNB)$588.78
  • Solana(SOL)$146.47
  • USDC(USDC)$1.00
  • XRP(XRP)$0.53
  • Lido Staked Ether(STETH)$3,130.05
  • Dogecoin(DOGE)$0.158709
  • Toncoin(TON)$5.72

The software available for download on Monero’s (XMR) official website was compromised to steal cryptocurrency, according to a Nov. 19 Reddit post published by the coin’s core development team.

The command-line interface (CLI) tools available at getmonero.org may have been compromised over the last 24 hours. In the announcement, the team notes that the hash of the binaries available for download did not match the expected hashes.

The software was malicious

On GitHub, a professional investigator going by the name of Serhack said that the software distributed after the server was compromised is indeed malicious, stating:

“I can confirm that the malicious binary is stealing coins. Roughly 9 hours after I ran the binary a single transaction drained the wallet. I downloaded the build yesterday around 6pm Pacific time.”

An important security practice

Hashes are non-reversible mathematical functions which, in this case, are used to generate an alphanumeric string from a file that would have been different if someone was to make changes to the file.

It is a popular practice in the open-source community to save the hash generated from software available for download and keep it on a separate server. Thanks to this measure, users are able to generate a hash from the file they downloaded and check it against the expected one.

If the hash generated from the downloaded file is different, then it is likely that the version distributed by the server has been replaced — possibly with a malicious variant. The Reddit announcement reads:

“It appears the box has been indeed compromised and different CLI binaries served for 35 minutes. Downloads are now served from a safe fallback source. […] If you downloaded binaries in the last 24h, and did not check the integrity of the files, do it immediately. If the hashes do not match, do NOT run what you downloaded.”

In general, blockchain development communities are vigilant in tracking possible vulnerabilities and maintaining network integrity.

In mid-September, the developer of Ethereum decentralized exchange protocol AirSwap’s developers announced a different important development for their project’s security. More precisely, they revealed the discovery of a critical vulnerability in the system’s new smart contract.

In order to incentivize network integrity, some organizations have founded bounty programs that reward so-called white-hack hackers for exposing vulnerabilities.

Source: Cointelegraph.com

Crypto Investing Risk Warning

Crypto assets are highly volatile. Your capital is at risk.
Don’t invest unless you’re prepared to lose all the money you invest.
This is a high-risk investment, and you should not expect to be protected if something goes wrong.

Read the full disclaimer

Newsletter

Sign up to receive the latest crypto breaking news in your inbox, every day.

I agree that my data is used according to the privacy policy

Check your inbox or spam folder to confirm your subscription.

Breaking crypto news about Bitcoin, Ethereum, Blockchain, NFTs, DeFi and Altcoins. Get instant notifications 24/7 as soon as a new article is published.

Exit mobile version