• bitcoinBitcoin (BTC) $ 61,389.00
  • ethereumEthereum (ETH) $ 2,984.02
  • tetherTether (USDT) $ 0.999444
  • bnbBNB (BNB) $ 600.16
  • solanaSolana (SOL) $ 143.72
  • usd-coinUSDC (USDC) $ 0.999966
  • xrpXRP (XRP) $ 0.518903
  • staked-etherLido Staked Ether (STETH) $ 2,983.78
  • dogecoinDogecoin (DOGE) $ 0.146052
  • the-open-networkToncoin (TON) $ 6.05
  • cardanoCardano (ADA) $ 0.454297
  • shiba-inuShiba Inu (SHIB) $ 0.000023
  • avalanche-2Avalanche (AVAX) $ 34.32
  • tronTRON (TRX) $ 0.124660
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 61,383.00
  • polkadotPolkadot (DOT) $ 6.91
  • bitcoin-cashBitcoin Cash (BCH) $ 448.73
  • chainlinkChainlink (LINK) $ 14.16
  • nearNEAR Protocol (NEAR) $ 7.14
  • matic-networkPolygon (MATIC) $ 0.683331
  • litecoinLitecoin (LTC) $ 81.82
  • internet-computerInternet Computer (ICP) $ 11.95
  • fetch-aiFetch.ai (FET) $ 2.20
  • uniswapUniswap (UNI) $ 7.31
  • daiDai (DAI) $ 1.00
  • leo-tokenLEO Token (LEO) $ 5.78
  • render-tokenRender (RNDR) $ 10.51
  • ethereum-classicEthereum Classic (ETC) $ 27.19
  • hedera-hashgraphHedera (HBAR) $ 0.108590
  • first-digital-usdFirst Digital USD (FDUSD) $ 1.00
  • aptosAptos (APT) $ 8.59
  • cosmosCosmos Hub (ATOM) $ 9.08
  • pepePepe (PEPE) $ 0.000008
  • crypto-com-chainCronos (CRO) $ 0.124629
  • mantleMantle (MNT) $ 1.02
  • filecoinFilecoin (FIL) $ 5.76
  • wrapped-eethWrapped eETH (WEETH) $ 3,095.00
  • stellarStellar (XLM) $ 0.106958
  • okbOKB (OKB) $ 50.31
  • blockstackStacks (STX) $ 2.06
  • immutable-xImmutable (IMX) $ 2.05
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,929.47
  • dogwifcoindogwifhat (WIF) $ 2.88
  • kaspaKaspa (KAS) $ 0.121586
  • arbitrumArbitrum (ARB) $ 1.02
  • optimismOptimism (OP) $ 2.58
  • bittensorBittensor (TAO) $ 398.08
  • arweaveArweave (AR) $ 39.71
  • vechainVeChain (VET) $ 0.035071
  • the-graphThe Graph (GRT) $ 0.268797
  • makerMaker (MKR) $ 2,689.72
  • moneroMonero (XMR) $ 131.36
  • suiSui (SUI) $ 0.996894
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • theta-tokenTheta Network (THETA) $ 2.14
  • injective-protocolInjective (INJ) $ 23.40
  • thorchainTHORChain (RUNE) $ 6.07
  • fantomFantom (FTM) $ 0.666303
  • celestiaCelestia (TIA) $ 9.50
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,297.17
  • flokiFLOKI (FLOKI) $ 0.000173
  • lido-daoLido DAO (LDO) $ 1.87
  • bonkBonk (BONK) $ 0.000024
  • bitget-tokenBitget Token (BGB) $ 1.10
  • algorandAlgorand (ALGO) $ 0.187871
  • galaGALA (GALA) $ 0.043279
  • coredaoorgCore (CORE) $ 1.70
  • sei-networkSei (SEI) $ 0.523835
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,070.54
  • whitebitWhiteBIT Coin (WBT) $ 9.94
  • jupiter-exchange-solanaJupiter (JUP) $ 1.05
  • quant-networkQuant (QNT) $ 96.76
  • flowFlow (FLOW) $ 0.878814
  • aaveAave (AAVE) $ 86.28
  • beam-2Beam (BEAM) $ 0.023943
  • ethenaEthena (ENA) $ 0.870679
  • bitcoin-svBitcoin SV (BSV) $ 62.36
  • dydx-chaindYdX (DYDX) $ 2.11
  • singularitynetSingularityNET (AGIX) $ 0.913841
  • bittorrentBitTorrent (BTT) $ 0.000001
  • worldcoin-wldWorldcoin (WLD) $ 5.52
  • ondo-financeOndo (ONDO) $ 0.783100
  • akash-networkAkash Network (AKT) $ 4.73
  • chilizChiliz (CHZ) $ 0.123988
  • wormholeWormhole (W) $ 0.610342
  • flare-networksFlare (FLR) $ 0.028098
  • ribbon-financeRibbon Finance (RBN) $ 1.12
  • elrond-erd-2MultiversX (EGLD) $ 40.03
  • neoNEO (NEO) $ 15.22
  • gatechain-tokenGate (GT) $ 8.09
  • axie-infinityAxie Infinity (AXS) $ 7.21
  • zebec-protocolZebec Protocol (ZBC) $ 0.020215
  • kucoin-sharesKuCoin (KCS) $ 10.39
  • the-sandboxThe Sandbox (SAND) $ 0.430721
  • tokenize-xchangeTokenize Xchange (TKX) $ 11.66
  • ecasheCash (XEC) $ 0.000047
  • eosEOS (EOS) $ 0.800873
  • starknetStarknet (STRK) $ 1.25
  • aioz-networkAIOZ Network (AIOZ) $ 0.825555
  • tezosTezos (XTZ) $ 0.919825
  • cheeleeCheelee (CHEEL) $ 15.85
  • jasmycoinJasmyCoin (JASMY) $ 0.018346
  • mina-protocolMina Protocol (MINA) $ 0.802823
  • msolMarinade Staked SOL (MSOL) $ 170.22
  • roninRonin (RON) $ 2.72
  • conflux-tokenConflux (CFX) $ 0.212283
  • havvenSynthetix Network (SNX) $ 2.55
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,002.17
  • ordinalsORDI (ORDI) $ 37.81
  • decentralandDecentraland (MANA) $ 0.422517
  • gnosisGnosis (GNO) $ 303.60
  • apecoinApeCoin (APE) $ 1.23
  • nervos-networkNervos Network (CKB) $ 0.017202
  • heliumHelium (HNT) $ 4.54
  • dexeDeXe (DEXE) $ 13.08
  • usddUSDD (USDD) $ 0.999976
  • book-of-memeBOOK OF MEME (BOME) $ 0.010587
  • safeSafe (SAFE) $ 1.71
  • axelarAxelar (AXL) $ 1.11
  • pyth-networkPyth Network (PYTH) $ 0.476419
  • theta-fuelTheta Fuel (TFUEL) $ 0.109006
  • iotaIOTA (IOTA) $ 0.219068
  • kavaKava (KAVA) $ 0.657477
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 2,973.90
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.69
  • nexoNEXO (NEXO) $ 1.24
  • lido-staked-solLido Staked SOL (STSOL) $ 169.62
  • fraxFrax (FRAX) $ 0.998431
  • klay-tokenKlaytn (KLAY) $ 0.172602
  • swethSwell Ethereum (SWETH) $ 3,137.27
  • fasttokenFasttoken (FTN) $ 1.95
  • echelon-primeEchelon Prime (PRIME) $ 15.47
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000104
  • blurBlur (BLUR) $ 0.376435
  • frax-etherFrax Ether (FRXETH) $ 2,970.76
  • ocean-protocolOcean Protocol (OCEAN) $ 0.921414
  • oasis-networkOasis Network (ROSE) $ 0.088438
  • mantra-daoMANTRA (OM) $ 0.722392
  • bitcoin-goldBitcoin Gold (BTG) $ 33.49
  • tether-goldTether Gold (XAUT) $ 2,312.62
  • dydxdYdX (ETHDYDX) $ 2.11
  • osmosisOsmosis (OSMO) $ 0.857820
  • illuviumIlluvium (ILV) $ 87.62
  • golemGolem (GLM) $ 0.560036
  • wemix-tokenWEMIX (WEMIX) $ 1.54
  • sats-ordinalsSATS (Ordinals) (SATS) $ 0.00000026
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,189.36
  • arkhamArkham (ARKM) $ 2.53
  • woo-networkWOO (WOO) $ 0.287882
  • curve-dao-tokenCurve DAO (CRV) $ 0.439533
  • astarAstar (ASTR) $ 0.092992
  • xdce-crowd-saleXDC Network (XDC) $ 0.036938
  • true-usdTrueUSD (TUSD) $ 0.999163
  • venomVenom (VENOM) $ 0.302878
  • livepeerLivepeer (LPT) $ 15.51
  • dymensionDymension (DYM) $ 2.97
  • mx-tokenMX (MX) $ 4.96
  • apenftAPENFT (NFT) $ 0.00000048
  • jito-governance-tokenJito (JTO) $ 3.87
  • staked-frax-etherStaked Frax Ether (SFRXETH) $ 3,229.83
  • aerodrome-financeAerodrome Finance (AERO) $ 1.05
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.12
  • altlayerAltLayer (ALT) $ 0.337073
  • iotexIoTeX (IOTX) $ 0.047589
  • ankrAnkr Network (ANKR) $ 0.044701
  • pendlePendle (PENDLE) $ 4.60
  • ethereum-name-serviceEthereum Name Service (ENS) $ 14.17
  • corgiaiCorgiAI (CORGIAI) $ 0.001278
  • radixRadix (XRD) $ 0.042004
  • stepnGMT (GMT) $ 0.216196
  • raydiumRaydium (RAY) $ 1.65
  • memecoin-2Memecoin (MEME) $ 0.024844
  • zilliqaZilliqa (ZIL) $ 0.023506
  • popcatPopcat (POPCAT) $ 0.438131
  • celoCelo (CELO) $ 0.801891
  • superfarmSuperVerse (SUPER) $ 0.948373
  • pax-goldPAX Gold (PAXG) $ 2,311.41
  • ether-fiEther.fi (ETHFI) $ 3.69
  • terra-luna-2Terra (LUNA) $ 0.613567
  • 1inch1inch (1INCH) $ 0.365058
  • manta-networkManta Network (MANTA) $ 1.66
  • ravencoinRavencoin (RVN) $ 0.030036
  • amp-tokenAmp (AMP) $ 0.007310
  • enjincoinEnjin Coin (ENJ) $ 0.281038
  • holotokenHolo (HOT) $ 0.002303
  • rocket-poolRocket Pool (RPL) $ 20.07
  • 0x0x Protocol (ZRX) $ 0.477595
  • siacoinSiacoin (SC) $ 0.007019
  • polymeshPolymesh (POLYX) $ 0.374150
  • project-galaxyGalxe (GAL) $ 3.40
  • celsius-degree-tokenCelsius Network (CEL) $ 0.919577
  • aelfaelf (ELF) $ 0.537128
  • compound-governance-tokenCompound (COMP) $ 56.73
  • stader-ethxStader ETHx (ETHX) $ 3,068.89
  • ethereum-pow-iouEthereumPoW (ETHW) $ 3.48
  • qtumQtum (QTUM) $ 3.53
  • skaleSKALE (SKL) $ 0.070769
  • compound-wrapped-btccWBTC (CWBTC) $ 1,232.88
  • safepalSafePal (SFP) $ 0.789764
  • zetachainZetaChain (ZETA) $ 1.53

Monerujo Wallet User Drains Monero’s CCS Wallet: Report

0 117

Monerujo Wallet User Drains Monero’s CCS Wallet: Report

  coinedition.com 32 m

Monerujo Wallet User Drains Monero’s CCS Wallet: Report

  • Monero’s Community Crowdfunding System (CCS) wallet was exploited and drained on September 1.
  • Till September 1, the wallet held a total balance of 2,675.73 XMR, worth $460,000.
  • Moonstone Research identified that the exploitation was done by a Monerujo wallet user with the PocketChange feature.

In a sudden turn of events, the decentralized community-driven project Monero revealed its Community Crowdfunding System’s (CCS) wallet exploitation that occurred on September 1, 2023. As per reports, the attacker drained the wallet in nine transactions, accumulating its entire balance accounting for 2,675.73 XMR, worth $460,000.

Chinese crypto reporter Colin Wu took to his official X page, Wu Blockchain, to share insights on Monero’s CCS hack, the source of which remains a mystery. The reporter also reflected on the blockchain security firm SlowMist’s assumption that the vulnerability is a “loophole in the Monero privacy model.”

The Monero team announced that the community crowdfunding system CCS Wallet was attacked on September 1, 2023, and the entire balance of 2,675.73 XMR (approximately $384,000) was stolen. So far, the source of the vulnerability cannot be determined. SlowMist believes that it…

— Wu Blockchain (@WuBlockchain) November 5, 2023

As per Monero’s revelations, until September 1, the CCS, a system funded by donations, held a total balance of 2675.73 XMR. In November, Monero developer Luigi identified that the wallet holdings had been completely stolen.

Moonstone Research traced the attacker’s transactions and concluded with the supposition that the exploiter was a Monerujo wallet user who had the PocketChange feature enabled. Monerujo is an Android non-custodial Monero wallet, offering PocketChange feature that mitigates a disadvantage of Monero by creating multiple “pockets” or “enotes”. The report further explained the notion, reflecting on Monerujo’s statement, which read,

As long as [PocketChange is] enabled, every time you use Monerujo to send moneros somewhere, it will take a bigger coin, split it in parts, and spread those smaller coins into 10 different pockets. That way, the coins won’t merge again, and you’ll be ready to spend instantly from all those pockets without waiting the dreadful 20 minutes.

With four Crescent Discovery Reports, Moonstone Research identified that the attacker had created 11 output enotes, which is unlikely for usual transactions. Reiterating their assumptions, Moonstone Research stated, “We believe this is the most likely case, regardless if the attacker was using Monerujo version 3.3.7 or 3.3.8.”

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source

Leave A Reply

Your email address will not be published.