Hacking of the Monero cryptocurrency website with substitution of the wallet offered for downloading

Cryptocurrency developers Monero, which is positioned as providing complete anonymity and protection from payment tracking, warned users about compromises official website of the project (GetMonero.com). As a result of the hack on November 18, from 5:30 to 21:30 (MSK), executable files of the console edition of the Monero wallet for Linux, macOS and Windows, replaced by attackers, were distributed in the download section.

Was integrated into executable files malicious code for theft funds from wallets. When opening the wallet, the malicious code sent cryptographic keys to the external server node.hashmonero.com, allowing control of the funds in the wallet. Some time after the information is transmitted, the attackers translated own funds available in the victim’s wallet.

Currently, the applications are rebuilt from a separate secure code base. Details about the hacking technique have not been provided; the incident is still under investigation. All Monero users who have recently installed a wallet from the official website are advised to ensure that they are using the correct builds, checking checksums with data on GitHub and project site.

Source: opennet.ru

Add a comment