Monero Discloses Bug Allowing XMR to Be Stolen From Exchanges

Published at: July 5, 2019

Several security vulnerabilities have been disclosed by Monero, including one that could have been exploited to steal xmr from exchanges, reports on the breach disclosure platform HackerOne revealed on July 3.

The vulnerability theoretically enabled attackers to send counterfeit xmr to an exchange. Once the fraudster’s account was credited, they could then convert it into other coins and make a withdrawal, leaving the exchange out of pocket.

Describing the critical breach they uncovered, the lead developer for CUT coin added:

“It is our belief that the vulnerability cannot be used to "mint" real, transactable monero out of thin air.”

A bounty of 45 xmr (about $4,000) was paid to the developer for their efforts.

Most of the vulnerabilities recently disclosed to HackerOne were identified a few months ago, but they have since been resolved.

In April, monero developers fixed a bug concerning the Ledger hardware wallet that made it look like user funds had disappeared.

The privacy-focused altcoin is 14th in the rankings of the biggest cryptocurrencies by market capitalization according to CoinMarketCap.

Tags
Related Posts
Blockchain platform offers security and accountability that DeFi cannot
A fintech platform is taking on the decentralized finance craze with a focus on security, stability and accountability that DeFi platforms, by their very nature, cannot match. “Crypto has a reputation problem and we hope to fix that,” crypto exchange and lender YouHodler CEO Ilya Volkov said. “We want to be as safe and reputable as your local TradFi bank but with an innovative twist that lets users harness the power of blockchain-based financial services.” Call it TradFi with a fintech twist, as YouHodler offers crypto-collateral loans on 30 cryptocurrencies, an exchange with a fiat off-ramp, high-interest savings, and a …
Technology / July 27, 2021
BitMEX Observes Increase in Attacks on Accounts, Stresses Security Measures
This article has been updated to correct that BitMEX is not Hong Kong-based. Peer-to-peer (P2P) cryptocurrency exchange BitMEX has reported an influx of attacks on user account credentials, according to an official blog post on June 11. In addition to covering a litany of best practices for user security, the cryptocurrency exchange stressed the importance of using two-factor authentication (2FA) in particular. The report summarizes 2FA as follows: “2FA, sometimes referred to as ‘two-step verification’ or ‘multi-factor authentication’, adds an additional layer of security to your account by requiring not only your username and password at login, but also the …
United States / June 11, 2019
Ethereum Classic 51% Attackers Allegedly Returned $100,000 to Crypto Exchange
The Ethereum Classic 51 percent attacker has reportedly returned $100,000 to cryptocurrency exchange Gate.io, a post on the official exchange’s blog reports on Jan. 12. The company further noted that they tried contacting the attacker but didn’t get any reply until now, and that they do not know the reason why the funds have been returned. The exchange declared: “If the attacker didn't run it for profit, he might be a white hacker who wanted to remind people the risks in blockchain consensus and hashing power security.” A white hat hacker is a hacker with a strong professional ethic who …
Altcoin / Jan. 13, 2019
MEGA Chrome Extension Compromised to Steal Users’ Monero
The MEGA Chrome extension version 3.39.4 has been compromised and can now steal user’s Monero in addition to other sensitive information, according to recent posts on Twitter and Reddit. MEGA Chrome extension is a tool that claims to improve browser performance by reducing page loading times, in addition to providing a secure cloud storage service. The official Twitter account of Monero (XMR) posted a warning, advising XMR holders to steer clear of MEGA. PSA: The official MEGA extension has been compromised and now includes functionality to steal your Monero: https://t.co/vzWwcM9E5k — Monero || #xmr (@monero) September 4, 2018 Another user …
Altcoin / Sept. 5, 2018
Report: Crypto-Related Fraud and Theft Resulted in $4.4B Loss in 2019
In 2019, the total volume of cryptocurrency-related fraud and theft resulted in losses worth $4.4 billion, according to CipherTrace’s report for the third quarter of 2019. In its “Cryptocurrency Anti-Money Laundering Report, 2019 Q3,” security research firm CipherTrace delved into the 120 most popular cryptocurrency exchanges’ compliance with Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements and analyzed patterns in crypto-related crimes. Decline in crypto crime volume and weak KYC standards Per the report, Q3 2019 saw a notable reduction in total cryptocurrency crimes as compared with previous quarters, and thus the lowest quarterly thefts and scams in two …
Bitcoin / Nov. 27, 2019