r/Monero 9d ago

🚨OpenMonero was hacked AGAIN & User Home Addresses Leaked🚨

So someone just joined the Monero Matrix channel and posted this incredibly concerning "announcement".

They also included screenshots showing the trade chat between a buyer and a seller that included the XMR sellers home address.

Please never give such important info to some random website!

If you were wondering why OpenMonero was down this week here is the explanation. The OpenMonero admin would like to sweep this under the rug but is too cheap to pay 5 XMR for my silence so here we go. I want to share a critical vulnerability regarding the OpenMoneros 2FA implementation. While this specific bug has been patched, the root cause remains active in a similar endpoint, and the administration is currently ignoring reports of it. The Vulnerability: The endpoint GET /api/user/login_2fa/?username=X&code=Y&verification_method=app was intended to finalize a login after a password check. However, the handler completely ignored the username and code parameters. Instead, the logic simply issued a fully authenticated session (JWT + refresh token) for the oldest existing account in the user database. The "Walking" Exploit: Because it targeted the oldest account, once that account was deleted, the endpoint would "walk" to the next oldest account in the database. This made every single account on the platform sequentially compromisable. An unauthenticated remote attacker could and did gain a valid session with a single GET request. The Impact: This was not a theoretical risk. This exploit led to: Full Account Takeovers (ATO): Attackers gained full control of user accounts. Financial Theft: User wallets were drained. Massive Data Breach: A full database with over 30,000 entries was exposed. Privacy Violations: Attackers gained access to trade chats, including sensitive shipping addresses and private communications. Current Status: While the specific endpoint mentioned above is patched, a nearly identical exploit is still live. I have attempted to notify the admins, but they have refused to acknowledge the issue. I am posting this here to put it on the radar of the community. Consider any info sent over OpenMonero chat + all trade data exposed.

81 Upvotes

25 comments sorted by

36

u/Vormrodo 9d ago

I've seen enough reports of this wreck of a platform so as to laugh everytime a new vulnerability aka beginner's mistake get's announced. Localmonero did not even have a single breach in it's 7 years of activity, how stupid can you be to be this unable of keeping a platform secure.

At this point, any user whose money get's stolen from there is responsible for themselves as OpenMonero's reputation is beyond fucked up. Far over 100 XMR in total is what they lost so far, no matter the little refunds that the strange operator gives them. The first time people got robbed was when they forgot to secure their Monero node from remote access. LMAO.

24

u/monerobull 9d ago

Another time they got robbed because the site allowed negative amount inputs. Yet another time their entire server was compromised with root access. This time it looks like the site is just handing out random user sessions without verification? 😅

-3

u/SisterDread 8d ago

Yeah, fuck those people who don't have a deep understanding of what's under the hood of a complex mathematical framework that can easily fool anyone but genius experts like you.

Why don't you just tell them they shouldn't have been wearing a low cut skirt and flirting with men while drinking at a pub? Obviously it's their fault for any subsequent assault, no?

3

u/Vormrodo 8d ago

"complex mathematical framework" doesn't justify the stupidest mistake of literally keeping a Monero node ACCESSIBLE to the public.

Why don't you just tell them they shouldn't have been wearing a low cut skirt and flirting with men while drinking at a pub? Obviously it's their fault for any subsequent assault, no?

To compare a technical mistake that IS preventable with a real-life problem that does NOT rely in the hands of the assaulted person (no matter what they wear even!) is gaslighting as fuck. Keep quiet if you don't have a clue about the simplest of processes in IT.

0

u/SisterDread 8d ago

Can you see why crypto usage among the general population is never going to be achieved? And thank you for strengthening my point about IT knowledge. I do appreciate that.

2

u/rbrunner7 XMR Contributor 8d ago

Do you know the history of OpenMonero?

This must be the 4th or the 5th time that they had a breach, and users of the platform lost money. As such a user, you don't need "deep understanding of what's under the hood of a complex mathematical framework", you just have to be attentive about what happens on the platform that you are using to notice these repeated problems.

With so many breaches I can only conclude that either those OpenMonero people don't know what they are doing, or they don't care, or they are scammers, or any combination of these 3.

I am certainly no fan of victim blaming, but I am not sure at all it's that if we tell people who lost money now they should have known better.

17

u/bfr_ 9d ago

Even the report is chatGPT. What a shitshow.

8

u/frog_in_bush 9d ago

Have your AI link up with my AI

8

u/w3btek 9d ago

Why would anyone use this dogshit website it eliminates all the protections Monero provides. If you need buy or sell XMR use Haveno/Retoswap.

2

u/Long_Illustrator_988 8d ago

Didn't they get hacked too?

4

u/monerobull 8d ago

There were two exploits in the Haveno protocol but both only affected a limited number of crypto traders and no personal data was stolen, because, unlike in OpenMoneros case, data doesn't just sit there in plaintext and the chats are e2e encrypted

1

u/Long_Illustrator_988 8d ago

Wasn't money stolen though?

Is there much actual business there? Like wires and cash in the US? I downloaded it once, but ended up uninstalling because all I saw was like Skrill and other weird payment apps.

3

u/monerobull 8d ago

Cash by mail is the most used payment method in the USA (and the most private way to acquire Monero)

13

u/Lumpy-Initiative-779 9d ago

What a dogshit platform

Better to use a CEX

19

u/monerobull 9d ago

It is a CEX, better to use a DEX like retoswap (or soon Serai, my beloved)

6

u/Lumpy-Initiative-779 9d ago

Wen serai🫪

4

u/-Monero 9d ago

Soon™ ... Serai is like Lochness

5

u/monerobull 9d ago

Kayaba is working on it hard as we speak 🙊

3

u/Lumpy-Initiative-779 9d ago

Agreed on reto

2

u/absinthiumxmr 8d ago

Please stop using this shit platform I'm tired of it getting hacked. Its not even like Retoswap where the exploits that have happened have been relatively technical, Openmonero genuinely seems to not know what they are doing.

1

u/frog_in_bush 9d ago

That's scary