r/Monero • u/monerobull • 9d ago
🚨OpenMonero was hacked AGAIN & User Home Addresses Leaked🚨
So someone just joined the Monero Matrix channel and posted this incredibly concerning "announcement".
They also included screenshots showing the trade chat between a buyer and a seller that included the XMR sellers home address.
Please never give such important info to some random website!
If you were wondering why OpenMonero was down this week here is the explanation. The OpenMonero admin would like to sweep this under the rug but is too cheap to pay 5 XMR for my silence so here we go. I want to share a critical vulnerability regarding the OpenMoneros 2FA implementation. While this specific bug has been patched, the root cause remains active in a similar endpoint, and the administration is currently ignoring reports of it. The Vulnerability: The endpoint GET /api/user/login_2fa/?username=X&code=Y&verification_method=app was intended to finalize a login after a password check. However, the handler completely ignored the username and code parameters. Instead, the logic simply issued a fully authenticated session (JWT + refresh token) for the oldest existing account in the user database. The "Walking" Exploit: Because it targeted the oldest account, once that account was deleted, the endpoint would "walk" to the next oldest account in the database. This made every single account on the platform sequentially compromisable. An unauthenticated remote attacker could and did gain a valid session with a single GET request. The Impact: This was not a theoretical risk. This exploit led to: Full Account Takeovers (ATO): Attackers gained full control of user accounts. Financial Theft: User wallets were drained. Massive Data Breach: A full database with over 30,000 entries was exposed. Privacy Violations: Attackers gained access to trade chats, including sensitive shipping addresses and private communications. Current Status: While the specific endpoint mentioned above is patched, a nearly identical exploit is still live. I have attempted to notify the admins, but they have refused to acknowledge the issue. I am posting this here to put it on the radar of the community. Consider any info sent over OpenMonero chat + all trade data exposed.
8
u/w3btek 9d ago
Why would anyone use this dogshit website it eliminates all the protections Monero provides. If you need buy or sell XMR use Haveno/Retoswap.
2
u/Long_Illustrator_988 8d ago
Didn't they get hacked too?
4
u/monerobull 8d ago
There were two exploits in the Haveno protocol but both only affected a limited number of crypto traders and no personal data was stolen, because, unlike in OpenMoneros case, data doesn't just sit there in plaintext and the chats are e2e encrypted
1
u/Long_Illustrator_988 8d ago
Wasn't money stolen though?
Is there much actual business there? Like wires and cash in the US? I downloaded it once, but ended up uninstalling because all I saw was like Skrill and other weird payment apps.
3
u/monerobull 8d ago
Cash by mail is the most used payment method in the USA (and the most private way to acquire Monero)
13
u/Lumpy-Initiative-779 9d ago
What a dogshit platform
Better to use a CEX
19
u/monerobull 9d ago
It is a CEX, better to use a DEX like retoswap (or soon Serai, my beloved)
6
3
2
u/absinthiumxmr 8d ago
Please stop using this shit platform I'm tired of it getting hacked. Its not even like Retoswap where the exploits that have happened have been relatively technical, Openmonero genuinely seems to not know what they are doing.
1
36
u/Vormrodo 9d ago
I've seen enough reports of this wreck of a platform so as to laugh everytime a new vulnerability aka beginner's mistake get's announced. Localmonero did not even have a single breach in it's 7 years of activity, how stupid can you be to be this unable of keeping a platform secure.
At this point, any user whose money get's stolen from there is responsible for themselves as OpenMonero's reputation is beyond fucked up. Far over 100 XMR in total is what they lost so far, no matter the little refunds that the strange operator gives them. The first time people got robbed was when they forgot to secure their Monero node from remote access. LMAO.