Jump to content

Monero Website Hacked Delivering Malware

via: https://arstechnica.com/information-technology/2019/11/official-monero-website-is-hacked-to-deliver-currency-stealing-malware/

The official website for the digital currency Monero was hacked and modified to deliver a malware disguised as crypto wallets with the purpose of stealing user's' currency.

Quote

The supply-chain attack came to light on Monday when a site user reported that the cryptographic hash for a command-line interface wallet downloaded from the site didn't match the hash listed on the page. Over the next several hours, users discovered that the mismatching hash wasn't the result of an error. Instead, it was an attack designed to infect GetMonero users with malware. Site officials later confirmed that finding.

"It's strongly recommended to anyone who downloaded the CLI wallet from this website between Monday 18th 2:30 AM UTC and 4:30 PM UTC, to check the hashes of their binaries," GetMonero officials wrote. "If they don't match the official ones, delete the files and download them again. Do not run the compromised binaries for any reason."

 

Researchers found that there had been changes made to the Linux binary was a script that ran when open which sent your wallet seed to a server. The Windows CLI wallet functioned similarly. At the time of publication of this topic and article from which this was sourced, one reddit user has claimed to have lost his/her coins due to the installation of the Linux binary.

Quote

"Roughly 9 hours after I ran the binary a single transaction drained my wallet of all $7000," the person wrote. "I downloaded the build yesterday around 6pm Pacific time."

GetMonero's advisory has yet to claim the any vulnerabilities in the website and if the site had been fixed. There is a download link of the Linux binary meant for developers and researchers to analyze and comprehend the code.

Link to comment
Share on other sites

Link to post
Share on other sites

I heard some people talking on the radio today about their coins going missing.  I wonder if this is the same thing. 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, mr moose said:

I heard some people talking on the radio today about their coins going missing.  I wonder if this is the same thing. 

Might be. Personally i heard this news a couple of hours ago and I just wanted to see the community's perspective on this and inform y'all

 

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, mr moose said:

I heard some people talking on the radio today about their coins going missing.  I wonder if this is the same thing. 

Pretty sure it is: Official Monero website is hacked to deliver currency-stealing malware

 

edit: Argh, I'm stupid :P Yeah, I mean the malware steals coins, so coins going missing would be expected?

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, jagdtigger said:

Meh, its fake money anyway so nothing is lost.... :dry:

One of the radio presenters I refereed to earlier asked if you forget you password can you just email the company and get it reset?  I'm screaming at the radio, "NO YOU TWAT, the whole point of crypto is no one is on control therefore when something goes wrong it's tuff titties, there is no one to fix it or take the blame".

 

Grrrrr.  

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, jagdtigger said:

Meh, its fake money anyway so nothing is lost.... :dry:

Cryptocurrency is like the opposite of monopoly money. It's equally useless but people decide to spend real money on something that's more volatile than the stock market.

For reference: $20580 in monopoly money is $20 USD. Meanwhile 1 XMR (monero) is $50-- no wait now it's $60 -- no, $55, no $40, no $10 OMG I'M RUINED AAAA, no wait nvm now it's $80 HAHA I'M RICH

 

Who seriously uses cryptocurrency, is what I want to know. Outside some very niche uses literally the only thing that comes to mind is money laundering.

Link to comment
Share on other sites

Link to post
Share on other sites

11 hours ago, mr moose said:

One of the radio presenters I refereed to earlier asked if you forget you password can you just email the company and get it reset?  I'm screaming at the radio, "NO YOU TWAT, the whole point of crypto is no one is on control therefore when something goes wrong it's tuff titties, there is no one to fix it or take the blame".

 

Grrrrr.  

I am optimistic about crypto but due to its high volatility and just how complex the whole process is compared just buying stocks of a public company I wouldn't recommend crypto to basically anyone as of right now. Let's see what the future holds for it though.

Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, haris7saud said:

 

The official website for the digital currency Monero was hacked and modified to deliver a malware disguised as crypto wallets with the purpose of stealing user's' currency.

 

 

What a cluster****.

 

So you can't trust the official site, for a currency which has no practical use and primarily used to facilitate crime? OK, why am I not surprised in the slightest.

 

Only two people play with Cryptocurrencies: Pump-and-Dump speculators, and criminals. No legitimate business deals in cryptocurrency without someone willing to take the losses for when the inevitable loss in value or coin theft happens.

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, HarryNyquist said:

Who seriously uses cryptocurrency, is what I want to know. Outside some very niche uses literally the only thing that comes to mind is money laundering.

 

There are some uses, but it's very edge case, basically if there was enough liquidity, where speculators couldn't spike the currency at all, it would make for a very simple currency conversion medium without having to have 10's of 1000's of dollars in a Forex account, or having your bank/credit card take very large comissions. However as store of value, there is no underlying value. It's true value is terribly negative, as energy was burned to "mine" a coin, and that coin can not be transferred back into energy. The last I heard it costs $30,000 in energy (depending on the part of the world) to mine coins.

 

It's extremely wasteful to mine the coins and generates more GHG the dirtier the power source is.

Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, haris7saud said:

with the purpose of stealing user's' currency.

If only it had also been a monero miner.

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, HarryNyquist said:

 

Who seriously uses cryptocurrency, is what I want to know. 

Me

 

Buy, trade, sell.  Rinse, repeat.

 

32 minutes ago, Kisai said:

 

It's extremely wasteful to mine the coins and generates more GHG the dirtier the power source is.

Depends what you identify as wasteful.  Most people don't understand the entire BTC enough to understand why it is very much still being mined today for profit.

 

It comes down to this:

When you have influence over a particular market where real money is exchanged and can manipulate crypto value through reduced profits in USD - it all is very much worth it, and while this is an opinion statement - Im actually living this "opinion".

 

 

Workstation Laptop: Dell Precision 7540, Xeon E-2276M, 32gb DDR4, Quadro T2000 GPU, 4k display

Wifes Rig: ASRock B550m Riptide, Ryzen 5 5600X, Sapphire Nitro+ RX 6700 XT, 16gb (2x8) 3600mhz V-Color Skywalker RAM, ARESGAME AGS 850w PSU, 1tb WD Black SN750, 500gb Crucial m.2, DIYPC MA01-G case

My Rig: ASRock B450m Pro4, Ryzen 5 3600, ARESGAME River 5 CPU cooler, EVGA RTX 2060 KO, 16gb (2x8) 3600mhz TeamGroup T-Force RAM, ARESGAME AGV750w PSU, 1tb WD Black SN750 NVMe Win 10 boot drive, 3tb Hitachi 7200 RPM HDD, Fractal Design Focus G Mini custom painted.  

NVIDIA GeForce RTX 2060 video card benchmark result - AMD Ryzen 5 3600,ASRock B450M Pro4 (3dmark.com)

Daughter 1 Rig: ASrock B450 Pro4, Ryzen 7 1700 @ 4.2ghz all core 1.4vCore, AMD R9 Fury X w/ Swiftech KOMODO waterblock, Custom Loop 2x240mm + 1x120mm radiators in push/pull 16gb (2x8) Patriot Viper CL14 2666mhz RAM, Corsair HX850 PSU, 250gb Samsun 960 EVO NVMe Win 10 boot drive, 500gb Samsung 840 EVO SSD, 512GB TeamGroup MP30 M.2 SATA III SSD, SuperTalent 512gb SATA III SSD, CoolerMaster HAF XM Case. 

https://www.3dmark.com/3dm/37004594?

Daughter 2 Rig: ASUS B350-PRIME ATX, Ryzen 7 1700, Sapphire Nitro+ R9 Fury Tri-X, 16gb (2x8) 3200mhz V-Color Skywalker, ANTEC Earthwatts 750w PSU, MasterLiquid Lite 120 AIO cooler in Push/Pull config as rear exhaust, 250gb Samsung 850 Evo SSD, Patriot Burst 240gb SSD, Cougar MX330-X Case

 

Link to comment
Share on other sites

Link to post
Share on other sites

On 11/21/2019 at 7:02 AM, haris7saud said:

I am optimistic about crypto but due to its high volatility and just how complex the whole process is compared just buying stocks of a public company I wouldn't recommend crypto to basically anyone as of right now. Let's see what the future holds for it though.

At best Crypto currency is just going to be a currency like any other,  except no bank holding your wallet for you.  It will still be subject to all the same forces of economics.  At worst it'll die in a fire as a clever way for a few people to get rich in what is effectively an electronic pyramid scheme disguised as a rebellion against the system.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×