Lounge Started May 30, 2026 5:20 PM

$40 in Exolix Swaps Exposed via API Vulnerability

1 replies - 20 views - 1 thanks - 1 tippers - 2 watchers

May 30, 2026 5:20 PM
#1

https://www.rastersec.com/blog/exolix-swapper-dump

Exolix vulnerability contains tx history for different swap partners, exposing tens of thousands of XMR transactions.

From blog: "In every case, the JWT key is not scoped or restricted. It grants full read access to the partner’s entire transaction history, including deposit addresses, withdrawal addresses, amounts, timestamps, on-chain transaction hashes, and swap statuses. There is no rate limiting or IP restriction to speak of. Later on, Exolix staff implemented WAF rules using Cloudflare instead of solving the root problem"

1 thanks - 1 tippers - 2 watchers

Replies

Page 1 of 1 - 1 total
May 30, 2026 6:28 PM
#2

Whoever is doing the communication on the exolix side has quite the unique mind.

thanks for bringing up this vulnerability, but actually this vulnerability is a feature requested by our partners (the spooks)

I'm dumb, so can someone tell me what swaps or exchanges ARE NOT using exolix?

Signature

I'm an artist (skills in vtuber making and livestreaming) and always willing to chat about nearly anything. Don't hesitate to start a convo with me.

1 thanks - cipherchan - 0 tippers

Post A Reply

You must be logged in to reply. Login or register.