Lounge Started May 20, 2026 1:14 PM

Retoswap Exploit [do not use until patched]

5 replies - 96 views - 1 thanks - 0 tippers - 4 watchers

May 20, 2026 1:14 PM Last edited May 20, 2026 1:16 PM
#1

It looks like retoswap is under attack and the lead dev recommends not using the protocol until it is fixed. u/plowsof has a good writeup on reddit: https://www.reddit.com/r/Monero/comments/1tijw6z/psa_haveno_tradeprotocol_exploit/

A live instance of the Haveno software (RetoSwap) is effected. Details of the exploit from Haveno dev woodser are as follows: "when the attacker took a trade, they sent a fake, out-of-order ACK message impersonating the arbitrator, causing the software to update the arbitrator's node address to their own, allowing them to create a compromised multisig wallet before funds were deposited. preventing this is straight forward, by checking that the multisig wallet is already created before updating the arbitrator's address: https://github.com/haveno-dex/haveno/pull/2315".

1 thanks - 0 tippers - 4 watchers

Replies

Page 1 of 1 - 5 total
May 20, 2026 1:17 PM
#2

cmon admin, archive everything!
the reddit post mentioned:

[PSA] Haveno TradeProtocol exploit

A live instance of the Haveno software (RetoSwap) is effected. Details of the exploit from Haveno dev woodser are as follows: "when the attacker took a trade, they sent a fake, out-of-order ACK message impersonating the arbitrator, causing the software to update the arbitrator's node address to their own, allowing them to create a compromised multisig wallet before funds were deposited. preventing this is straight forward, by checking that the multisig wallet is already created before updating the arbitrator's address: https://github.com/haveno-dex/haveno/pull/2315".

It's not yet clear exactly how much Monero has been stolen. Haveno network operators are strongly advised to halt trading which RetoSwap has done.

Signature

I'm an artist (skills in vtuber making and livestreaming) and always willing to chat about nearly anything. Don't hesitate to start a convo with me.

0 thanks - 0 tippers
May 20, 2026 5:09 PM
#4

Almost 7000 XMR ($2.7M) is now believed to have been stolen from RetoSwap users in the recent exploit 💔

0 thanks - 0 tippers
May 20, 2026 7:15 PM
#6

@quadriocellata fuck........................................

0 thanks - 0 tippers

Post A Reply

You must be logged in to reply. Login or register.