It looks like retoswap is under attack and the lead dev recommends not using the protocol until it is fixed. u/plowsof has a good writeup on reddit: https://www.reddit.com/r/Monero/comments/1tijw6z/psa_haveno_tradeprotocol_exploit/
A live instance of the Haveno software (RetoSwap) is effected. Details of the exploit from Haveno dev woodser are as follows: "when the attacker took a trade, they sent a fake, out-of-order ACK message impersonating the arbitrator, causing the software to update the arbitrator's node address to their own, allowing them to create a compromised multisig wallet before funds were deposited. preventing this is straight forward, by checking that the multisig wallet is already created before updating the arbitrator's address: https://github.com/haveno-dex/haveno/pull/2315".

