Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,152,492 members, 7,816,163 topics. Date: Friday, 03 May 2024 at 06:56 AM

Investigator Says Malware On Official Monero Website Can Steal Crypto - Nairaland / General - Nairaland

Nairaland Forum / Nairaland / General / Investigator Says Malware On Official Monero Website Can Steal Crypto (160 Views)

Riccardo Spagni, Monero Maintainer Steps Down - Details / Bitbay Discontinues Support For Monero Following Regulatory Concerns / Confused Monkey Tries To Steal A Burger Through A Car Windscreen In South Africa (2) (3) (4)

(1) (Reply)

Investigator Says Malware On Official Monero Website Can Steal Crypto by Testboo: 4:43pm On Nov 19, 2019
@TestBoo.com



According to a post on November 19th on Reddit, published by the coin’s core development team the software available for download on Monero’s (XMR) official website was made in a way to steal cryptocurrency,

In the announcement, the team said the hash of the binaries available for download did not match the expected hashes. The command-line interface (CLI) tools available at getmonero.org may have been compromised over the past 24 hours.

On GitHub, a professional investigator going by the name of Serhack said that the software distributed after the server was compromised is malicious. He said:

“I can confirm that the malicious binary is stealing coins. Roughly 9 hours after I ran the binary a single transaction drained the wallet. I downloaded the build yesterday around 6pm Pacific time.”

Hashes are non-reversible mathematical functions which are used to generate an alphanumeric string from a file that would have been different if anybody was to make changes to the file.

It is a practice in the open-source community to save the hash generated from software available for download and keep it on a separate server.

If the hash generated from the downloaded file is different, then there is a high possibility that the version distributed by the server has been replaced. The Reddit announcement reads:

“It appears the box has been indeed compromised and different CLI binaries served for 35 minutes. Downloads are now served from a safe fallback source. [...] If you downloaded binaries in the last 24h, and did not check the integrity of the files, do it immediately. If the hashes do not match, do NOT run what you downloaded.”

From - TestBoo.Com - https://testboo.com/malware-monero-website-steal-crypto/

(1) (Reply)

Twitter Privacy Settings You Need To Change Immediately / School Feeding Programme My Top Priority – Minister / Hmm Sulaim's Thoughts | My Students

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 11
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.