Cryptocurrency [loss] $460,895

CCS Wallet Incident

2023-11-01 [vendor] Monero community wallet [chain] monero
Primary Source ↗
Financial Loss $460,895 (460,895 USD)
Blockchain(s) Monero

Incident Details

Monero’s Community Crowdfunding System (CCS) funds projects that aim to improve the ecosystem of Monero, a privacycoin. The CCS is funded by donations, and up until September 1, 2023, held a balance of 2675.73 XMR (~$460,000). Two months after the fact, “Luigi” (a Monero developer and one of the two people with access to the wallet seed phrase) disclosed on Github that the wallet had been drained entirely. According to Luigi, he only discovered this a month after the theft.The other person with access to the wallet is a former Monero developer named “fluffypony”, or Ricardo Spagni. He surrendered to US authorities in July 2023 for extradition to South Africa, where he has been charged with invoice fraud against a cookie company (think chocolate chip, not software). However, he was released in late September, and has been working to “address this matter” while free but under court supervision.

Total loss estimated at $460,895.

Technical Details

Initial Attack Vector
Seed phrase / wallet compromise
Vendor / Product
Monero community wallet

Timeline

  1. 2023-11-01 Breach occurred
  2. 2023-11-01 Publicly disclosed