Monero Project admits thieves stole 6-figure sum from a wallet in mystery breach
- Reference: 1699443969
- News link: https://www.theregister.co.uk/2023/11/08/monero_project_developers_announce_breach/
- Source link:
A Monero Project maintainer who goes by the alias of Luigi announced on November 2 that the project's community crowdfunding system (CCS) wallet was drained of 2,675.73 XMR on September 1.
The team behind Monero is trying to determine how the breach occurred but said it could be related to the ongoing [1]wallet-draining attacks the community has seen since April.
[2]
The funds were drained during nine separate transactions that took place in as many minutes.
[3]
[4]
None of the project's other wallets were affected, including the general fund, which is used to support the project's development and occasionally contributing to key community initiatives like conferences or research.
The project's maintainers have "taken additional precautions" to secure the other wallets associated with Monero, such as enabling multisig so more than one individual is required to sign off on any given transaction.
[5]
"It's also possible that the attacker isn't aware of what they've stolen, in which case I'd ask them to consider that they have stolen funds that are donated by individuals against specific things that Monero contributors are working on," [6]said another maintainer.
"This attack is unconscionable, as they've taken funds that a contributor might be relying on to pay their rent or buy food. I'd urge them to take action to make this right if they become aware of this."
Wider wallet-draining attacks
Atomic Wallet was attacked earlier this year in an incident that ultimately led to more than 5,000 cryptocurrency wallets mysteriously drained of their funds.
Those behind the attack have reportedly netted themselves at least $100 million, including ten victims losing $1 million or more. The average loss for each wallet was $2,800, according to [7]Elliptic .
The blockchain analytics provider [8]attributed the attack to the North Korean state-sponsored Lazarus Group, which it says has stolen more than $2 billion across several heists.
How are they getting in?
The question of how Lazarus is breaking into these wallets remains unanswered. In response to the attack, Atomic Wallet contacted victims to gather information about their setups in an attempt to determine the source of the breach, but has not yet publicized its findings.
In October, Atomic Wallet [9]revealed it was able to work with leading cryptocurrency exchanges to freeze $2 million in stolen funds related to the earlier incident. It hasn't published details of the ongoing investigation into the mass draining, which is being supported by blockchain forensic specialists Chainalysis and Crystal.
[10]
Tracking the wallet-draining attacks, Taylor Monahan, lead product manager/owner at cryptocurrency wallet software company MetaMask, [11]said the profile of victims "is the most striking thing" and they're all "reasonably secure" and reputable organizations.
There is a wide diversity of cryptocurrencies and blockchains that have been successfully targeted, including Bitcoin, Monero, and Ethereum, and wallets with seed lengths of 12 and 24 words have both been breached.
Monahan noted that most victims are high profile and large sums are being stolen in each wallet sweep, indicating that it may be a targeted operation.
[12]Cryptojackers steal AWS credentials from GitHub in 5 minutes
[13]Google puts $1M behind its promise to detect cryptomining malware
[14]Acer confirms server intrusion after miscreant offers 160GB cache of stolen files
[15]Monero-mining botnet targets Windows, Linux web servers
Responding to the community's discussions around the possibility that the [16]LastPass breach could have had a role in leaking the seeds to the raided wallets, she said she was "confident" that seeds were stolen from the password manager.
"The number of victims who only had the specific group of seeds/keys that were drained stored in LastPass is simply too much to ignore," Monahan [17]wrote .
"To this day LastPass has not provided useful indicators of compromise or any info that could lead to attribution (e.g. IPs, UAs).
"Additionally, most users who had their wallets drained had extremely secure LastPass passwords. It would be legitimately impossible to brute force them. Which means that either someone has compromised hundreds of users' vaults one by one via a still undetected method, or it means that LastPass has still not shared some critical details about their security posture and the stuff that was compromised by the attackers.
"I want to emphasize strongly that LastPass can and should be doing more here. They are a disgusting failure of a company."
The idea that LastPass's breach played a role in these attacks was supported by an independent blockchain investigator going by the alias ZachXBT.
More than 25 different victims had their wallets drained on October 25 alone, amounting to a total of $4.4 million stolen, according to their [18]account of the incident, which was "a result of the LastPass hack."
LastPass CEO Karim Toubba told The Register that there is no current evidence linking the company's breach to the ongoing wallet-draining attacks.
"The work being done by these researchers in uncovering the theft of cryptocurrency is important," he said. "Since initial assertions surfaced linking the 2022 LastPass security incidents to the theft of cryptocurrency, we have reached out to researchers to investigate these claims.
"To date we have no evidence that directly connects these events to LastPass. We urge any security researchers with evidence to reach out to the LastPass Threat Intelligence team by contacting securitydisclosure@lastpass.com."
Despite these wallet-draining attacks starting in April, the method used to carry them out is still yet to be established. ®
Get our [19]Tech Resources
[1] https://www.theregister.com/2023/06/08/lazarus_link_atomic_wallet/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZUu@tcqSZMnkI73TNnwmvgAAABA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUu@tcqSZMnkI73TNnwmvgAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUu@tcqSZMnkI73TNnwmvgAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUu@tcqSZMnkI73TNnwmvgAAABA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://github.com/monero-project/meta/issues/916
[7] https://hub.elliptic.co/analysis/north-korea-linked-atomic-wallet-heist-tops-100-million/
[8] https://www.theregister.com/2023/06/08/lazarus_link_atomic_wallet/
[9] https://atomicwallet.io/blog/articles/2m-of-suspicious-deposits-frozen-on-centralised-exchanges
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUu@tcqSZMnkI73TNnwmvgAAABA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://twitter.com/tayvano_/status/1696222660013998407
[12] https://www.theregister.com/2023/10/30/cryptojackers_steal_aws_credentials_github/
[13] https://www.theregister.com/2023/06/08/google_1m_cryptominer_guarantee/
[14] https://www.theregister.com/2023/03/08/acer_confirms_server_breach/
[15] https://www.theregister.com/2022/05/18/microsoft-cryptomining-sysrv-k/
[16] https://www.theregister.com/2022/12/23/lastpass_attack_update/
[17] https://twitter.com/tayvano_/status/1696222671699329271
[18] https://twitter.com/zachxbt/status/1717901088521687330
[19] https://whitepapers.theregister.com/
Re: Oh dear
When I was a kid stealing $437,000 would have normally needed a wheel barrow, I remember a local guy being robbed and had lost $125!!!
We're all so happy that today's world has made so many things easier, originally going out into the countryside to catch something to eat was a big effort with relatively little risk, but after the 13th century we created guns - is this a better world now?
I'm selecting the anonymous icon after watching V for Vendetta on November 5th, forecasting the future - I love that movie!
Re: Oh dear
originally going out into the countryside to catch something to eat was a big effort with relatively little risk, but after the 13th century we created guns - is this a better world now?
I take it that your unaware that the oldest preserved human body is approximately 5000 years old, and the chap died from being shot with an arrow when out in the countryside? This rather argues against the notion that the world was one of peace and civilisation prior to the invention of firearms. Not that anybody with any notion of history would assume it is, but...
Re: Oh dear
So it became a better world for gunsmiths, and a worse one for fletchers? For all the rest of us 'going out into the countryside to catch something to eat' only improved markedly in the mid to late 20th century with the invention of the out-of-town supermarket.
When I was a kid stealing $437,000 required time, patience and CISI certification. The last being notoriously difficult for North Korean financial planners to acquire
Sorry, but why aren't you moving that into an offline wallet on a regular basis?
I mean, at least every $100,000, even if there's a transaction charge. I'd be doing it every $10,000 or similar. Activate machine with offline wallet, send money to offline wallet, confirm transaction, turn off machine with offline wallet.
Same way that supermarket cashiers would put notes into a tub and send off to a safe rather than having it all on the shop floor for anyone to rob.
For rich people, and large companies dealing in money, they appear to be completely naive in how they handle other people's.
Also keep the password offline.
A few minor corrections to the article
Just a few small points, in regards to the article:
"they're all "reasonably secure" and reputable organizations"
This is Crypto - there is no such thing as secure or reputable, about anyone or anything involved in that business!
"Those behind the attack have reportedly netted themselves at least $100 million"
Unless there is evidence that they have actually managed to convert that into hard currency or actual commodities (like Beanie Babies or Tulips), then no they've netted themselves computer tokens that they hope to sell on to idiots for actual currency. If no one buys those tokens off them, then they have nothing but a collection of 1's and 0's which will not help feed the starving poor of North Korea, or more likely finance some Kim vanity project or nuclear missile program.
From my reading here and elsewhere, a considerable section of the Norks stolen tokens are sitting in identified wallets, unable to move as they've been effectively frozen or blacklisted. It doesnt help the poor sod who had the token in the first place, but it's not helping the Norks either..
Crypto - Just say No!
True cryptocurrency
Monero is a true crypto currency unlike things like Bitcoin.
The reason is that it is not possible to trace coin's transaction history from the chain itself (at least not to my knowledge) and that makes it fungible unlike BTC, where 1 BTC != 1 BTC (nobody wants to touch coins from blacklisted walled, therefore they are worth 0).
So it will be a test for Monero. If they recover the funds by any other mean than theft's good will, then Monero is toast.
Re: True cryptocurrency
Didn't the article state that they already froze some of the stolen funds with the help of some crypto exchanges? Looks like they aren't completely untraceable...
Re: True cryptocurrency
The linked article says the frozen funds were ETH through BTC.
they're all "reasonably secure" and reputable organizations.
Goes to prove that "reasonably secure" is not a sufficient level of security, especially when you entrust it to a 3rd party. As for reputable organizations - can't say I can think of one who would be trusting some combination of crypto wallet and password manager as part of their banking and bookkeeping operations.................
What it Bowser and his Koopa Troop
“ A Monero Project maintainer who goes by the alias of Luigi announced on November 2 that the project's community crowdfunding system (CCS) wallet was drained of 2,675.73 XMR on September 1.”
“ The New York Times recently equated the total power consumed by Bitcoin annually to what’s used by Finland in one year. The fact is that even the most efficient Bitcoin mining operation takes roughly [1]155,000 kWh to mine one Bitcoin ”
[1] https://www.toptal.com/finance/blockchain/what-is-bitcoin-mining
Oh dear
All is not well in digital tulip bulb land!