BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Coin Stealer Found in Monero Linux Binaries From Official Site

The Monero Project is currently investigating a potential compromise of the official website after a coin stealer was found in the Linux 64-bit command line (CLI) Monero binaries downloaded from the download page.

- Advertisement -

“CLI binaries available on http://getmonero.org  may have been compromised at some point during the last 24h. Investigations ongoing,” the Monero team said on Twitter.

As reported and confirmed by multiple users on GitHubReddit and Twitter, the Monero website delivered potentially malicious binaries with not matching hashes a little over 30 minutes. At the moment all binaries are clean as they are currently delivered from a secure fallback hosting server.

Users are encouraged by moderators on the Monero subreddit to “check the integrity of the binaries and verify that they were signed by Fluffypony’s GPG key.”

Guides on how to check if the downloaded binaries have the corrected hashes are available for Windows here and for Linux and macOS here.

- Advertisement -

Although Windows and macOS files haven’t been reported to be compromised, users of all platforms should check the hashes for all downloaded Monero binaries since all of them could’ve been switched with malicious versions.

Correct hashes for all Monero binaries available for download on the official site are here: https://web.getmonero.org/downloads/hashes.txt.

If you downloaded binaries in the last 24h, and did not check the integrity of the files, do it immediately. If the hashes do not match, do NOT run what you downloaded. If you have already run them, transfer the funds out of all wallets that you opened with the (probably malicious) executables immediately, using a safe version of the Monero wallet (the one online as we speak is safe — but check the hashes). More information will be posted as several people are currently investigating to get to the bottom of this. – Monero Core Team

Malicious binaries drop a coin stealer

While a full analysis of the malicious Monero binaries that were distributed through the project’s official download platform is not yet available, security researcher and contributor to the Monero project SerHack says that he was able to find a coin stealer embedded within.

“I can confirm that the malicious binary is stealing coins. Roughly 9 hours after I ran the binary a single transaction drained the wallet,” moneromanz, one of the users who downloaded the compromised Monero binaries, confirmed. “I downloaded the build yesterday around 6pm Pacific time.”

“I have not completed any malware analysis as of yet, but I’d like to get to the bottom of whether the binary is limited to stealing xmr, or also tries to compromise the machine as a whole or any of its files,” he adds.

The malicious binaries downloaded from the official Monero website during the approximately 30 minutes window were also uploaded by moneromanz to an anonymous file hosting server and are available for analysis at https://anonfile[.]com/bbq8h9Bdn7/monero-wallet-cli.

H/T dark.fail

Source

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

MegaETH LPs Outraged Over Kumbaya’s Undisclosed 50% Fee Take

Kumbaya, the flagship DEX on MegaETH, reportedly took an undisclosed 50% of trading fees...

Crypto Market Splinters: From AI Pivot to ETH Losses

Analysts at Bernstein project IREN could pivot from Bitcoin mining to build a $3.7...

SaaS Hackers Launch “Silent” Extortion Campaigns

Two cybercrime groups, Cordial Spider and Snarky Spider, are conducting rapid, high-impact data theft...

Record Crypto Hacks in April Spotlight DeFi Weaknesses

April set a monthly record with 29 crypto hacks, according to DefiLlama data, marking...

Rayls Mainnet Opens Tokenized Real-World Yield Through Live Institutional Rails

For years, the most attractive yield and asset-backed opportunities in the Brazilian market have...

Must Read

Top 9 Most Legit Bitcoin Faucets

Bitcoin faucets are platforms where you can earn Bitcoin free. Some other faucet apps and websites allow users to receive different cryptocurrencies for free....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading