monero.town
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Rucknium to Monero · 2 years ago

Almost entire balance (2675 XMR) of Community Crowdfunding System (CCS) Monero wallet has been stolen

github.com

external-link
message-square
29
fedilink
  • cross-posted to:
  • [email protected]
55
external-link

Almost entire balance (2675 XMR) of Community Crowdfunding System (CCS) Monero wallet has been stolen

github.com

Rucknium to Monero · 2 years ago
message-square
29
fedilink
  • cross-posted to:
  • [email protected]
CCS Wallet Incident · Issue #916 · monero-project/meta
github.com
external-link
The CCS Wallet was drained of 2,675.73 XMR (the entire balance) on September 1, 2023, just before midnight. The hot wallet, used for payments to contributors, is untouched; its balance is ~244 XMR....

Timeline of events

In the last Monero General Fund transparency report in March 2023, the General Fund held 8452 XMR. As far as we know, this separate wallet is safe and unaffected. It would be possible to pay people with active CCS proposal from the General Fund, but nothing has been decided.

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    10
    ·
    edit-2
    2 years ago

    Seems like a good time to start using a multi-signature wallet going forward.

    The developer who got arrested, that should have tainted any keys they were holding, you don’t know who had access to the devices while in police custody

    This is a very expensive learning opportunity.

    It is interesting that it took nine transactions to empty the CCS wallet. Is that indicative of somebody new to monero?

    • RuckniumOP
      link
      fedilink
      arrow-up
      7
      ·
      2 years ago

      It is interesting that it took nine transactions to empty the CCS wallet. Is that indicative of somebody new to monero?

      No.

      A donation wallet has lots of individual transaction outputs that need to be consolidated if you move the entire balance. A transaction that has a lot of inputs that consolidates these transactions will be large in kilobytes. Unless network transaction volume is high enough to push up the dynamic block size rules, the maximum block size is about 300 kilobytes. Transactions must fit inside a single block, so there is a limit to the number of inputs in a single transaction. Plus, you don’t want to create a transaction the full 300 kilobytes in size since miners’ block creation rules might not mine a transaction that large. The first theft transaction in the list was about 22 kilobytes with 33 inputs:

      https://xmrchain.net/search?value=ffc82e64dde43d3939354ca1445d41278aef0b80a7d16d7ca12ab9a88f5bc56a

      The next was 99 kilobytes with 146 inputs:

      https://xmrchain.net/search?value=08487d5dbf53dfb60008f6783d2784bc4c3b33e1a7db43356a0f61fb27ab90cc

      Etc.

      The full list: ffc82e64dde43d3939354ca1445d41278aef0b80a7d16d7ca12ab9a88f5bc56a 08487d5dbf53dfb60008f6783d2784bc4c3b33e1a7db43356a0f61fb27ab90cc 4b73bd9731f6e188c6fcebed91cc1eb25d2a96d183037c3e4b46e83dbf1868a9 8a5ed5483b5746bd0fa0bc4b7c4605dda1a3643e8bb9144c3f37eb13d46c1441 56dd063f42775600adf03ae1e7d7376813d9640c65f08916e3802dbfee489e2c e2ab762927637fe0255246f8795a02bd7bb99f905ae7afc21284e6ff9e7f73db 9bf312ed09da1e7dfce281a76ae2fc5b7b9edc35d31c9eb46b21d38500716b6b 837de977651136c18b0018269626be7155d477cc731c5ca907608a2db57ff6a8 9c278d1496788aee6c7f26556a3f6f2cbb7e109cd20400e0b2381f6c2d4e29f4

    • jet@hackertalks.com
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 years ago

      Multi signature wallets with at the very least prevent us from suspecting the keyholders being individually liable. Which is a possibility

    • Saki
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 years ago

      It is interesting that it took nine transactions to empty the CCS wallet. Is that indicative of somebody new to monero?

      Not sure but perhaps they weren’t able to send it in one go for technical reasons (like byte size limit), as inputs would have been too many (a lot of relatively small coins, originally received from many supporters)?

      Firstly relatively small 23527 B. They did a small “test”? https://localmonero.co/blocks/search/ffc82e64dde43d3939354ca1445d41278aef0b80a7d16d7ca12ab9a88f5bc56a

      Then bigger like 101 KB https://localmonero.co/blocks/search/08487d5dbf53dfb60008f6783d2784bc4c3b33e1a7db43356a0f61fb27ab90cc https://localmonero.co/blocks/search/4b73bd9731f6e188c6fcebed91cc1eb25d2a96d183037c3e4b46e83dbf1868a9 https://localmonero.co/blocks/search/8a5ed5483b5746bd0fa0bc4b7c4605dda1a3643e8bb9144c3f37eb13d46c1441 etc.

Monero

monero

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

This is the lemmy community of Monero (XMR), a secure, private, untraceable currency that is open-source and freely available to all.

GitHub

StackExchange

Twitter

Wallets

Desktop (CLI, GUI)

Desktop (Feather)

Mac & Linux (Cake Wallet)

Web (MyMonero)

Android (Monerujo)

Android (MyMonero)

Android (Cake Wallet) / (Monero.com)

Android (Stack Wallet)

iOS (MyMonero)

iOS (Cake Wallet) / (Monero.com)

iOS (Stack Wallet)

iOS (Edge Wallet)

Instance tags for discoverability:

Monero, XMR, crypto, cryptocurrency

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 47 users / week
  • 143 users / month
  • 517 users / 6 months
  • 214 local subscribers
  • 1.91K subscribers
  • 1.1K Posts
  • 6.15K Comments
  • Modlog
  • mods:
  • admin
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org