monero.town
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Rucknium to Monero · 2 years ago

Almost entire balance (2675 XMR) of Community Crowdfunding System (CCS) Monero wallet has been stolen

github.com

external-link
message-square
29
fedilink
  • cross-posted to:
  • [email protected]
55
external-link

Almost entire balance (2675 XMR) of Community Crowdfunding System (CCS) Monero wallet has been stolen

github.com

Rucknium to Monero · 2 years ago
message-square
29
fedilink
  • cross-posted to:
  • [email protected]
CCS Wallet Incident · Issue #916 · monero-project/meta
github.com
external-link
The CCS Wallet was drained of 2,675.73 XMR (the entire balance) on September 1, 2023, just before midnight. The hot wallet, used for payments to contributors, is untouched; its balance is ~244 XMR....

Timeline of events

In the last Monero General Fund transparency report in March 2023, the General Fund held 8452 XMR. As far as we know, this separate wallet is safe and unaffected. It would be possible to pay people with active CCS proposal from the General Fund, but nothing has been decided.

  • Uncle Iroh ☑️@merovingian.club
    link
    fedilink
    arrow-up
    3
    ·
    2 years ago

    @shortwavesurfer @Rucknium

    Seconded.

    With only 2 known keyholders and likely 1 single person with physical access to the Qubes laptop, and where the whole key and wallet were probably stored in a standalone offline vault-vm, what the fuck happened?

    • Uncle Iroh ☑️@merovingian.club
      link
      fedilink
      arrow-up
      4
      ·
      2 years ago

      @shortwavesurfer @Rucknium

      I see. They held the hot wallet on Windows fucking 10.

      Unbelievable. Opsec? What’s Opsec?

      • Uncle Iroh ☑️@merovingian.club
        link
        fedilink
        arrow-up
        2
        ·
        2 years ago

        @shortwavesurfer @Rucknium

        As pointed out in the github thread by someone, the more useful opsec flow should have gone something like this.

        And make the offline computer an offline vault-vm on a non-internet Qubes laptop .

      • tusker
        link
        fedilink
        arrow-up
        2
        ·
        2 years ago

        How anyone that understands crypto is using windows in the year 2023 is beyond me. You cannot fix laziness with FOSS.

        • Uncle Iroh ☑️@merovingian.club
          link
          fedilink
          arrow-up
          2
          arrow-down
          1
          ·
          2 years ago

          @tusker

          It’s worse than that.

          Fiscal responsibility alone dictates that you have a duty to create a public Opsec Charter of sorts.

          And that’s nothing to say of an ideological-FOSS duty to create the same.

          This reeks of more than incompetence.

Monero

monero

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

This is the lemmy community of Monero (XMR), a secure, private, untraceable currency that is open-source and freely available to all.

GitHub

StackExchange

Twitter

Wallets

Desktop (CLI, GUI)

Desktop (Feather)

Mac & Linux (Cake Wallet)

Web (MyMonero)

Android (Monerujo)

Android (MyMonero)

Android (Cake Wallet) / (Monero.com)

Android (Stack Wallet)

iOS (MyMonero)

iOS (Cake Wallet) / (Monero.com)

iOS (Stack Wallet)

iOS (Edge Wallet)

Instance tags for discoverability:

Monero, XMR, crypto, cryptocurrency

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 47 users / week
  • 143 users / month
  • 514 users / 6 months
  • 214 local subscribers
  • 1.91K subscribers
  • 1.1K Posts
  • 6.15K Comments
  • Modlog
  • mods:
  • admin
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org