The official website for Monero (XMR), GetMonero.com, has been hacked and caused users to download cryptocurrency stealing malware when attempting to obtain the privacy-centric cryptocurrency’s wallet.
According to a report by Ars Technica, GetMonero was discovered to have been hacked on Nov. 19 when a user noticed that the hash from the downloaded XMR wallet did not match the one listed on the site. User nikitasius published a post on GitHub detailing the different hashes, which was confirmed by other members of the community.
Rather than being an error, the mismatched hash was determined to be the result of an attack on users of GetMonero. Users who downloaded the wallet from the website were put at risk of a cryptocurrency-stealing malware.
GetMonero promptly issued a warning, telling community members,
It's strongly recommended to anyone who downloaded the CLI wallet from this website between Monday 18th 2:30 AM UTC and 4:30 PM UTC, to check the hashes of their binaries. If they don't match the official ones, delete the files and download them again. Do not run the compromised binaries for any reason.
PSA: We've posted an announcement regarding the potentially compromised CLI v0.15.0.0 binaries on our website.https://t.co/rLnN8HrJ1d
— Monero || #xmr (@monero) November 19, 2019
One unfortunate Reddit user detailed losing $7,000 from his wallet after downloading the malicious client,
I can confirm that the malicious binary is stealing coins. Roughly 9 hours after I ran the binary a single transaction drained my wallet of all $7000. I downloaded the build yesterday around 6pm Pacific time.
Featured Image Credit: Photo via Pixabay.com