The day before yesterday, November 18, the official site of the Monero cryptocurrency was compromised by hackers with the aim of distributing a malware-infected file, which steals money from account holders.
The breach was discovered by a Monero user who reported the issue on GitHub. Following the publication, the Monero team confirmed the breach in a tweet.
The user discovered that something was wrong when he downloaded a 64-bit Linux binary from the Linux.
After downloading the installer from the official site, he noticed that the SHA256 hash for the downloaded file did not match the SHA256 hash listed on the site. This is how he understood that the file had been modified.

The M onero teamis investigating the case
The team is urging all users who downloaded the CLI wallet on Monday to check the hashes of their binaries. If they notice that they don’t match the hashes on the site, they should delete the files and download them again. “Do not run the compromised binaries for any reason,” the Monero team stressed.
After discovering the breach, the team removed the malicious file. However, one user reported losing their cryptocurrencies.
“I can confirm that the malicious binary is stealing cryptocurrencies. Approximately 9 hours after the binary was executed, a transaction occurred that emptied my wallet,” the user said. According to his posts, he lost $7,000 worth of Monero.
The Monero team is still investigating the case to understand how the hackers to compromise the download server. At this time, there is no risk, however, users should always check.
Aside from the user who publicly reported losing Monero after downloading the malicious file, no other breaches have been reported. However, other users.
breach taught us a good lesson and showed that a simple hash verification can be lifesaving. All users should do these checks.
