2 Nov 2023 | Updated 19 Nov 2023 [CCS] [pinned]

luigi1111 discloses critical breach: 'CCS Wallet was drained of 2,675.73 XMR'

Monero Core Team member luigi11111 has reported2 a serious incident that occurred on September 1st 2023 and which resulted in the loss of 2,675.73 XMR from the main CCS wallet3:

The CCS Wallet was drained of 2,675.73 XMR (the entire balance) [..] The hot wallet, used for payments to contributors, is untouched; its balance is ~244 XMR. We have thus far not been able to ascertain the source of the breach. [..] How do we achieve CCS continuity for existing contributors? Core team is in favor of covering existing liabilities from the General Fund.

Join #monero-community4 discussions and consult -meta issue #9162 to learn more about the issue.

This is an ongoing story and the report will be updated when new information is available.

Update 23/11/3: the GF will be used to cover the loss, according to plowsof’s -site PR #22085; completed proposals should start receiving payments today, per luigi’s comment6; added address of compromised wallet for reference3.

Update 23/11/4: ‘Postmortem of Monero CCS Hack: A Transaction Graph Analysis’ report published by Moonstone Research7.

Update 23/11/19: core/Seraphis dev proposals in the ideas stage will be funded (probably from GF)8.

