Tools Crypto Exploit Tracker exploit-0041
Exploit record
RetoSwap
- Loss
- $3M
- Attack vector
- Smart Contract Bug
- Chain
- Monero
- Sector
- DEX
What happened
On 20 May 2026 the Monero P2P exchange RetoSwap, a Haveno Protocol fork, was exploited for about 7,000 XMR (roughly $2.7 million) via a forged-message flaw in its trade arbitration flow.
The client accepted a forged, out-of-order ACK message without verifying the sender's signature, letting the attacker overwrite the arbitrator's stored Tor address with their own; the attacker then held two of three keys to newly created trade multisig wallets and swept victims' XMR the moment deposits landed. RetoSwap suspended trading, and Haveno's lead developer shipped a fix the same day preventing node-address updates before multisig creation.
Sources
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026