Incident case file
Sign in to watchRetoSwap / Haveno Forged DepositRequest NACK Exploit
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Onion address fg2lhfhgjrfz4oywqy2mfwfehhqsjse6wyrtdczsrhtves2jofi2qpad.onion:9999 (banned by RetoSwap). No on-chain Monero address publicly disclosed — Monero's privacy features prevent fund tracing.
Timeline: On June 16, 2026 at 18:02 UTC, RetoSwap received a report that the Haveno trade protocol was being actively exploited. The team immediately halted trading by setting the minimum client version to 2.0.0 via the filter feature and banned the attacker's onion address (fg2lhfhgjrfz4oywqy2mfwfehhqsjse6wyrtdczsrhtves2jofi2qpad.onion:9999). RetoSwap clarified on X that its own infrastructure was not compromised — the vulnerability lies in the underlying Haveno protocol itself, meaning other Haveno-based exchanges could be similarly exposed: 'The RetoSwap team has not been compromised. This was a flaw in the Haveno protocol. Damage appears to be contained to large scale crypto offers with fiat traders unaffected.' Affected traders were directed to RetoSwap's SimpleX support channel. Approximately twelve hours after the disclosure, Haveno contributor 'monerobull' filed GitHub issue #2365, identifying the precise root cause: the protocol's generic acknowledgment handler accepts a forged DepositRequest NACK from any verified peer (not just the arbitrator), which triggers immediate, unsafe wallet deletion in the victim before on-chain confirmation that no deposit has been published — permanently locking the victim's funds in a multisig they can no longer access, while the attacker risks nothing. This is a sibling vulnerability to previously identified issue #2363. A fix was proposed the same day in PR #2366, pending merge at the time of this report. No SECURITY.md or formal security advisory has been published by the Haveno project, and no dollar figure for the loss has been officially disclosed by RetoSwap or any Haveno maintainer. This is the second confirmed RetoSwap/Haveno security incident in 2026, following an unrelated $2.7M (7,000 XMR) theft via arbitrator impersonation on May 20, 2026 (outside this reporting window — do not merge figures from the two incidents).
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)