RetoSwap Hack

Reported loss $2.7M
Monero
Other

What happened

On May 20, 2026, RetoSwap lost an estimated $2.7 million (about 7,000 XMR) when an attacker abused a Haveno trade-protocol authentication flaw. A forged ACK message redirected the arbitrator role during multisig-wallet setup to an attacker-controlled address.

How it happened

  1. The attacker joined a trade as a buyer or seller, obtaining one key in its 2-of-3 multisig flow.
  2. Before the multisig wallet was created, the attacker sent a forged, out-of-order ACK message that carried an attacker-controlled .onion address and impersonated the arbitrator.
  3. The client accepted that address without cryptographically checking it against the expected arbitrator public key.
  4. Multisig setup was then routed to the attacker, who acquired the arbitrator's signing position.
  5. After counterparties deposited funds into the compromised wallet, the attacker could move the balance.

Protocol details

Classification Exchange (DEX) / Input Validation / Governance
Protocol Type Exploit/Other
Implementation language C++
Protocol links Website @RetoSwap

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.