Filters

Clear all

Service Events Timeline

  1. Active incidents
  2. Low incident

    Trading halted | security issues are being patched

    Ongoing since

    On July 1st 11:15 AM, Bisq has issued a notice stating that trading on Bisq 1 has been halted. A security audit has identified several issues, three critical and other minor ones, that are currently being patched. The network has been halted as a precautionary measure. Existing trades are unaffected and can be completed normally. RetoSwap admins have recieved information that both their service and the underlying Haveno code are unaffected by these issues. Status updates will be provided on Matrix, Reddit, and Telegram. Additional announcements may also be published on X and Nostr.

  3. Critical incident

    June 2026 server breach: ~200 XMR stolen

    Ongoing since

    On June 8, 2026, OpenMonero was breached again, less than three weeks after the May exploit. An attacker gained root access at the server level, not the application, and took roughly 200 XMR (about $63,000), which the operator said was all platform funds.

    The operator then reported the funds as lost and has not committed to reimbursing victims. This is the platform's third funds-loss incident in twelve months.

  4. High incident

    Exolix API exposed ~$39.5M of swap history

    Ongoing since

    A security researcher found that Exolix's partner API used unscoped JWT keys with no rate limiting or IP restrictions, which let anyone dump full swap histories. The exposed data covered roughly 355,000 transactions and $39.5M in volume from January 2025 to May 2026: deposit and withdrawal addresses, on-chain hashes, amounts, rates, and timestamps.

    For a no-KYC swapper, this links addresses and undoes the privacy users came for. After the disclosure, Exolix called the open access "a feature, not a bug," added WAF rules, and left the underlying flaw in place.

  5. Medium incident

    Exit IP Fingerprinting vulnerability found | Patch rollout in progress

    Ongoing since

    A security researcher found a vulnerability in the way Mullvad servers assign exit IP addresses to user devices, allowing websites to fingerprint the same user accessing them through different servers. Changing servers has been rendered useless for unlinkability purposes. Mullvad has acknowledged the vulnerability in a blog post and is currently patching its servers to mitigate the issue. Here is a list of the servers that have been patched.

  6. Ongoing events
  7. Ownership change

    Ongoing since

    On July 17, 2026 Nonlogs announced on X that they would transfer full ownership of the exchange to monero.forum. It is unclear whether the refunds that were previously promised have occurred at all. It appears that all remaining balances on the exchange have been transfered to monero.forum. We are monitoring the situation.

  8. New deposit & withdrawal limits | Effective Aug 15

    Ongoing since

    Kraken has begun sending a notice to XMR traders on their platform in which they announce new limits on Monero deposit and withdrawals.These changes will enter into effect August 15th. The exchange cites risk-based compliance controls as the main reason behind this increased scrutiny. For individual accounts in any given 30-day period, the deposit limit will be $3,500 while the withdrawal limit will be $1,000. For corporate accounts in the same rolling period, $30,000 will be the limit for deposits and $10,000 for withdrawals. Kraken states that individuals wanting higher limits can ask for them through a whitelisting review process, where additional information involving SoF, trading purpose or expected volume will likely be requested. Finally, Kraken recommends proactively contacting support and initiating the review process if you expect your future trading activity to be higher than the new limits.

  9. Possible hidden fees | Act with caution

    Ongoing since

    A user in the OrangeFren SimpleX group reported that Swapuz charged him an undisclosed hidden fee for a “high-risk” transfer. OrangeFren intervened and successfully negotiated a refund on the user’s behalf.

    If the final amount you receive after a trade differs significantly from the quoted amount, we encourage you to contact the platform’s support team and inform us as well. For added protection, we highly recommend executing trades through an aggregator that offers a guarantee.

  10. Service paused

    Ongoing since

    Due to security concerns over upstream code quality, the Dawnswap admins have decided to pause the service and halt all trading until a more stable Haveno version is released or a third party security audit is performed on the Haveno codebase. They have expressed willingness to partially fund such audit if there is also interest from other Haveno instances in doing so.

  11. Suspicious promotion via compromised subreddit

    Ongoing since

    r/AskMonero shows signs of being compromised, as Fujn Swap is being actively promoted in posts citing it as the best swap provider. There is no disclosure that Fujn is paying mods for that promotional content. This lack of transparency makes the subreddit and, by extension, the service appear untrustworthy. Users should exercise due caution with any amounts and avoid relying on the subreddit for advice.

  12. Compliance procedures update

    Ongoing since

    Due to recent sanctions-related developments involving Huobi/HTX, funds originating from Huobi will be suspended by the service and will be subject to additional verification.

  13. New beta available for testing

    Ongoing since

    xChange.me announced a new beta software available at https://beta.xchange.me and https://nojs.xchange.me for Tor usage. In the beta period, lasting between one to three months, there will be a 1% fee in the new sites for XMR and BTC to encourage testing.

  14. Earlier
  15. Attribute added

    Attribute "Strict no-log policy" was added to GoyMail

  16. Attribute removed

    Attribute "May suspend your account" was removed from GoyMail

  17. Verification update

    Verification status changed from COMMUNITY_CONTRIBUTED to VERIFICATION_FAILED

  18. Attribute added

    Attribute "May require KYC/SOF by policy/law" was added to Hellex

  19. Attribute added

    Attribute "Data Sharing" was added to Hellex

  20. Attribute added

    Attribute "API available" was added to Hellex

  21. Attribute added

    Attribute "Transaction monitoring" was added to Hellex

  22. Currency update

    Added currencies: FIAT

  23. Currency update

    Added currencies: CASH

  24. Currency update

    Removed currencies: MONERO

  25. Description update

    Description was updated

  26. Critical incident

    Exchange closing down | Withdraw funds on July 18 11:30 AM UTC

    From to

    Following last week's hack, Nonlogs has decided to cease operations. The operator cited an inability to continue as the primary reason for the shutdown and has declared insolvency, stating they cannot cover the losses or issue refunds.

    Withdrawals are scheduled to open on July 18 at 11:30 AM UTC. Users who withdraw BTC, WOW, and XMR first may receive partial reimbursement. GRIN and other unaffected coins can be withdrawn normally. Servers will remain online until the end of the month, setting the withdrawal deadline for July 31.

  27. Attribute added

    Attribute "No JavaScript needed" was added to GoyMail

  28. Attribute removed

    Attribute "JavaScript needed" was removed from GoyMail

  29. Attribute added

    Attribute "Third-Party payment processor" was added to WaldenPay

  30. KYC update

    KYC level changed from 0 to 1

  31. Attribute added

    Attribute "KYC depends on partners" was added to WaldenPay

  32. Attribute removed

    Attribute "Strict no-log policy" was removed from WaldenPay

  33. KYC update

    KYC level changed from 3 to 0

  34. Attribute removed

    Attribute "Operating for less than 3 months" was removed from GoyMail

  35. Attribute added

    Attribute "Third party infrastructure" was added to servers guru

  36. Verification update

    Verification status changed from APPROVED to COMMUNITY_CONTRIBUTED due to not responding for a long time to a user with blocked funds. Also, appears to have bad reviews in platforms like Bestchange. The issue is ongoing, and we will update if we have any news. We have contacted Swapter and we are waiting for a reply.

  37. Critical incident Resolved

    Exchange hacked | ~$45k stolen

    From to

    On July 7, 2026 7:00 AM UTC, the exchange nonlogs.io announced they experienced a security incident affecting withdrawals. They have paused withdrawal flows and are reviewing the ones executed in the past two days. The amount stolen oscillates around $44k, with the majority being in BTC, followed by XMR and WOW. The exploit mechanism appears to have involved a compromised JWT signing secret. Attackers were able to forge new JWT keys using admin user UUIDs found on a public API, allowing them to dump balances and execute withdrawals. It appears USDT reserves were not targeted by the hackers. A full technical report of the attack can be found in the source of this incident.

  38. High incident Resolved

    Swap refund security issue | Update to v0.17.2 before resuming swaps

    On July 14, 2026, the team behind BasicSwap posted an advisory urging trading be halted due to a newly-found security vulnerability. A race condition on the automatic refund path of adaptor-signature swaps, also known as Monero-style swaps, allowed an attacker with a modified client to steal swap funds before a refund was broadcasted to the blockchain. This attack involved targeted risk, as only a counter-party deliberately running a modified client could use it. Regularly completed swaps remain unaffected. A total loss of 0.66 BTC (~$42k) has been reported by the team.

    v0.17.2 has been released with a security fix. Users are strongly encouraged to update. Once the update has been performed, its safe to bring the node back online to complete any pending trades.

  39. v0.17.2: security fix for adaptor-signature swaps + hardening

    Version 0.17.2 of BasicSwapDEX has been released, bringing with it a fix for the adaptor-signature refund path, a hardened spent-index watcher, an improved mechanism to receive mercy transactions on BCH and AMM offer-revoke fixes. Users are strongly encouraged to first, perform the update, and second, bring their nodes back online. After those two steps are taken, previously unsettled trades can be concluded without being vulnerable to the known exploits this release fixes.

  40. Attribute added

    Attribute "Email required" was added to FetchSMS

  41. Attribute added

    Attribute "No-refund policy" was added to FetchSMS

  42. Attribute removed

    Attribute "No registration needed" was removed from FetchSMS

  43. Attribute removed

    Attribute "Own infrastructure" was removed from FetchSMS

  44. Attribute added

    Attribute "Service Termination Policy" was added to FetchSMS

  45. KYC update

    KYC level changed from 0 to 1

  46. Attribute added

    Attribute "Account required" was added to FetchSMS

  47. Service back online

    After a day of downtime, kyun.sh is accessible again. ICMP has been mitigated in order to rate-limit connection attempts and defend against further DDoS.

  48. Service down due to DDoS attack

    From to

    On July 8, 2026 Kyun has been hit with an ongoing DDoS attack. WA is down and their RO is currently not announcing Kyun IP ranges. Authorship of the attack remains unknown. We will monitor the issue for further updates.

  49. Service downtime

    From to

    On July 6, 2026 Wagyu suffered a service outage while the operator remained unreachable. An X user was unable to swap 0.5 XMR to DAI through Wagyu with the following error message: 'Failed to fetch'. Less than 24h later the operator responded, claiming the service had suffered a DDoS attack. Wagyu is back in operation and no further issues have come up. We will keep an eye on future developments.

  50. Attribute added

    Attribute "RAM-only infrastructure" was added to AirVPN

  51. Attribute added

    Attribute "Third-Party payment processor" was added to AirVPN

  52. Attribute added

    Attribute "Strict no-log policy" was added to AirVPN

  53. Attribute removed

    Attribute "JavaScript needed" was removed from simsup

  54. Attribute added

    Attribute "No JavaScript needed" was added to simsup

  55. Attribute added

    Attribute "Identity-Free registration" was added to simsup

  56. Attribute added

    Attribute "Token-based login" was added to simsup

  57. Domain change

    Service URLs updated from https://simsup.net to https://simsup.com

  58. Website back online

    Both the clearnet and onion sites for RoboSats are back online.

  59. Website is down

    From to

    Both robosats.org and its onion site are down. We are monitoring the issue for future updates. You can try using some of the secondary onion addresses in the meantime.

  60. Advertises below market rates | Possible exit scam

    From to

    According to the swap service directory OrangeFren, Bitania has been advertising swaps with below market rates. This can indicate a possible exit scam.

  61. Attribute added

    Attribute "May Freeze or Seize Funds " was added to Baltex

  62. Attribute added

    Attribute "Identity-Free registration" was added to Baltex

  63. Attribute added

    Attribute "Transaction monitoring" was added to Baltex

  64. Attribute added

    Attribute "Data Sharing" was added to Baltex

  65. Attribute added

    Attribute "Non-custodial protocol" was added to Baltex

  66. Description update

    Description was updated

  67. Android app v1.0.7 released | update encouraged

    A new version of the RetoSwap Android app has been released, making this release compatible with Haveno v1.8.0. It also adds Zcash support and brings the ability to use stablecoin market value when making an offer, besides small UX improvements. Since this release is compatible with Haveno v1.8.0, the one containing the security enhancements, Android users are strongly encouraged to update.

  68. Version 0.16.6 released with multiple security improvements | update recommended

    BSX Core 16.6 has been released, with substantial hardening done to the fund-safety verification process. Notable security improvements include stronger lock-amount verification, symmetric refund-signature verification, smarter swap-type defaults, automatic chain-fee-rate validation and subfee bids.

  69. Attribute added

    Attribute "Some countries are restricted" was added to sideshift.ai

  70. Call for password reset +2FA

    Following the latest hack, the OpenMonero admin has issued a new update, having reset all user 2FA tokens and urging them to change passwords and settlement wallet addresses. Users who registered between April 12 and May 22 are encouraged to open a support ticket. A new Session Notification Bot has also been created, while users have been told to block the old one.

  71. Trading has resumed

    After more than a month offline, trading has resumed on THORChain. v3.19.1 shipped with new protocol patches. The release has bundled two things: patches to the KeyVerify process, and a fix for a Gaia (Cosmos Hub) bug the team wanted to patch before bringing those nodes back to the chain tip. XMR integration is expected to go live one month from now.

  72. Medium incident

    Haveno vulnerability confirmed | Pause all trading

    From to

    Haveno lead developer woodser confirmed a new vulnerability in the dispute resolution process, allowing attackers to forge dispute payouts. Since Dawnswap is built on top of Haveno, it is vulnerable to the same exploit. A security patch is being prepared, and users are advised to back up their application data (e.g., wallet directories) in case of recovery efforts. The admins have issued a message in their SimpleX group asking users to cancel all offers and conclude trading, though its unclear if they have taken the service offline. A user has reported a small loss of funds in the Haveno Matrix room, but the Dawnswap admins claim not to have received any such refund request. They remain open to check the issue if contacted though.

    If you are running Dawnswap, revoke all offers and refrain from trading.

  73. Currency update

    Added currencies: LIGHTNING

  74. Attribute removed

    Attribute "Non-custodial wallet" was removed from Fujn Swap

  75. Attribute removed

    Attribute "Peer to peer market" was removed from Fujn Swap

  76. Attribute removed

    Attribute "Good Customer Support" was removed from Fujn Swap

  77. Attribute removed

    Attribute "No KYC after AML check" was removed from Fujn Swap

  78. Attribute added

    Attribute "Potential risk" was added to Fujn Swap

  79. Attribute removed

    Attribute "No registration needed" was removed from Fujn Swap

  80. Medium incident Resolved

    Node exploit drained $10.7M, trading halted

    From to

    On May 15, 2026, a malicious node exploited a flaw in THORChain's threshold-signature scheme to rebuild a vault's signing key and drain about $10.7M from one Asgard vault. The funds were protocol-owned; user swaps and LP positions stayed safe.

    THORChain halted trading, signing, and churning, slashed the attacker's bond, and patched the flaw in v3.18.1 and v3.19.0. Node operators approved the ADR-028 recovery plan, which absorbs the loss through protocol-owned liquidity without minting RUNE or diluting holders. As of mid-June the network runs a staged restart and trading remains paused.

  81. RetoSwap 1.8.0 released | security issue fixed

    Shortly after Haveno lead developer woodser released version 1.8.0, RetoSwap shipped the update, fixing the previously exploited vulnerability and patching other related issues. Additionally, you can now enable passphrase protected offers, where by only users whom you share the passphrase with can take them. Trading can be resumed. Refunds are still pending but are expected to be covered mostly by future trading fees.

  82. Version 1.8.0 released | security issue patched

    Haveno lead developer woodser released a new version of Haveno, fixing the previously exploited security issue and more. The fix also contains passphrase protection for all offer types.

  83. Medium incident Resolved

    Haveno vulnerability confirmed - Trading halted

    From to

    Haveno lead dev woodser confirmed a new vulnerability in the dispute resolution process, allowing attackers to forge dispute payouts. A security patch is being prepared, and users are advised to back up their application data (e.g., wallet directories) in case of recovery efforts. RetoSwap and operators were again urged to act cautiously.

    If you are running RetoSwap, revoke all offeers and pause trading. Affected users can reach out to RetoSwap in the RetoSwap SimpleX group via the 'chat with admin' feature.

  84. Medium incident Resolved

    Haveno vulnerability confirmed - Trading halted

    From to

    Haveno lead dev woodser confirmed a new vulnerability in the dispute resolution process, allowing attackers to forge dispute payouts. A security patch is being prepared, and users are advised to back up their application data (e.g., wallet directories) in case of recovery efforts. RetoSwap and operators were again urged to act cautiously.

    If you are running RetoSwap, revoke all offeers and pause trading. Affected users can reach out to RetoSwap in the RetoSwap SimpleX group via the 'chat with admin' feature.

  85. v1.10.2 released | update encouraged

    Bisq version 1.10.2 has been released, bringing with it both stronger DAO consensus validation and merit verification. It also improves DAO voting precision and issuance calculations. Finally, it adds protections against invalid consensus states.

  86. Domain change

    Service URLs updated from https://roboex.cc, https://roboex.cx to https://roboex.cc

  87. Fund-loss reports investigated, not reproduced

    From to

    Some users reported sending funds that never arrived in their accounts. We investigated and could not reproduce the problem: two separate test deposits credited correctly and SMS delivery worked. We could not reproduce any loss of funds, and some of the reports appear coordinated.

  88. Peach web released

    Peach Bitcoin has released a web app, allowing for seamless use across all platforms. Logging in to the web app is handled by scanning a QR code in the phone app. Transacting on the website is authorized though the mobile app.

  89. Medium incident Resolved

    Exploit in poisoned secret-has atomic swaps | Update to 0.16.4 or higher

    From to

    This exploit enables an attacker running a modified legacy client to under-fund their side of a trade, executing the trade with a lower amount than the one initially agreed upon. A couple of malicious offers have been spotted on the wild. A fix was rolled out with version 0.16.4. BasicSwap has urged its users to update.

  90. Abruptly terminates VPS customers without notice

    From to

    1984.is abruptly shut down the VPS hosting XMRBazaar (a Monero marketplace) on June 6, 2026, citing abuse tickets, mostly DMCA, that XMRBazaar says it never received and had no chance to answer. Service was restored within about a day after review.

    It fits a pattern: 1984 also cut off Hack Liberty in March 2026 after four years. Its terms reserve the right to terminate "with or without notice" at sole discretion, so the action was within policy, but for a host that markets privacy and civil rights, no-notice takedowns over disputed copyright claims drew downgrades from several directories.

  91. Android app passes security assessment

    The Mullvad VPN Android app has successfully passed a security assessment by Leviathan Security Group. The app has updated minor issues in order to more closely align with the Mobile App Profile specification. This is the second year in a row where the app passes the assessment.

  92. Low incident Resolved

    Maker-side ASB bug exploited to grief liquidity providers

    From to

    Before the May 27 patch, eigenwallet's maker-side Automated Swap Backend (ASB) failed to sanity-check the Bitcoin cancel-transaction fee. A malicious taker could propose an absurdly high fee and burn value during a swap, griefing the maker. Regular wallet users and takers were never at risk.

    Attackers used it across four swaps, affecting two market makers and roughly 0.657 BTC. Nothing was stolen: the griefer burned more of their own BTC than they destroyed. eigenwallet shipped fee validation in v4.6.7 within a day and started a reimbursement fund, its donation wallet plus community donations, to cover affected makers in part.

  93. High incident Resolved

    Haveno protocol exploit: ~7,000 XMR stolen

    From to

    On May 20, 2026, attackers exploited a flaw in the Haveno trade protocol that RetoSwap runs on, impersonating the trade arbitrator before funds reached the multisig escrow and draining about 7,000 XMR (~$2.7M) from users mid-trade.

    RetoSwap caught it within minutes, banned the attacker's onion address, halted trading, and pushed a mandatory client upgrade with identity-verification fixes before resuming. The root flaw was in Haveno, an upstream dependency, not RetoSwap's own code.

    The stolen XMR was not recovered, and no reimbursement has been confirmed. Affected users were told to keep their wallet backups in case recovery becomes possible later.

  94. Medium incident Resolved

    May 2026 exploit: ~40 XMR lost

    From to

    On May 21, 2026, an application-layer exploit cost OpenMonero around 40 XMR. The team told users to halt payments (report) and patched the flaw within two days. OpenMonero later reported that it had refunded every affected user in full.

    This was the platform's second funds-loss incident, after the 2025 server breach.

  95. Android app released

    ObscuraVPN now has an official Android client.

  96. Bridge downtime triggered rug-pull claims

    From to

    Wagyu's bridge and UI went down in May 2026, and the outage sparked rug-pull allegations across Reddit and X. The developer clarified that funds were safe and that withdrawals still worked through the Hyperliquid Terminal, and users have since confirmed the bridge keeps working both ways.

    Note: Wagyu runs a centralized bridge, so you are trusting the team to hold and deliver the actual Monero. That counterparty risk stands regardless of this scare.

  97. High incident Resolved

    Bisq v1 protocol exploit: ~11 BTC stolen

    From to

    On May 1, 2026, an attacker exploited a negative miner-fee validation bug in the Bisq v1 trade protocol and took about 11 BTC from roughly 10 users, mostly on altcoin trades.

    Bisq patched the flaw in v1.10.0 two weeks later and published a full post-mortem. The bug never reached the newer Bisq 2 or Bisq Easy protocols.

    The Bisq DAO reimbursed affected users in full, in BTC or BSQ. See the official thread for details.

  98. Owner background

    From to

    The owner is a convicted cybercriminal with a history of DDoS blackmail, extortion, and faking customer reviews.

    (event ended on favor of the verification step warning)

  99. Critical incident Resolved

    Seized domain

    The domain has been seized by the FBI

  100. Service outage

    From to

    The service is down and can't be accessed. We are monitoring the situation.

  101. Service is down

    From to

    As of 03/18 7AM (UTC), the service is unresponsive

  102. Project renamed to nadanada

    LNVPN has been renamed to nadanada

  103. Absence Due to Family Emergency

    From to

    Trêvoid will be unavailable for two weeks due to a family emergency. All active swaps are closed, and no new requests will be processed during this period. Return is expected once the situation stabilizes.