Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events
No Result
View All Result
Cryip
No Result
View All Result
Home News Security & Hacks

RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

RetoSwap halts all trading after a second Haveno protocol exploit exposed flaws in dispute resolution, prompting emergency security measures and a pending patch.

Saravana Kumar Mahendran by Saravana Kumar Mahendran
June 17, 2026
in Security & Hacks
0 0
RetoSwap Suspends Trading Following Second Exploit in Haveno Protocol

Created by Cryip

Share on FacebookShare on Twitter
MakeCryipCryippreferred onGoogle

RetoSwap, a leading privacy-focused peer-to-peer decentralized exchange for trading Monero (XMR) against fiat and other cryptocurrencies over Tor, has temporarily suspended all trading after a new security exploit was detected in the underlying Haveno protocol.

Today at 18:02 UTC we have received a report that the Haveno trade protocol is actively being exploited.
The team immediately halted trading by setting the minimum client version to 2.0.0 using the filter feature and banned the exploiters onion address.

— RetoSwap (@RetoSwap) June 16, 2026

The RetoSwap team received the first report around 18:02 UTC (2:02 AM Beijing time) on June 16, 2026. They responded swiftly by raising the minimum client version to 2.0.0, blacklisting the attacker’s onion address (fg2lhfh…2qpad.onion), and halting trading. Trading will remain paused until a full security patch is developed, tested, and released.This is the second major incident involving the Haveno protocol within a short period. In mid-May 2026, attackers exploited a flaw in ACK message handling and arbitrator impersonation during multisig wallet creation, resulting in the theft of approximately $2.7 million (around 7,000 XMR). Losses were mainly limited to large crypto-to-crypto trades, with fiat traders largely unaffected.

The May Haveno exploit occurred during a month that saw elevated losses across the crypto sector. According to industry tracking, crypto projects lost more than $84 million across 41 security incidents in May 2026 alone, highlighting the broader challenges facing protocol security and risk management across decentralized ecosystems.

The latest June exploit targets the dispute resolution and forced arbitration mechanism. According to community updates and Haveno contributors, the attacker (acting as a buyer) took buy offers, forced arbitration, and managed to release XMR after Bitcoin confirmations (around 30 blocks) without sending the corresponding BTC. Notably, this incident appears to involve what looks like legitimate arbitrator addresses in some cases, differing from the May attack vector.

The incident also follows a series of recent protocol-level exploits affecting decentralized finance platforms. Earlier this month, Solv Protocol suffered a $2.7 million loss linked to a smart contract vulnerability in its Bro Vault, underscoring how both application-layer and protocol-layer weaknesses continue to pose significant risks to users.

RetoSwap confirmed that its own infrastructure was not breached. The vulnerability lies entirely within the Haveno protocol. Losses in this new incident appear limited so far, as the team acted quickly to contain it. Haveno lead developer woodser stated:

woodser
woodser

Advice for Users

  • Revoke all open offers immediately
  • Check and back up your application data
  • Avoid any further trading until the patch is deployed
  • Contact support via the official SimpleX group (“chat with admin”) if you have affected trades

RetoSwap is an active implementation/fork of the Haveno protocol, offering fully non-custodial, Tor-based P2P Monero trading with 2-of-3 multisignature escrow. Haveno itself originated as a fork of Bisq, aiming to provide strong privacy and decentralization. However, the repeated issues in message validation, address handling, and arbitration logic have exposed challenges in securing these complex decentralized systems.

The RetoSwap and Haveno teams are working on a verified security patch. Trading is expected to resume only after the update is thoroughly tested and released. The team is also evaluating recovery options for any affected users and plans to release a detailed post-mortem report.This back-to-back incidents highlight the real-world difficulties in building secure peer-to-peer trading protocols, especially for high-value privacy assets like Monero. While the core vision of private, non-custodial trading remains important amid global regulatory pressures, these events emphasize the need for rigorous auditing and rapid community response.We will continue monitoring for official patch releases, loss estimates, and any compensation details from the teams.

Disclaimer: Cryip is an independent media and research outlet providing news, data, and analysis on the cryptocurrency industry. Content is for informational and research purposes only and does not constitute financial, legal, tax, or investment advice. Cryptocurrency markets are volatile and past performance is not indicative of future results. References to specific assets, platforms, or incidents are for journalistic purposes only and do not imply endorsement, and readers assume full responsibility for their decisions.
Tags: Crypto Hacks

Related Posts

Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop
Market Updates

Humanity Protocol to Replace Compromised $H Tokens With New ERC-20 Airdrop

by Saravana Kumar Mahendran
June 16, 2026

Humanity Protocol, the blockchain project focused on zero-knowledge proof-based identity verification and "Proof of Humanity," has released a detailed recovery...

Read moreDetails
Thetanuts Finance Hit by $2.1M Exploit as Legacy Ethereum Vault Flaw Resurfaces

Thetanuts Finance Hit by $2.1M Exploit as Legacy Ethereum Vault Flaw Resurfaces

June 16, 2026
Aztec Connect Exploit Drains $2.19M From Deprecated Protocol, Aztec Network Safe

Aztec Connect Exploit Drains $2.19M From Deprecated Protocol, Aztec Network Safe

June 15, 2026 - Updated on June 16, 2026
Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

Humanity Protocol Hack Linked to North Korean Actors as Quantstamp Investigation Reveals $36M Exploit

June 13, 2026
Raydium Suffers $1.34M Exploit as Attacker Drains Dormant Legacy AMM V3 Liquidity Pools on Solana

Raydium Suffers $1.34M Exploit as Attacker Drains Dormant Legacy AMM V3 Liquidity Pools on Solana

June 11, 2026
Token of Power Loses $1.58M in Governance Exploit as Attacker Hijacks Aragon DAOEthereum

Token of Power Loses $1.58M in Governance Exploit as Attacker Hijacks Aragon DAOEthereum

June 10, 2026
Humanity Protocol Faces $36M Bridge Exploit: Detailed Incident Update on Multisig Compromise

Humanity Protocol Faces $36M Bridge Exploit: Detailed Incident Update on Multisig Compromise

June 9, 2026
Next Post
Ripple Invests in Flutterwave at $3.2 Billion Valuation to Expand Stablecoin Payments Across Africa

Ripple Invests in Flutterwave at $3.2 Billion Valuation to Expand Stablecoin Payments Across Africa

Recommended

  • All
  • News
Senate Housing Bill With CBDC Ban Until 2030 Advances Toward Final Congressional Votes

Senate Housing Bill With CBDC Ban Until 2030 Advances Toward Final Congressional Votes

June 17, 2026
FBI Warns Crypto Scammers Are Sending Couriers to Victims’ Doorsteps for Cash Pickups

FBI Warns Crypto Scammers Are Sending Courier to Victims Doorstep for Cash Pickups

June 17, 2026
Coinbase Launches 11 Backed Tokenized Stocks and AI Investment Tools

Coinbase Launches 1:1 Backed Tokenized Stocks and AI Investment Tools

June 17, 2026
Ripple Invests in Flutterwave at $3.2 Billion Valuation to Expand Stablecoin Payments Across Africa

Ripple Invests in Flutterwave at $3.2 Billion Valuation to Expand Stablecoin Payments Across Africa

June 17, 2026
Price Analysis June 17: BTC, ETH, BNB, XRP, SOL as Traders Assess Key Support Levels Amid Market Pullback

Price Analysis June 17: BTC, ETH, BNB, XRP, SOL as Traders Assess Key Support Levels Amid Market Pullback

June 17, 2026
How to Use Etherscan Complete Beginner to Expert Guide for Ethereum Blockchain Tracking

How to Use Etherscan: Complete Beginner to Expert Guide for Ethereum Blockchain Tracking

June 17, 2026
Senate Housing Bill With CBDC Ban Until 2030 Advances Toward Final Congressional Votes

Senate Housing Bill With CBDC Ban Until 2030 Advances Toward Final Congressional Votes

June 17, 2026
FBI Warns Crypto Scammers Are Sending Couriers to Victims’ Doorsteps for Cash Pickups

FBI Warns Crypto Scammers Are Sending Courier to Victims Doorstep for Cash Pickups

June 17, 2026

Cryip focuses on crypto research and on-chain analysis, supported by coverage of markets, regulation, security events, and blockchain ecosystems.

Recent Posts

  • Price Analysis June 17: BTC, ETH, BNB, XRP, SOL as Traders Assess Key Support Levels Amid Market Pullback
  • How to Use Etherscan: Complete Beginner to Expert Guide for Ethereum Blockchain Tracking
  • Senate Housing Bill With CBDC Ban Until 2030 Advances Toward Final Congressional Votes

Categories

  • AI × Crypto
  • Data & Dashboards
  • DeFi Basics
  • Investing Basics
  • Market & Price
  • Market Updates
  • On-Chain Analysis
  • OpSec
  • Policy & Regulation
  • Post Mortems
  • Press Release
  • Reports
  • Scams & Fraud
  • Security & Hacks
  • Stablecoins
  • Tokenomics
  • VC & Funding
  • Wallets & Custody

Company

  • About Us
  • Contact Us
  • Editorial Standards & Integrity
  • Our Team
  • Privacy Policy
  • Review Methodology
  • Terms and Conditions
  • Trust, Disclosures & Independence

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • News
  • Research & Analysis
  • Reviews & Comparisons
  • Learn Crypto
  • Features
  • Events

© 2026 Cryip - Research-Driven Crypto Analysis & News by Hashlays.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.