Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    CLARITY Act Clears Senate Banking Committee 15-9 Here’s What Every Crypto Leader Is Saying
    CLARITY Act Clears Senate Banking Committee 15-9: Here’s What Every Crypto Leader Is Saying
    GENIUS Act stablecoin regulation 2026 — US Treasury, OCC, FDIC and NCUA rulemaking on federal vs state oversight
    GENIUS Act at 10 Months: Inside America’s New Stablecoin Rulebook
    $10.8 Million Drained Inside the THORChain Exploit That Froze Cross-Chain DeFi for 13 Hours
    $10.8 Million Drained: Inside the THORChain Exploit That Froze Cross-Chain DeFi for 13 Hours
    BG Wealth and DSJ Exchange collapse exposes 2026 crypto scam pipeline
    How BG Wealth and DSJ Exposed the New Pipeline Model Behind 2026 Crypto Fraud
    Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
    Exclusive: Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
  • Opinion
    OpinionShow More
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Happens to the One Asset Designed to Escape Control
    What Happens to the One Asset Designed to Escape Control?
    A System Built on Control, and a Question That Refuses to Settle
    A System Built on Control, and a Question That Refuses to Settle
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

Monero DEX RetoSwap Suspends Trading After $2.7M Exploit in Haveno Protocol

The Monero-based decentralized exchange detected the Haveno exploit at 2:31 UTC on May 20 and froze trading within minutes after blocking the attacker’s onion address.

Written By:
Kenrodgers Fabian

Reviewed By:
Divya Mistry

Last updated: 41 minutes ago
Published 41 minutes ago
Share
Last updated: 41 minutes ago
Published 41 minutes ago
Monero DEX RetoSwap Suspends Trading After $2.7M Exploit in Haveno Protocol
Show AI Summary
Attackers exploited a flaw in Haveno’s trade protocol, specifically targeting the multisig process, to drain $2.7 million in XMR.
RetoSwap’s emergency response included blocking the attacker’s onion address and freezing trading within two minutes via a client update.
The exploit involved interfering with Haveno’s trade messaging system, allowing hackers to pose as an arbitrator and gain unauthorized control during trades.

RetoSwap halted trading after attackers exploited a flaw in the Haveno trade protocol and drained roughly 7,000 XMR, valued at about $2.7 million. The Monero-based decentralized exchange disclosed the incident through posts on X on May 21, saying Haveno lead developer woodser detected the exploit at 2:31 UTC. RetoSwap said it blocked the attacker’s onion address and froze trading two minutes later through an emergency client update.

The company said the attack did not breach RetoSwap’s own infrastructure. Instead, hackers exploited a weakness inside Haveno’s trading protocol. According to RetoSwap, the incident mainly affected large crypto trades, while fiat transactions remained unaffected. The platform has since paused operations as developers investigate the flaw and work on a security patch.

Today at 2:31 UTC Haveno lead developer woodser reported the Haveno trade protocol is actively being exploited.

At 2:33 UTC RetoSwap banned the exploiters onion address and halt trading by setting the minimum client version to 2.0.0 using the filter feature.

— RetoSwap (@RetoSwap) May 20, 2026

Exploit targeted haveno multisig process

RetoSwap later detailed how attackers carried out the exploit, saying they interfered with Haveno’s trade messaging system during active transactions. The flaw allowed attackers to pose as an arbitrator before funds entered a multisignature wallet, which created a pathway for unauthorized control during trades.

Per woodser, “here’s how the exploit worked: when the attacker took a trade, they sent a fake, out-of-order ACK message impersonating the arbitrator, causing the software to update the arbitrator’s node address to their own, allowing them to create a compromised multisig wallet before funds were deposited”.

Later the same day, RetoSwap told users to immediately back up wallet files in case recovery efforts become possible. The platform shared backup steps for Linux, macOS, and Windows systems and also pointed users to Haveno’s built-in backup tool. Additionally, it urged users to act quickly to secure local data.

If you have been affected by today's incident please back up the following folder ASAP and keep it safe. It will be required for potential recovery plans:

Linux: ~/.local/share/Haveno-reto/xmr_mainnet/wallet
macOS: ~/Library/Application Support/Haveno-reto/xmr_mainnet/wallet…

— RetoSwap (@RetoSwap) May 20, 2026

RetoSwap runs as a peer-to-peer trading platform that uses Tor and the Haveno protocol. It does not hold user funds, since traders operate directly from local wallets instead of depositing assets into centralized accounts. The platform supports Monero, Bitcoin, Ethereum, Litecoin, Bitcoin Cash, and several stablecoins across Ethereum and Tron networks.

Bridge exploits continue across crypto

The RetoSwap exploit comes amid a wider wave of security failures across decentralized finance systems. Besides RetoSwap, MAP Protocol and ButterNetwork also reported a bridge attack involving nearly 1 quadrillion fake MAPO tokens. Blockchain security firm Blockaid linked the incident to weaknesses in bridge message verification systems.

Meanwhile, Echo Protocol said it regained control of an admin key after attackers minted about $816,000 worth of unauthorized eBTC tokens. The project paused parts of its cross-chain operations while it reviewed access controls and contract security.

According to blockchain security firm PeckShield, hackers have stolen roughly $328.6 million from bridge-related exploits in 2026 alone. The rising losses highlight ongoing weaknesses in cross-chain infrastructure, where small security gaps continue to trigger large-scale fund drains.

Also Read: Binance Says India Has No Law Restricting Crypto Withdrawals

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto HackDecentralized Exchange
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Divya Mistry - Content Editor at The Crypto Times
By Divya Mistry
Follow:
Divya Mistry is a Content Editor with over 9 years of experience in news, PR, marketing, and research. Armed with a Master’s Degree in English Literature from the University of Mumbai, she specializes in crafting and refining long-form content across digital and print platforms. Over the years, Divya has contributed to and shaped content for leading brands across a range of industries, including real estate, healthcare, vertical transport, entertainment, lifestyle, education, EdTech, tech, and finance. Her research work has been featured on platforms like DNA India, Forbes, and Elevator World India. She now brings her editorial and research skills to explore the rapidly evolving world of cryptocurrency.

Latest News

Bipartisan PARITY Act Seeks Major Overhaul of US Crypto Tax Rules
Bipartisan PARITY Act Seeks Major Overhaul of US Crypto Tax Rules
CJP Token Rockets 400% on Pump.fun as 'Cockroach Janta Party' Viral Satire Captures Gen-Z Attention
CJP Token Rockets 400% on Pump.fun as ‘Cockroach Janta Party’ Viral Satire Captures Gen-Z Attention
SEC Delays Novel Crypto ETF Launches as Regulatory Review Expands
SEC Delays Novel Crypto ETF Launches as Regulatory Review Expands
Elon Musk’s SpaceX IPO Filing 18,712 BTC Treasury Worth $1.45B, Unchanged Since 2024
Elon Musk’s SpaceX IPO Filing: 18,712 BTC Treasury Worth $1.45B, Unchanged Since 2024
Syndicate Labs Shuts Down as Rollup Market Loses Steam
Syndicate Labs Shuts Down as Rollup Market Loses Steam

Find Us on Socials

You may also like

MAP Bridge Exploit 1 Quadrillion MAPO Minted in Cross-Chain Attack

MAP Bridge Exploit: 1 Quadrillion MAPO Minted in Cross-Chain Attack

$6.7M Stolen From Kraken and Coinbase User, Funds Mixed On-Chain

$6.7M Stolen From Kraken and Coinbase User, Funds Mixed On-Chain

Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets

Bankr Breach Exposes AI Crypto Wallet After Attacker Accessed 14 Wallets

GitHub Investigates Internal Repo Breach Tied to Poisoned VS Code Task

GitHub Investigates Internal Repo Breach Tied to Poisoned VS Code Task

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information