Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In November 2019, modified Monero command-line (CLI) wallet binaries were served through an official download path. The project warned downloaders to verify their files, delete any that failed the hash check, download clean copies, and never run the compromised binaries. The incident affected CLI wallet downloads; the public record does not establish the compromise method, the total number of affected downloads, or the full amount stolen.

What happened to Monero’s wallet downloads?

On November 19, 2019, Monero community member ErCiccione posted an official warning that an investigation had found compromised CLI wallet binaries being served from a download source. The announcement said the issue had been fixed and downloads were being served from another source. It warned that anyone who downloaded the CLI wallet during the specified period should check the file hashes, delete any mismatching binaries, and download again. ErCiccione wrote: “Do not run the compromised binaries for any reason.” Read the official warning.

This was a software supply-chain incident: users seeking the wallet software could receive altered binaries in place of the expected release. The sources identify the CLI wallet binaries as affected. They do not establish that Monero’s graphical user interface (GUI) wallet was compromised.

Why are there two different time windows?

The warning gave users a broad interval to check: downloads made from November 18, 2019, at 02:30 through 16:30 UTC. That was a precautionary check window, not a finding that malicious binaries were served continuously for 14 hours.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Trezor Safe 3 Crypto Hardware Wallet with Secure Element
  • Unparalleled Security: Protect your assets NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency
  • Simple & Secure Interface: Manage your digital assets easily with a clear OLED screen for secure on-device confirmations
  • Supports 1000s of Coins & Tokens: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet
  • Effortless Asset Management: Monitor and transact seamlessly with Trezor Suite, our intuitive desktop and mobile app
  • Enhanced Backup Solution: Rest assured with Multi-share Backup, eliminating single points of failure for secure cold wallet recovery

Notes from Monero’s November 23 community meeting describe a shorter estimated exposure period. They record the last file-integrity monitor entry at 16:04 UTC, a GitHub issue at 16:21, notification to site administrators at 16:30, and failover to a backup source at 16:40. Participants characterized approximately 35 minutes as the maximum period during which malicious binaries could have been served. The notes also say CDN binaries were not affected and describe the direct source as the fallback. Read the meeting log.

What did the malware do, and what losses were reported?

CERT-EU’s November 26, 2019 memo described added code designed to steal cryptocurrency. The Monero meeting notes refer to analyses that characterized it as a simple coin stealer. CERT-EU relayed a report that at least one user lost about $7,000; that figure is a reported user claim, not a verified total for the incident. The available sources do not establish a complete victim count or aggregate loss. Read CERT-EU’s memo.

Rank #2
Sale
Cold Wallet Crypto with 2-of-3 Recovery Double Safety Design, Offline NFC Hardware Wallet for Bitcoin& 2,800+ Tokens, Trade Anywhere &Anytime, 3 pack by Safnect
  • 【Military‑grade EAL6+ security&Easy to Use】Safnect crypto wallet eatures the top-tier EAL6+ security technology and a sealed secure-element chip — No Bluetooth. No Wi‑Fi. No battery. No seed phrase to manage. Your cryptocurrencies stay strongly protected from online attackers, it is immune to remote hacks and effortless for first-time users.
  • 【3-Pack Backup = Double Secure】This 100% offline hardware wallet not just a 3‑pack. It's a breakthrough in key management.You can store these three cold crypto wallets in separate locations for safer, decentralized asset protection.
  • 【Instant Tap Connection&Friendly for Begginer】Simply tap the crypto wallet card against your mobile device to pair with the Safnect App in seconds. Effortlessly buy, sell and transfer crypto assets safely through the app. Experience the fast convenience of a hot wallet, paired with the robust security of genuine cold storage.
  • 【Multi-Chain & Multi-Account Management】 The Safnect cold crypto wallet seamlessly manages Bitcoin, Ethereum, Solana, and over 2,800 tokens across 54+ mainstream blockchains, giving you complete multi-chain and multi-account control.You can buy, sell, swap, stake, and spend cryptocurrency directly any time any way.
  • 【Basically Indestructible&Easy to Carry】Only 2 mm thin with a credit-card sized design, this crypto wallet features IP66 waterproofing and bend-resistant construction. If you're a crypto holder who travels for work or just moves around a lot, you already know the struggle: Safnect crypto wallet that actually fits your life.

The meeting notes mention fewer than 10 wallet downloads per hour from the direct source after failover. That is an observed post-failover download rate, not a count of malicious downloads or affected users.

How was the download path compromised?

The public accounts do not establish how the attackers gained access to the server or download path. The November 23 meeting record says participants could not yet explain how the website had been compromised and that security professionals were investigating. CERT-EU likewise said the method was unclear. Claims of a particular exploit, stolen credentials, or other specific access route go beyond what these sources confirm.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to verify a Monero download

Monero’s binary-verification guide says to verify a download before extracting or using it. Its process checks both authenticity and integrity: confirm the maintainer’s public-key fingerprint, verify the signature on the published hash list, then calculate the SHA-256 hash of the downloaded archive and compare it with the entry for the exact filename. The guide says core developers sign the hash list and identifies binaryFate as a release signer. Check Monero’s current verification guide for live key and release details; those details can change.

  1. Confirm the signing key. Import the maintainer’s public key and compare its fingerprint against the value provided by Monero through its official documentation.
  2. Verify the signed hash list. Check the signature on Monero’s published hash list using that key. A hash list is useful only if its authenticity is verified.
  3. Hash the exact downloaded archive. Calculate its SHA-256 value and compare it with the signed list entry matching the downloaded filename.
  4. Stop if anything differs. Do not extract or run a file whose signature, filename, or hash does not check out; investigate and obtain a fresh copy from an official source.

A matching hash by itself confirms that a file matches the listed value; verifying the signed list is what helps establish that the expected value came from an authentic release source.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.