xmrwalletScam (OP)
Newbie
Offline
Activity: 1
Merit: 0
|
 |
May 09, 2024, 07:24:51 AM |
|
There's this long-running Monero web wallet xmrwallet.com
They claim to be client-side JS, which is true, and the keys are generated on client-side, but the issue is that if you check the network tab of your browser and observe the requests made to the server-side PHPs after creating a wallet you'll notice that in first or second periodic balance calls on the dashboard page it'll include a mysterious field named `data`. Value of this field includes your private key with a thin obfuscation. This field stops existing in any subsequent requests.
Unsurprisingly enough the web is full of people claiming to have lost their XMR from addresses generated and used in this web wallet, in way higher proportion than any legit wallet.
Also the owner is using an obviously fake persona, doesn't take genius to see that.
It's quite sad to think that this person has probably stolen more than few million dollars since starting operating 6 years ago, just by wrapping official Monero software behind their PHP and throwing together few novicely-written JS scripts and a dumb landing page.
|
|
|
|
|
|
|
JeromeTash
Legendary
Offline
Activity: 2744
Merit: 1438
Heisenberg
|
 |
May 10, 2024, 09:46:07 PM |
|
I don't know about programming and code, but when I checked their repository on GitHub. I don't to see any open ior closed ssue talking about the vulnerability or stealing off private keys. Don't you think it would be a good thing to open up an issue about it over there for all to see? https://github.com/XMRWallet/Website/issues
|
|
|
|
BitcoinGirl.Club
Legendary
Offline
Activity: 3234
Merit: 2837
The voice of the community w/o a gang
|
 |
May 11, 2024, 01:56:51 PM |
|
Unsurprisingly enough the web is full of people claiming to have lost their XMR from addresses generated and used in this web wallet, in way higher proportion than any legit wallet.
Can you bring some of the posts from the web so that we know some victims. Losing a coin from any wallet mostly users fault. Even after more than a decade, still a majority of the crypto users do not know the usual practices of securing their wallet. I have know people who kept their backup on Google Drive.
|
| . BC.GAME | ███████████████ ███████████████ ███████████████ ███████████████ ██████▀░▀██████ ████▀░░░░░▀████ ███░░░░░░░░░███ ███▄░░▄░▄░░▄███ █████▀░░░▀█████ ███████████████ ███████████████ ███████████████ ███████████████ | ███████████████ ███████████████ ███████████████ ███████████████ ███░░▀░░░▀░░███ ███░░▄▄▄░░▄████ ███▄▄█▀░░▄█████ █████▀░░▐██████ █████░░░░██████ ███████████████ ███████████████ ███████████████ ███████████████ | ███████████████ ███████████████ ███████████████ ███████████████ ██████▀▀░▀▄░███ ████▀░░▄░▄░▀███ ███▀░░▀▄▀▄░▄███ ███▄░░▀░▀░▄████ ███░▀▄░▄▄██████ ███████████████ ███████████████ ███████████████ ███████████████ | │ │ | DEPOSIT BONUS .1000%. | GET FREE ...5 BTC... | │ │ | REFER & EARN ..$1000 + 15%.. COMMISSION | │ │ | Play Now |
|
|
|
PX-Z
Legendary
Offline
Activity: 2044
Merit: 1253
Wallet transaction notifier @txnNotifierBot
|
 |
May 11, 2024, 11:59:24 PM Last edit: May 12, 2024, 01:31:05 AM by PX-Z |
|
That's fuck up, they are running 6 years already and no one noticed this. Their source code is in github but no one knows if its fully open source or only partial. Edit: I checked the website, OP is talking right with data request to /getbalance.php in the /app.js, but you can't read the actual code because it's been obfuscate and i checked the github repo and there's no /getbalance.php file. Here's the data request on /getbalance.php
|
|
|
|
|
|
| . betpanda.io | │ |
ANONYMOUS & INSTANT .......ONLINE CASINO....... | │ | ▄███████████████████████▄ █████████████████████████ █████████████████████████ ████████▀▀▀▀▀▀███████████ ████▀▀▀█░▀▀░░░░░░▄███████ ████░▄▄█▄▄▀█▄░░░█▄░▄█████ ████▀██▀░▄█▀░░░█▀░░██████ ██████░░▄▀░░░░▐░░░▐█▄████ ██████▄▄█░▀▀░░░█▄▄▄██████ █████████████████████████ █████████████████████████ █████████████████████████ ▀███████████████████████▀ | ▄███████████████████████▄ █████████████████████████ ██████████▀░░░▀██████████ █████████░░░░░░░█████████ ████████░░░░░░░░░████████ ████████░░░░░░░░░████████ █████████▄░░░░░▄█████████ ███████▀▀▀█▄▄▄█▀▀▀███████ ██████░░░░▄░▄░▄░░░░██████ ██████░░░░█▀█▀█░░░░██████ ██████░░░░░░░░░░░░░██████ █████████████████████████ ▀███████████████████████▀ | ▄███████████████████████▄ █████████████████████████ ██████████▀▀▀▀▀▀█████████ ███████▀▀░░░░░░░░░███████ ██████▀░░░░░░░░░░░░▀█████ ██████░░░░░░░░░░░░░░▀████ ██████▄░░░░░░▄▄░░░░░░████ ████▀▀▀▀▀░░░█░░█░░░░░████ ████░▀░▀░░░░░▀▀░░░░░█████ ████░▀░▀▄░░░░░░▄▄▄▄██████ █████░▀░█████████████████ █████████████████████████ ▀███████████████████████▀ | .
SLOT GAMES ....SPORTS.... LIVE CASINO | │ | ▄░░▄█▄░░▄ ▀█▀░▄▀▄░▀█▀ ▄▄▄▄▄▄▄▄▄▄▄ █████████████ █░░░░░░░░░░░█ █████████████ ▄▀▄██▀▄▄▄▄▄███▄▀▄ ▄▀▄██▄███▄█▄██▄▀▄ ▄▀▄█▐▐▌███▐▐▌█▄▀▄ ▄▀▄██▀█████▀██▄▀▄ ▄▀▄█████▀▄████▄▀▄ ▀▄▀▄▀█████▀▄▀▄▀ ▀▀▀▄█▀█▄▀▄▀▀ | Regional Sponsor of the Argentina National Team |
|
|
|
owlcatz
Legendary
Offline
Activity: 4186
Merit: 2030
|
 |
May 12, 2024, 12:14:49 AM |
|
That's fuck up, they are running 6 years already and no one noticed this. Their source code is in github but no one knows if its fully open source or only partial.
Until this user posts some actual evidence, I'm not one to say. It's been out there a while, so yeah it's technically open source, but can you understand it? Maybe this is it? https://github.com/XMRWallet/Website/blob/master/src/js/monero.js#L3755
|
|
|
|
|
PX-Z
Legendary
Offline
Activity: 2044
Merit: 1253
Wallet transaction notifier @txnNotifierBot
|
 |
May 12, 2024, 01:30:54 AM |
|
That's fuck up, they are running 6 years already and no one noticed this. Their source code is in github but no one knows if its fully open source or only partial.
Until this user posts some actual evidence, I'm not one to say. It's been out there a while, so yeah it's technically open source, but can you understand it? Maybe this is it? https://github.com/XMRWallet/Website/blob/master/src/js/monero.js#L3755The monero.js is an open source made by others to create a wallet and other monero-related stuff. I have edited my post above upon checking the website. Other files were not existing in the repo. So it's good to say that the project is not fully open source in my POV as i can't read the /app.js as it's obsfucated, especially the POST data requests.
|
|
|
|
|
|
| . betpanda.io | │ |
ANONYMOUS & INSTANT .......ONLINE CASINO....... | │ | ▄███████████████████████▄ █████████████████████████ █████████████████████████ ████████▀▀▀▀▀▀███████████ ████▀▀▀█░▀▀░░░░░░▄███████ ████░▄▄█▄▄▀█▄░░░█▄░▄█████ ████▀██▀░▄█▀░░░█▀░░██████ ██████░░▄▀░░░░▐░░░▐█▄████ ██████▄▄█░▀▀░░░█▄▄▄██████ █████████████████████████ █████████████████████████ █████████████████████████ ▀███████████████████████▀ | ▄███████████████████████▄ █████████████████████████ ██████████▀░░░▀██████████ █████████░░░░░░░█████████ ████████░░░░░░░░░████████ ████████░░░░░░░░░████████ █████████▄░░░░░▄█████████ ███████▀▀▀█▄▄▄█▀▀▀███████ ██████░░░░▄░▄░▄░░░░██████ ██████░░░░█▀█▀█░░░░██████ ██████░░░░░░░░░░░░░██████ █████████████████████████ ▀███████████████████████▀ | ▄███████████████████████▄ █████████████████████████ ██████████▀▀▀▀▀▀█████████ ███████▀▀░░░░░░░░░███████ ██████▀░░░░░░░░░░░░▀█████ ██████░░░░░░░░░░░░░░▀████ ██████▄░░░░░░▄▄░░░░░░████ ████▀▀▀▀▀░░░█░░█░░░░░████ ████░▀░▀░░░░░▀▀░░░░░█████ ████░▀░▀▄░░░░░░▄▄▄▄██████ █████░▀░█████████████████ █████████████████████████ ▀███████████████████████▀ | .
SLOT GAMES ....SPORTS.... LIVE CASINO | │ | ▄░░▄█▄░░▄ ▀█▀░▄▀▄░▀█▀ ▄▄▄▄▄▄▄▄▄▄▄ █████████████ █░░░░░░░░░░░█ █████████████ ▄▀▄██▀▄▄▄▄▄███▄▀▄ ▄▀▄██▄███▄█▄██▄▀▄ ▄▀▄█▐▐▌███▐▐▌█▄▀▄ ▄▀▄██▀█████▀██▄▀▄ ▄▀▄█████▀▄████▄▀▄ ▀▄▀▄▀█████▀▄▀▄▀ ▀▀▀▄█▀█▄▀▄▀▀ | Regional Sponsor of the Argentina National Team |
|
|
|
NotATether
Legendary
Offline
Activity: 2198
Merit: 9218
Trêvoid █ No KYC-AML Crypto Swaps
|
 |
May 12, 2024, 04:38:51 PM |
|
Here's the data request on /getbalance.php That's base64 encoding. Can someone try to base64decode it and post the output here (in hex, if it is binary)?
|
|
|
|
|
|
| . betpanda.io | │ |
ANONYMOUS & INSTANT .......ONLINE CASINO....... | │ | ▄███████████████████████▄ █████████████████████████ █████████████████████████ ████████▀▀▀▀▀▀███████████ ████▀▀▀█░▀▀░░░░░░▄███████ ████░▄▄█▄▄▀█▄░░░█▄░▄█████ ████▀██▀░▄█▀░░░█▀░░██████ ██████░░▄▀░░░░▐░░░▐█▄████ ██████▄▄█░▀▀░░░█▄▄▄██████ █████████████████████████ █████████████████████████ █████████████████████████ ▀███████████████████████▀ | ▄███████████████████████▄ █████████████████████████ ██████████▀░░░▀██████████ █████████░░░░░░░█████████ ████████░░░░░░░░░████████ ████████░░░░░░░░░████████ █████████▄░░░░░▄█████████ ███████▀▀▀█▄▄▄█▀▀▀███████ ██████░░░░▄░▄░▄░░░░██████ ██████░░░░█▀█▀█░░░░██████ ██████░░░░░░░░░░░░░██████ █████████████████████████ ▀███████████████████████▀ | ▄███████████████████████▄ █████████████████████████ ██████████▀▀▀▀▀▀█████████ ███████▀▀░░░░░░░░░███████ ██████▀░░░░░░░░░░░░▀█████ ██████░░░░░░░░░░░░░░▀████ ██████▄░░░░░░▄▄░░░░░░████ ████▀▀▀▀▀░░░█░░█░░░░░████ ████░▀░▀░░░░░▀▀░░░░░█████ ████░▀░▀▄░░░░░░▄▄▄▄██████ █████░▀░█████████████████ █████████████████████████ ▀███████████████████████▀ | .
SLOT GAMES ....SPORTS.... LIVE CASINO | │ | ▄░░▄█▄░░▄ ▀█▀░▄▀▄░▀█▀ ▄▄▄▄▄▄▄▄▄▄▄ █████████████ █░░░░░░░░░░░█ █████████████ ▄▀▄██▀▄▄▄▄▄███▄▀▄ ▄▀▄██▄███▄█▄██▄▀▄ ▄▀▄█▐▐▌███▐▐▌█▄▀▄ ▄▀▄██▀█████▀██▄▀▄ ▄▀▄█████▀▄████▄▀▄ ▀▄▀▄▀█████▀▄▀▄▀ ▀▀▀▄█▀█▄▀▄▀▀ | Regional Sponsor of the Argentina National Team |
|
|
|
jastigueta12
Newbie
Offline
Activity: 3
Merit: 0
|
 |
February 03, 2025, 01:20:14 PM |
|
There's this long-running Monero web wallet xmrwallet.com
They claim to be client-side JS, which is true, and the keys are generated on client-side, but the issue is that if you check the network tab of your browser and observe the requests made to the server-side PHPs after creating a wallet you'll notice that in first or second periodic balance calls on the dashboard page it'll include a mysterious field named `data`. Value of this field includes your private key with a thin obfuscation. This field stops existing in any subsequent requests.
Unsurprisingly enough the web is full of people claiming to have lost their XMR from addresses generated and used in this web wallet, in way higher proportion than any legit wallet.
Also the owner is using an obviously fake persona, doesn't take genius to see that.
It's quite sad to think that this person has probably stolen more than few million dollars since starting operating 6 years ago, just by wrapping official Monero software behind their PHP and throwing together few novicely-written JS scripts and a dumb landing page.
God why would I do that? i have been chronicling 8000 monero since 2017 and gave to this site... the jerks above githam nkiak is not affiliated with the site, thanks for your inaction and igshnor check reddit this site has stolen billions already, great community no one cares.
|
|
|
|
|
jastigueta12
Newbie
Offline
Activity: 3
Merit: 0
|
 |
February 03, 2025, 01:27:17 PM |
|
That's fuck up, they are running 6 years already and no one noticed this. Their source code is in github but no one knows if its fully open source or only partial.
Until this user posts some actual evidence, I'm not one to say. It's been out there a while, so yeah it's technically open source, but can you understand it? Maybe this is it? https://github.com/XMRWallet/Website/blob/master/src/js/monero.js#L3755The monero.js is an open source made by others to create a wallet and other monero-related stuff. I have edited my post above upon checking the website. Other files were not existing in the repo. So it's good to say that the project is not fully open source in my POV as i can't read the /app.js as it's obsfucated, especially the POST data requests. lol official xmr - not list this shit like official all internet in case about scam - they steal a lot of money an d good defend 5m+
|
|
|
|
|
|
|
|
|
|