$2.7M Drained: How One Unaudited Dependency Hacked RetoSwap Users Who Did Everything Right

You didn't get hacked.
Your protocol did.
How one unaudited dependency drained $2.7M from users who did everything right
On May 21, 2026, RetoSwap users woke up to find 7,000 XMR missing — roughly $2.7 million — drained through a vulnerability nobody in their codebase wrote, and nobody on their team had touched.
The numbers:
$2.7M stolen in a single exploit
7,000 XMR drained from user funds
Haveno protocol the origin of the breach
The attacker didn’t go through RetoSwap. They went through Haveno — the open-source trading protocol that RetoSwap is forked from. One compromised upstream dependency. One exploited pathway in the multisig settlement layer. And then silence, because this is Monero: irreversible, untraceable by design.
RetoSwap reacted fast. They blocked the attacker’s onion address, froze trading via client version restrictions, and confirmed clearly: their own infrastructure was not directly breached. Technically, that’s accurate. But accuracy doesn’t restore funds.
What the attack actually tells you about risk
Only crypto-to-crypto trades were hit. Fiat settlements were untouched. That’s not a coincidence — it means the attacker mapped the protocol’s architecture, identified the specific pathway that handled large-volume crypto swaps, and aimed precisely there. This wasn’t opportunistic. It was deliberate.
And it could have happened to any fork of Haveno. RetoSwap didn’t write the vulnerable code. They inherited it — the way every forked project inherits the bugs, the blind spots, and the unaudited corners of whatever they built on top of.
“Your security is only as strong as the least-audited line in your dependency chain.”
Recovery options are still being evaluated. But in the XMR ecosystem, “evaluating recovery” is mostly a formality. The privacy that makes Monero valuable makes stolen Monero nearly impossible to trace or recover. PeckShield flagged the incident. The funds are already gone.
The lesson nobody wants to hear
The lesson isn’t “don’t use DEXs.” The lesson is simpler: know exactly what your swap platform is built on, and whether that foundation has ever been audited.
Not every non-custodial exchange carries the same risk profile. Some operate on purpose-built infrastructure with independent security reviews. Some are forks of forks of community-maintained code that nobody has properly stress-tested since 2023.
The price difference between them isn’t always visible in the UI. The difference in what happens during an exploit is.
Swap privately on infrastructure you can trust
Xgram.io — wallet-to-wallet, no KYC, best rates on BTC/XMR and 500+ pairs. → xgram.io
Private crypto swaps
Best rates. Secure. Wallet to wallet
