T
iTokenly

RetoSwap hack — May 2026

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident(approximate)
Publicly disclosedMay 21, 2026
Target typeDecentralised exchange
Loss$2,700,000Price at time of incident
MethodAccess control flawHaveno trades settle through a 2-of-3 multisig whose third key belongs to an arbitrator. The attacker sent a forged, out-of-order acknowledgement (ACK) message appearing to originate from the arbitrator; the client accepted it and updated the arbitrator's node address to one the attacker controlled, so the multisig wallet was created with the attacker holding a key before either counterparty deposited funds.
ChainsOther
OutcomeUnresolved

What happened

On 20 May 2026 RetoSwap, a peer-to-peer Monero exchange, lost about 7,000 XMR, roughly $2.7 million, to an attack on the Haveno trading protocol it is built on rather than on RetoSwap's own infrastructure.

Haveno trades settle through a 2-of-3 multisig wallet whose third key belongs to an arbitrator. According to Haveno lead developer woodser, when the attacker took a trade they sent a forged, out-of-order acknowledgement message that appeared to come from the arbitrator. The client accepted it and updated the arbitrator's node address to one the attacker controlled, so the multisig wallet was created with the attacker already holding a key, before either side deposited funds. Halborn describes the same sequence as an authentication flaw in the trade protocol rather than a coding defect, and the vulnerable message handling is reported to have been present since a March 2025 commit.

woodser reported active exploitation at 02:31 UTC; RetoSwap halted trading two minutes later by raising the minimum client version to 2.0.0, and blocked the attacker's onion address. The losses were concentrated in large crypto-to-crypto offers, with fiat trades unaffected. Because the proceeds are in Monero they cannot be traced or frozen, and none have been recovered.

The date is reported inconsistently: contemporaneous trackers and technical analyses put the exploit on 20 May 2026, while The Crypto Times published its account on 21 May. A second and separate RetoSwap incident followed on 16 June 2026, in which an attacker abused forced arbitration to release XMR without sending the corresponding BTC. RetoSwap again suspended trading; losses from that event were described as limited and have not been quantified. The $2.7 million figure belongs to the May ACK attack, not the June one.

Sources

  1. The Crypto TimesSecondary · retrieved 2026-08-01
  2. HalbornSecondary · retrieved 2026-08-01
  3. Web3 Is Going GreatAggregator · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "RetoSwap hack — May 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/retoswap
https://itokenly.com/hacks/retoswap

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.