xmr.club
EN 中文 ES RU
★ FRONT-PAGECOllie Swap— Anonymous Tor-only swap for BTC, BCH, DASH, LTC, XMR — no accounts, own liquidity, PGP-verified operator identity.
/exchanges · 已驗證 2026-07-30

OpenMonero

F

Agoradesk 分支 —— 點對點市集,買賣 XMR,賣方自託管結算。提供 Tor 與 I2P 鏡像。2026 年 5 月發生漏洞事件;運營方正在退款給受影響使用者。

事件時間線

  1. 2026-05-21 Prior exploit (~40 XMR); operator later claimed all affected users were fully refunded.
  2. 2026-06-08 Operator posted an "OpenMonero is Back" announcement following the May incident.
  3. 2026-06-10 OrangeFren publicly reported "hacked again, 200 XMR stolen" (citing an OpenMonero Telegram screenshot). Downgraded to D.
  4. 2026-06-11 Operator has not confirmed the 06-08 incident. Some claim a negative-trade-amount input bug, others call it a rug — unverified. Treat funds as at-risk pending a verifiable post-mortem.
  5. 2026-06-25auto Within the last 7 days, OpenMonero's operator issued a post-breach remediation notice (tracked by kycnot.me ~10h before this scan, source: openmonero.com): all user 2FA tokens were reset, users were told to change passwords and settlement wallet addresses, April 12-May 22 registrants were asked to file support ticke…
  6. 2026-06-28 Operator recovery post: "OpenMonero is back after 2 weeks of downtime." Security posture rebuilt — servers switched, new onion address generated, env vars and backup codes reset, full wallet isolation from the frontend, backend IP hidden. 90 XMR were refunded to affected users on 2026-06-24 (partial recovery vs. the ~200 XMR reported stolen by OrangeFren; not the full loss). No independent audit disclosed.
  7. 2026-07-07 Curator re-verified: clearnet homepage carries an alert banner directing users registered Apr 12 – May 22 to open a support ticket, passwords in that window to be reset, OTP codes reset platform-wide (users must reactivate 2FA), and the new onion pinned. xmr.club rotated the tor field to the new onion address. Grade held at D — the 2026-06-28 recovery post reports 90 XMR refunded of a claimed ~200 XMR loss (partial, not full), and no public post-mortem or independent audit has been published. This is a resumption of service, not a rehabilitation of the trust track.
  8. 2026-07-24 New outage window. Operator posted an "API server under attack" banner on the website for ~17h then removed it with no follow-up statement. xmr.club chatbox users (registered handles 610fd67f, cd55da94) report they cannot withdraw from active trades and question whether this is turning into an exit scam. Operator X account (@OpenMonero) has posted nothing since 2026-06-08. No independent DDoS confirmation. Withdrawal status unverified. Grade reverted from the 2026-07-07 D → C lift back to D pending withdrawal-restoration confirmation from our own reader channel.
  9. 2026-07-25 24h re-check on 2026-07-24 outage escalated to full compromise incident. kycnot.me published a critical advisory (2026-07-24) based on a Monero Matrix Channel disclosure: "By executing a single GET request, an attacker could gain full access to the oldest existing user account on OpenMonero. This broken endpoint allowed taking over all other accounts on a sequential basis—from oldest to newest. The user claims OpenMonero admins have chosen to remain silent on the issue and are actively ignoring a similar unpatched vulnerability, leading to user accounts getting drained and their full trading history getting leaked. Other sensitive data such as shipping addresses and private chat logs is also believed to have been compromised." (source: https://kycnot.me/service/openmonero, cite: xcancel.com/monerobull/status/2080627692773282014). Operator X account (@OpenMonero) still silent since 2026-06-08 — no acknowledgement of the API vulnerability, no post-mortem, no user notification. Chat context on xmr.club chatbox (handles 610fd67f, cd55da94) reporting frozen trades from 2026-07-23/24 is now recontextualised as consistent with the API-endpoint compromise. Grade escalated D → F. Tagline updated. Recommendation now unambiguous: do not deposit; withdraw anything still accessible; treat trading history / shipping-address / chat-log data as exfiltrated. Prior lift path (post-mortem + independent audit + no-incident window) is now blocked by the data-leak class — even a full post-mortem cannot un-leak exfiltrated data. No further wake scheduled — grade is stable at F pending an operator response that would meaningfully change the picture.
  10. 2026-07-30 THIRD documented exploit. OpenMonero posted an update (surfaced 2026-07-30 via OrangeFren + Dark Web Informer on X) claiming another **399 XMR drain** (~$60k+ at current prices) attributed to "a zero-day vulnerability that had been hiding since the start of the project." OrangeFren's public reaction: "I lost track how many times they claimed to have been exploited at this point." Combined pattern now on record: (a) 2025-06 first drain (~90 XMR, later claimed fully refunded); (b) 2026-06 second drain (~200 XMR reported, only ~90 XMR refunded per operator recovery post); (c) 2026-07 API-endpoint sequential-account-takeover exploit reported by kycnot 2026-07-24; (d) 2026-07-30 third drain of 399 XMR now announced. Grade held at F (no lower tier). No wake reschedule — the incident record now speaks for itself. Reader takeaway: repeated-exploit pattern with each event framed as a fresh "zero-day" makes competence claims unfalsifiable; the operational security track record is broken. Community sentiment reflected in our own X: "Just forget about them already."

一覽

等級
F ()
KYC 立場
無 KYC · 匿名註冊
手續費
費率結構承自 Agoradesk 分支 —— 買方端有少量每筆交易費;賣方免費上架。可選付費置頂並不激進。
最後驗證
2026-07-30
營運起始
2024 · 2y — WHOIS 2024 predates archive.org first snapshot 2018; treated as current-entity year (domain may have been re-registered)
Tor 鏡像
http://hj63yzwjqumozyt34dohknaadyp7p5ilcb32d67al2jpc2b3vs2b6uad.onion
I2P 鏡像
http://sex2vkgaeigmgk5dou4pw4uegokxnc3k3vksotlmyldmual5guyq.b32.i2p
事件
⚠ 活躍自 2026-06-08 — /incidents

評測

Agoradesk 分支,為賣家提供自主託管交易結算,並在原版基礎上進行了多項隱私升級(Session 通知、可自毀聊天記錄等)。P2P 市場模式:買賣雙方發布報價,站內聊天處理協商,付款 + 交付以點對點方式安排。支援的付款方式包括 PayPal、信用卡/金融卡、銀行轉帳、禮品卡、現金郵寄、BTC、Venmo 等。

鏡像站: 明網 openmonero.com、Tor 洋蔥 (`fgssv2btn4…njev6sjbyd.onion`)、I2P (`sex2vkgaei…ual5guyq.b32.i2p`)。對於受限網路中的使用者,可及性很重要。

匿名註冊。 無 KYC,無政府證件。帳號創建只需使用者名稱 + 密碼。每位賣家的聲譽隨交易累積,是信任機制。

2026 年 5 月事件(已確認)。 OrangeFren 於 2026-05-21 報導:「OpenMonero 在 RetoSwap 用戶因平台漏洞損失近 $3M 的次日再次遭到攻擊。OpenMonero 用戶損失未知。」OpenMonero 回應:「此問題現已修復,一切恢復正常,所有受害者將於下週前獲得退款。」一篇 KYCnot 文章獨立引用約 40 XMR,但運營商尚未公布確認的損失數字。編輯方對退款完成情況的驗證仍在進行中。本目錄對此類事件嚴肅看待 — 非託管設計是緩衝,但針對平台本身的攻擊仍然暴露真實風險;回應方式(承認 + 退款承諾)是決定評級的關鍵。

評級 B(事件後)。 維持 B 而非 A,原因是退款週期未閉環 + KYCnot 上 18 條用戶評分平均 3.2/5(有部分營運摩擦回報)。Agoradesk 血統 + Tor + I2P + 自主託管設計 + 透明的事件回應,使其仍是 P2P XMR 交易的重要選項。與 XMRBazaar 搭配使用 — 兩者皆為非託管、皆為 XMR 原生、皆為 Monero 點對點基礎設施的基石。

適用場景:

  • 您想用現金 / 法幣 / 不常見的支付管道(PayPal、禮品卡、Venmo)購買 XMR
  • 您需要可透過 Tor 或 I2P 訪問的交易介面
  • 您願意在放大交易規模前先以小額交易驗證賣家

注意事項:

  • 近期發生平台級漏洞(2026 年 5 月)。運營商回應方向正確;編輯尚未驗證全額退款是否完成。
  • KYCnot 上 18 條用戶評分平均 3.2/5 — 存在實際營運摩擦
  • P2P 自我防護適用:先小額試單、驗證賣家聲譽和溝通品質、必要時透過站內爭議管道升級

手續費

費率結構承自 Agoradesk 分支 —— 買方端有少量每筆交易費;賣方免費上架。可選付費置頂並不激進。

即時運營數據

kyc.rip 尚未透過 OpenMonero 路由兌換,因此我們沒有其第一手的結算數據(XMR 一般結算、慢尾、確認數)。

運營方?申請接入: @kyc_rip_bot

接入狀態不影響此服務商的評級或評測。

連結

稽核軌跡 — 編輯主張的收據

  • UPSTREAM 正常 · HTTP 200 · 472ms · 檢查於 7h ago
  • ONION 與營運方公布相符 hj63yzwjqumozyt34dohknaadyp7p5ilcb32d67al2jpc2b3vs2b6uad.onion
  • MANUAL 最後手動驗證 2026-07-30 (<30d)

評論 — 已審核 · 規則

尚無社群評論。當第一個。

新增評論

歡迎誠實、中立的回饋。策展人審核後才會顯示。不需 JS。

必填:評論內容。誠實、具描述性的評論一天內核可。行銷文案、辱罵或攻擊會被退件。每 IP 每日上限 5 筆。