Bitcoin Forum
February 20, 2026, 02:34:13 PM *
News: Community awards 2025
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: xmrwallet.com steals your private keys  (Read 277 times)
xmrwalletScam (OP)
Newbie
*
Offline Offline

Activity: 1
Merit: 0


View Profile
May 09, 2024, 07:24:51 AM
 #1

There's this long-running Monero web wallet xmrwallet.com

They claim to be client-side JS, which is true, and the keys are generated on client-side, but the issue is that if you check the network tab of your browser and observe the requests made to the server-side PHPs after creating a wallet you'll notice that in first or second periodic balance calls on the dashboard page it'll include a mysterious field named `data`. Value of this field includes your private key with a thin obfuscation. This field stops existing in any subsequent requests.

Unsurprisingly enough the web is full of people claiming to have lost their XMR from addresses generated and used in this web wallet, in way higher proportion than any legit wallet.

Also the owner is using an obviously fake persona, doesn't take genius to see that.

It's quite sad to think that this person has probably stolen more than few million dollars since starting operating 6 years ago, just by wrapping official Monero software behind their PHP and throwing together few novicely-written JS scripts and a dumb landing page.
owlcatz
Legendary
*
Offline Offline

Activity: 4228
Merit: 2031



View Profile
May 09, 2024, 11:21:32 PM
 #2

Interesting. Never heard of this. 6 years and its on github?

Can you show or tell me where in the tree this file that does this resides please?

https://github.com/XMRWallet/Website/tree/master/src/js

Thanks!
JeromeTash
Legendary
*
Offline Offline

Activity: 2800
Merit: 1454


Heisenberg


View Profile
May 10, 2024, 09:46:07 PM
 #3

I don't know about programming and code, but when I checked their repository on GitHub. I don't to see any open ior closed ssue talking about the vulnerability or stealing off private keys. Don't you think it would be a good thing to open up an issue about it over there for all to see?

https://github.com/XMRWallet/Website/issues

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
BitcoinGirl.Club
Legendary
*
Offline Offline

Activity: 3248
Merit: 2841


The voice of the community w/o a gang


View Profile WWW
May 11, 2024, 01:56:51 PM
 #4

Unsurprisingly enough the web is full of people claiming to have lost their XMR from addresses generated and used in this web wallet, in way higher proportion than any legit wallet.
Can you bring some of the posts from the web so that we know some victims. Losing a coin from any wallet mostly users fault. Even after more than a decade, still a majority of the crypto users do not know the usual practices of securing their wallet. I have know people who kept their backup on Google Drive.

▄███████████████████▄
████████████████████████

██████████▀▀▀▀██████████
███████████████▀▀███████
█████████▄▄███▄▄█████
████████▀▀████▀███████
█████████▄▄██▀██████████
████████████▄███████████
██████████████▄█████████
██████████▀▀███▀▀███████
███████████████████████
█████████▄▄████▄▄████████
▀███████████████████▀
.
 BC.GAME 
███████████████
███████████████
███████████████
███████████████
██████▀░▀██████
████▀░░░░░▀████
███░░░░░░░░░███
███▄░░▄░▄░░▄███
█████▀░░░▀█████

███████████████

███████████████

███████████████

███████████████
███████████████
███████████████
███████████████
███████████████
███░░▀░░░▀░░███
███░░▄▄▄░░▄████
███▄▄█▀░░▄█████
█████▀░░▐██████
█████░░░░██████

███████████████

███████████████

███████████████

███████████████
███████████████
███████████████
███████████████
███████████████
██████▀▀░▀▄░███
████▀░░▄░▄░▀███
███▀░░▀▄▀▄░▄███
███▄░░▀░▀░▄████
███░▀▄░▄▄██████

███████████████

███████████████

███████████████

███████████████

DEPOSIT BONUS
.1000%.
GET FREE
...5 BTC...

REFER & EARN
..$1000 + 15%..
COMMISSION


 Play Now 
PX-Z
Legendary
*
Offline Offline

Activity: 2100
Merit: 1283


Wallet Transaction Notifier - @txnNotifierBot


View Profile
May 11, 2024, 11:59:24 PM
Last edit: May 12, 2024, 01:31:05 AM by PX-Z
 #5

That's fuck up, they are running 6 years already and no one noticed this. Their source code is in github but no one knows if its fully open source or only partial.

Edit: I checked the website, OP is talking right with data request to /getbalance.php in the /app.js, but you can't read the actual code because it's been obfuscate and i checked the github repo and there's no /getbalance.php file.

Here's the data request on /getbalance.php



 
 b1exch.io 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
owlcatz
Legendary
*
Offline Offline

Activity: 4228
Merit: 2031



View Profile
May 12, 2024, 12:14:49 AM
 #6

That's fuck up, they are running 6 years already and no one noticed this. Their source code is in github but no one knows if its fully open source or only partial.

Until this user posts some actual evidence, I'm not one to say. It's been out there  a while, so yeah it's technically open source, but can you understand it?

Maybe this is it? Grin

https://github.com/XMRWallet/Website/blob/master/src/js/monero.js#L3755

PX-Z
Legendary
*
Offline Offline

Activity: 2100
Merit: 1283


Wallet Transaction Notifier - @txnNotifierBot


View Profile
May 12, 2024, 01:30:54 AM
 #7

That's fuck up, they are running 6 years already and no one noticed this. Their source code is in github but no one knows if its fully open source or only partial.

Until this user posts some actual evidence, I'm not one to say. It's been out there  a while, so yeah it's technically open source, but can you understand it?

Maybe this is it? Grin

https://github.com/XMRWallet/Website/blob/master/src/js/monero.js#L3755
The monero.js is an open source made by others to create a wallet and other monero-related stuff.

I have edited my post above upon checking the website. Other files were not existing in the repo. So it's good to say that the project is not fully open source in my POV as i can't read the /app.js as it's obsfucated, especially the POST data requests.

 
 b1exch.io 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
NotATether
Legendary
*
Offline Offline

Activity: 2254
Merit: 9507


Trêvoid █ No KYC-AML Crypto Swaps


View Profile WWW
May 12, 2024, 04:38:51 PM
 #8

Here's the data request on /getbalance.php


That's base64 encoding. Can someone try to base64decode it and post the output here (in hex, if it is binary)?

 
 b1exch.io 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
jastigueta12
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
February 03, 2025, 01:20:14 PM
 #9

There's this long-running Monero web wallet xmrwallet.com

They claim to be client-side JS, which is true, and the keys are generated on client-side, but the issue is that if you check the network tab of your browser and observe the requests made to the server-side PHPs after creating a wallet you'll notice that in first or second periodic balance calls on the dashboard page it'll include a mysterious field named `data`. Value of this field includes your private key with a thin obfuscation. This field stops existing in any subsequent requests.

Unsurprisingly enough the web is full of people claiming to have lost their XMR from addresses generated and used in this web wallet, in way higher proportion than any legit wallet.

Also the owner is using an obviously fake persona, doesn't take genius to see that.

It's quite sad to think that this person has probably stolen more than few million dollars since starting operating 6 years ago, just by wrapping official Monero software behind their PHP and throwing together few novicely-written JS scripts and a dumb landing page.

God why would I do that? i have been chronicling 8000 monero since 2017 and gave to this site... the jerks above githam nkiak is not affiliated with the site, thanks for your inaction and igshnor check reddit this site has stolen billions already, great community no one cares.
jastigueta12
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
February 03, 2025, 01:27:17 PM
 #10

That's fuck up, they are running 6 years already and no one noticed this. Their source code is in github but no one knows if its fully open source or only partial.

Until this user posts some actual evidence, I'm not one to say. It's been out there  a while, so yeah it's technically open source, but can you understand it?

Maybe this is it? Grin

https://github.com/XMRWallet/Website/blob/master/src/js/monero.js#L3755
The monero.js is an open source made by others to create a wallet and other monero-related stuff.

I have edited my post above upon checking the website. Other files were not existing in the repo. So it's good to say that the project is not fully open source in my POV as i can't read the /app.js as it's obsfucated, especially the POST data requests.

lol official xmr - not list this  shit like official all internet in case about scam - they steal a lot of money an d good defend 5m+
owlcatz
Legendary
*
Offline Offline

Activity: 4228
Merit: 2031



View Profile
February 03, 2025, 10:50:33 PM
 #11

lol official xmr - not list this  shit like official all internet in case about scam - they steal a lot of money an d good defend 5m+

https://www.getyarn.io/yarn-clip/ca56f96f-72cd-4846-960c-aba3d82dd776

I'm not sure what you're saying, can you be clearer please? I'll have a look at the site again as well as I've always found this interesting. Grin

Edit - their trustpilot looks good, and I see no scam accusations since 2020 out there?

https://www.trustpilot.com/review/www.xmrwallet.com
jastigueta12
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
February 05, 2025, 01:09:12 AM
 #12

https://github.com/uBlockOrigin/uAssets/discussions/25202

https://www.sitejabber.com/reviews/xmrwallet.com

https://web.archive.org/web/20240510154440/https://www.trustpilot.com/review/www.xmrwallet.com (we can see how they do real review - now its deleted buy there report) on githab same deleted all true

just seo and report do and stole millons on chain which cant trace  - deo + name of wallet = 6 fag profit

Don’t be naive. It’s not just about what’s on Trustpilot now. The history shows something completely different. Go check the web archive and see how they’ve cleaned up their reputation. The site has been flagged as a scam multiple times, and their GitHub activity shows they’re not open source as they claim. Open source wallets should generate private keys and seed phrases on the client side, not the server side – that’s basic knowledge, and it’s embarrassing not to understand this.

If you want to check, here are some links:

Reddit: XMRWallet Scam - https://www.reddit.com/r/Monero/comments/k0ytgq/statement_from_xmrwalletcom_about_recent_phishing/?rdt=60585
Reddit: XMRWallet Scam - https://www.reddit.com/r/Monero/comments/jh15e3/psa_xmrwalletcom_is_a_scam_who_steals_your_funds/
Scamadviser: XMRWallet Check - https://www.scamadviser.com/check-website/xmrwallet.com
Medium: XMRWallet Scam - https://medium.com/@mosheglasper/xmrwallet-scam-and-lier-5bf21f73f55c
Just be smarter, and don’t forget to Google and use archives to see the full picture. Scammers like this build their reputation on manipulation, not honesty.

Have you ever seen that the purse builds reputation not due to reputable audits, and at the expense of fake reviews and custom purchased articles with the mark (sponsored) funny Grin Grin Grin
phishdestroy
Newbie
*
Offline Offline

Activity: 2
Merit: 0


View Profile WWW
February 18, 2026, 04:13:14 PM
 #13

[SECURITY RESEARCH] www.xmrwallet.com — Confirmed Private Key Exfiltration | Seeking Affected Users
Our team has been tracking this service for some time. We focus on scam infrastructure analysis, threat attribution, and technical documentation. This is not a commercial effort — we publish findings publicly and work with affected parties only within a legitimate legal framework.
What we've confirmed so far:
This is not a case of poor security practice or an isolated bug. The evidence we've collected points to a systematic, intentional operation designed to harvest private view keys from every wallet opened through the service — including wallets created on the platform.
Our preliminary analysis covered:

Network traffic behavior and request structure
Private key handling and session token encoding
Infrastructure patterns and backend API design

Technical findings are documented publicly:
https://github.com/XMRWallet/Website/issues/36
https://github.com/XMRWallet/Website/issues/35
Current status:
We have partial attribution signals. We are not publishing them yet — doing so prematurely would compromise any chance of real accountability.
What we need:
Attribution alone is not actionable without victims willing to formally participate. If you used xmrwallet.com and experienced unexplained fund loss or suspicious activity, your cooperation would allow this investigation to move from analysis to enforcement.
Specifically useful:

Transaction history from the period of use
Wallet addresses used on the platform
Screenshots or logs if available
Willingness to engage with a legal process

Contact via this thread or privately. All communications handled confidentially.
We will continue publishing what can be verified publicly — regardless of whether anyone comes forward.

There's this long-running Monero web wallet xmrwallet.com

They claim to be client-side JS, which is true, and the keys are generated on client-side, but the issue is that if you check the network tab of your browser and observe the requests made to the server-side PHPs after creating a wallet you'll notice that in first or second periodic balance calls on the dashboard page it'll include a mysterious field named `data`. Value of this field includes your private key with a thin obfuscation. This field stops existing in any subsequent requests.

Unsurprisingly enough the web is full of people claiming to have lost their XMR from addresses generated and used in this web wallet, in way higher proportion than any legit wallet.

Also the owner is using an obviously fake persona, doesn't take genius to see that.

It's quite sad to think that this person has probably stolen more than few million dollars since starting operating 6 years ago, just by wrapping official Monero software behind their PHP and throwing together few novicely-written JS scripts and a dumb landing page.
JeromeTash
Legendary
*
Offline Offline

Activity: 2800
Merit: 1454


Heisenberg


View Profile
February 18, 2026, 09:19:42 PM
 #14

-snip-
I think what else should be done is to report the GitHub profile. GitHub has zero tolerance for malware and phishing sites. They will delete it as soon as possible. Also while the legal part is being worked on, reporting the domain too can help reduce on the scam if it get's flagged by the browsers or even taken down by the registrar

Quote
Domain: xmrwallet.com
Registered On: 2016-08-29
Expires On: 2031-08-29
Updated On: 2026-02-16
Status: client transfer prohibited
Name Servers: ns1.ddos-guard.net
ns2.ddos-guard.net

Registrar Information

Registrar: NameSilo, LLC
IANA ID: 1479
URL: https://www.namesilo.com
Email: support@namesilo.com
Abuse Email: abuse@namesilo.com
Abuse Phone: +1.4805240066

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
albon
Legendary
*
Offline Offline

Activity: 2352
Merit: 2057



View Profile
February 19, 2026, 03:53:59 PM
Merited by JeromeTash (1)
 #15

I think what else should be done is to report the GitHub profile. GitHub has zero tolerance for malware and phishing sites. They will delete it as soon as possible. Also while the legal part is being worked on, reporting the domain too can help reduce on the scam if it get's flagged by the browsers or even taken down by the registrar
It's good to know that when you open the xmrwallet link, MetaMask flags the site as potentially deceptive, showing any visitor: "This website might be harmful". This may serve as a protective layer for new users who might try their fraudulent wallet.

I've also already reported their GitHub account. Anyone can click on "Report abuse" under their profile picture and fill in the required fields with relevant information and evidence.



I also submitted a report to the domain registrar, NameSilo, via their website, but I received the message: "That is not an active domain in our system". I also tried sending the report to their official abuse email, so we’ll have to wait and see.

I urge everyone to file reports, because the reason this fraudulent wallet has continued to operate and appear until now is the lack of reporting. Just a few minutes spent submitting a report can protect many other users.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!