Bitcoin Forum
June 02, 2026, 07:19:50 AM *
News: Latest Bitcoin Core release: 31.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Exolix Swaps Exposed via API Vulnerability  (Read 51 times)
examplens (OP)
Legendary
*
Offline

Activity: 4032
Merit: 4687



View Profile WWW
May 31, 2026, 09:09:01 AM
Merited by OmegaStarScream (4), Knight Hider (1)
 #1

If you've used Exolix via Edge, Monerujo, Exodus, or BTCPay in the last year and a half, your swaps are probably in someone's database

A serious broken access control in the Exolix API was discovered. Partners who integrate Exolix receive API keys, which are often hardcoded in applications or public repositories, and are not scoped, giving full access to the history of all transactions of that partner.
By using these keys, anyone can dump the complete swap data via the endpoint

That's what happened, 355,944 transactions (January 2025 – May 2026), total value ~39.5 million USD
Dominant currencies: Monero (XMR) is by far the most represented, especially in pairs with BTC, USDT, ETH, and LTC.

Source: https://www.rastersec.com/blog/exolix-swapper-dump


 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
OmegaStarScream
Staff
Legendary
*
Offline

Activity: 4228
Merit: 7381


♻️ Automatic Exchange


View Profile
May 31, 2026, 09:23:08 AM
 #2

Edge as in Airbitz? am I missing something here, how come they are responsible for most of the volume and transactions from this list?

That's what happened, 355,944 transactions (January 2025 – May 2026), total value ~39.5 million USD
Dominant currencies: Monero (XMR) is by far the most represented, especially in pairs with BTC, USDT, ETH, and LTC.

Chain Analyasis companies are going to have a great time with this one. Although I don't see why would anyone use Exolix for swapping XMR to start with.

░░░░▄▄████████████▄
▄████████████████▀
▄████████████████▀▄█▄
▄██████▀▀░░▄███▀▄████▄
▄██████▀░░░▄███▀▀██████▄
██████▀░░▄████▄░░░▀██████
██████░░▀▀▀▀▄▄▄▄░░██████
██████▄░░░▀████▀░░▄██████
▀██████▄▄███▀░░░▄██████▀
▀████▀▄████░░▄▄███████▀
▀█▀▄████████████████▀
▄████████████████▀
▀████████████▀▀░░░░
 
 CCECASH 
examplens (OP)
Legendary
*
Offline

Activity: 4032
Merit: 4687



View Profile WWW
May 31, 2026, 09:41:00 AM
 #3

Although I don't see why would anyone use Exolix for swapping XMR to start with.
If they are integrated in wallets or payment processors, many users were probably not even aware that their transactions were completed through Exolix. I recently paid for a domain extension, the registrar used BTCPay to process that transaction. It is very possible that the swap was finalized by Exolix, although I could not see it anywhere.
Likewise, I'm sure that at least 50% of Trezor users don't even know that their swap can go through Changenow if they do it directly from the Trezor Suite.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
NotATether
Legendary
*
Offline

Activity: 2352
Merit: 9770


┻┻ ︵㇏(°□°㇏)


View Profile WWW
May 31, 2026, 12:50:16 PM
 #4

This is a really bad security vulnerability, but it obviously could've been much worse than this.

We should be relieved that this only dumps swap history and doesn't attempt to scam or drain people by manipulating the return body shape.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!