High Smart contract exploit Source: DeFiLlama Hacks

RetoSwap — Missing Input Validation

RetoSwap, a P2P multisig DEX for Monero, was exploited due to missing input validation, allowing attackers to impersonate arbitrators and steal funds. Trading was halted, and a patch is in progress.

Estimated loss
$2,700,000
Protocols
RetoSwap
Chains
Monero
Confidence
High
First seen
20 May 2026, 00:00 UTC

Read the original report ↗ (opens in a new tab)