Monero Security Checklist: How People Actually Lose Their XMR (and How to Stop It)
Monero’s privacy features protect your financial history. They do not protect you from sending funds to a thief’s address, downloading a fake wallet, or leaving your seed phrase in a cloud folder. This article covers the actual attack vectors that cost people their XMR in 2026, based on incidents reported on Reddit, support forums, and security advisories.
Clipboard hijacking: the most common theft vector
Clipboard malware — also called “clippers” — silently replaces the crypto address you copy with the attacker’s address. When you paste and hit send, the XMR goes to the wrong wallet. A Reddit post documenting this attack received over 4,800 upvotes on r/CryptoCurrency in 2026.
How it works: the malware monitors your clipboard roughly every 500 milliseconds. It recognises Monero addresses by their prefix (starting with 4 or 8) and 95-character length. When it detects one, it swaps it instantly.
How to protect yourself:
- Always compare the first and last 6 characters of the pasted address with the original. If even one character differs, your clipboard is compromised.
- Use a hardware wallet. Trezor and Ledger display the recipient address on their physical screen, which malware cannot tamper with. See our hardware wallet guide.
- Use our address checker to validate the format before sending.
- Send a small test transaction first when sending to a new address.
- Avoid pirated software, cracked games, and browser extensions from unknown publishers. These are the primary distribution channels for clipboard malware.
Fake wallets and phishing sites
Fake Monero wallet apps appear periodically on app stores and as search engine ads. The OpenMonero web wallet was drained of 399 XMR in one incident, and then hacked again with user home addresses leaked. These were not theoretical risks — real users lost real money.
How to protect yourself:
- Only download wallets from official sources. For Cake Wallet: the App Store, Google Play, or cakewallet.com. For the Monero GUI: getmonero.org. For Feather: featherwallet.org. Our wallet directory links to the verified official sites.
- Verify downloads. The Monero GUI and Feather publish GPG signatures. Check them.
- Never use a web wallet that asks you to enter your seed phrase. Legitimate web wallets either generate a new wallet in your browser or connect to an existing one via keys — they never ask you to type your seed into a web form.
- Bookmark official wallet sites instead of searching for them each time. Phishing sites pay for search ads.
Seed phrase exposure
Your 25-word Monero seed phrase is the master key to your funds. If anyone obtains it, they can drain your wallet from anywhere in the world. Common mistakes:
- Storing the seed in a cloud service (Google Drive, iCloud, Dropbox, OneDrive). If your cloud account is breached, your XMR is gone.
- Taking a screenshot or photo of the seed. Photos sync to cloud services automatically on most phones.
- Storing it in a password manager that has been breached. Password managers are better than plaintext files, but not as safe as paper stored offline.
- Entering the seed on a phishing site. No legitimate service or support agent will ever ask for your seed phrase.
Best practice: Write the 25 words on paper (or stamp them on metal for fire resistance). Store the paper in a secure location. Never type the seed into any website. If you must store it digitally, use an encrypted, air-gapped device that never connects to the internet.
Exchange and custodial wallet risks
When your XMR sits on an exchange, you don’t hold the keys — the exchange does. Exchanges get hacked, freeze withdrawals, or delist Monero with short notice. Notable events in recent years:
- Multiple exchanges delisted Monero under regulatory pressure (see our delisting tracker by country)
- Some exchanges have frozen Monero withdrawals for weeks during “wallet maintenance”
Rule of thumb: Buy on an exchange, withdraw to your own wallet immediately. Do not use an exchange as a long-term storage solution. Our wallet guide covers options for every platform.
Transaction mistakes
Monero transactions are irreversible. Common errors:
- Sending to the wrong address. Always double-check. Use address validation.
- Wrong network. Monero mainnet addresses start with
4(standard) or8(subaddress). If someone gives you an address starting with anything else for a “Monero payment,” it is not a Monero address. - Stuck transactions. Monero has dynamic fees and block sizes, so transactions rarely get stuck. If yours does, it will time out and the funds will return to your wallet after about 24 hours. Check the transaction checker for status.
Node privacy
If you use a remote node to sync your wallet, that node operator can see your IP address and the transactions you submit (though Monero’s ring signatures prevent them from knowing the true inputs). For stronger privacy:
- Run your own node. Our node directory has guides and node hardware listings.
- Use Tor. Feather Wallet routes all traffic through Tor by default. The GUI wallet can be configured to use Tor.
- If you must use a remote node, pick one from our live node list, which shows uptime, response times, and whether each node is Tor-accessible.
The checklist
Print this or save it to your device. Run through it before every significant transaction.
- Wallet downloaded from official source? (Check our directory for links.)
- Seed phrase stored on paper, offline, in a secure location?
- Receiving address verified on hardware wallet screen (if using one)?
- Pasted address matches the original (first and last 6 characters)?
- Test transaction sent successfully?
- Operating system and wallet software up to date?
- No suspicious browser extensions or recently installed software?
- Using your own node or Tor for wallet sync?
- Funds withdrawn from exchange to your own wallet?
FAQ
Can Monero be traced if my wallet is compromised?
If someone has your seed phrase or view key, they can see your incoming transactions and balance. However, Monero’s ring signatures still protect the sender’s identity in each transaction. The threat is to your funds, not necessarily to the privacy of people who sent you XMR.
Is it safer to use Monero on Tails or a live USB?
Yes, significantly. Tails is an amnesic operating system that runs from a USB drive, routes all traffic through Tor, and leaves no trace on the host computer. It eliminates most malware risks. Feather Wallet runs natively on Tails.
What should I do if I think my clipboard is compromised?
Stop all crypto transactions immediately. Run a full malware scan with a reputable antivirus (Malwarebytes is effective against clippers). Reinstall your operating system from a clean image if possible. Move your funds to a new wallet using a known-clean device.
Are mobile wallets safe?
Mobile wallets like Cake Wallet and Monerujo are generally safe for everyday amounts. Phones have better app sandboxing than desktop operating systems, which limits malware’s ability to read your clipboard. For large holdings, use a hardware wallet.
XMRList provides free security and verification tools including an address format checker, transaction lookup, and a directory of wallets with verified download links — everything you need to send XMR safely.