Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: bbc.reporter on December 28, 2018, 01:47:06 AM



Title: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: bbc.reporter on December 28, 2018, 01:47:06 AM
Electrum users, we are all targets by hackers. I have never experienced Electrum asking for updates from the wallet itself. Updates should be downloaded from the official website and repositories and must be verified by their checksums and the developer's PGP keys.

I reckon this hack should be a lesson for us to start verifying all software we download.

https://zdnet2.cbsistatic.com/hub/i/2018/12/27/b86818a9-581f-4c69-8a33-d9eb025e6f9f/9600b33f28ed017eeb729cb6bb69fd42/electrum-error-message.png

Another attack has hit the cryptospace – this time, the target was the Electrum Bitcoin Wallet. The hacker, or hackers, got away with over 200 Bitcoin (around $718,000 as of press) by urging wallet users to download and install a malicious software update, according to business technology news outlet ZDNet. The hack began last Friday, December 21, and has been temporarily halted by GitHub administrators as of today.

To acquire users' bitcoin, the attacker added several malicious servers to Electrum's network. If an initiated bitcoin transaction reached one of these servers, it would respond with an error message prompting the user to follow a GitHub link to download an update. After download, the updated app would request a two-factor authentication code, which, if provided, would allow the malicious software to transfer the user's funds into the attacker's Bitcoin addresses.

Some users even manually copy-and-pasted the link provided in the error message and downloaded the malicious update via that route.

Although GitHub eventually removed the offending repository, the Electrum team silently responded to the hack beforehand by updating the app so that the fake messages would no longer appear as formatted text, which looks more legitimate than plain text. An Electrum developer, known as SomberNight, said the team did not publicly disclose the attack until today because the hacker had apparently stopped.

However, Electrum anticipates another attack to occur using either a different GitHub repository or another download location. The malicious servers also remain on the Electrum network – in fact, Electrum developers have identified at least 33 of them. The team has not disclosed what it intends to do about these servers.


Read in full https://www.ethnews.com/200-bitcoin-stolen-from-electrum-wallet-users-via-hack


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: r1s2g3 on December 28, 2018, 02:17:00 AM
Post by theymos for this phishing link:

https://bitcointalk.org/index.php?topic=5090097.0

Post warning about the fake Electrum wallets:
https://bitcointalk.org/index.php?topic=5089963.0

Alternatively you can read multiple stories in below board how users got cheated of their BTC.

Bitcoin Forum > Bitcoin > Development & Technical Discussion > Alternative clients > Electrum


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: elisabetheva on December 28, 2018, 02:27:14 AM
I think that strongly agree with your opinion that "we are all targets of hackers" just how we should be more careful not to be affected.
But clearly the information you provide will add to our knowledge more carefully, thank you


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: steampunkz on December 28, 2018, 02:31:57 AM
Electrum users, we are all targets by hackers. I have never experienced Electrum asking for updates from the wallet itself. Updates should be downloaded from the official website and repositories and must be verified by their checksums and the developer's PGP keys.

I reckon this hack should be a lesson for us to start verifying all software we download.

https://zdnet2.cbsistatic.com/hub/i/2018/12/27/b86818a9-581f-4c69-8a33-d9eb025e6f9f/9600b33f28ed017eeb729cb6bb69fd42/electrum-error-message.png

Another attack has hit the cryptospace – this time, the target was the Electrum Bitcoin Wallet. The hacker, or hackers, got away with over 200 Bitcoin (around $718,000 as of press) by urging wallet users to download and install a malicious software update, according to business technology news outlet ZDNet. The hack began last Friday, December 21, and has been temporarily halted by GitHub administrators as of today.

To acquire users' bitcoin, the attacker added several malicious servers to Electrum's network. If an initiated bitcoin transaction reached one of these servers, it would respond with an error message prompting the user to follow a GitHub link to download an update. After download, the updated app would request a two-factor authentication code, which, if provided, would allow the malicious software to transfer the user's funds into the attacker's Bitcoin addresses.

Some users even manually copy-and-pasted the link provided in the error message and downloaded the malicious update via that route.

Although GitHub eventually removed the offending repository, the Electrum team silently responded to the hack beforehand by updating the app so that the fake messages would no longer appear as formatted text, which looks more legitimate than plain text. An Electrum developer, known as SomberNight, said the team did not publicly disclose the attack until today because the hacker had apparently stopped.

However, Electrum anticipates another attack to occur using either a different GitHub repository or another download location. The malicious servers also remain on the Electrum network – in fact, Electrum developers have identified at least 33 of them. The team has not disclosed what it intends to do about these servers.


Read in full https://www.ethnews.com/200-bitcoin-stolen-from-electrum-wallet-users-via-hack


I'm glad bitcoin talk administrator already have a warning about the electrum fake update, It will prevent the majority of people and users of BTC who will fall for this scam. Good work from the team of BTT!


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: pooya87 on December 28, 2018, 03:55:19 AM
the strange part is that people knew Electrum has no warning like that ever to tell them to upgrade their wallet but yet they clicked the link without thinking about it. also majority of those whom i know download it from the electrum.org website not github page so when they opened that link it should have looked strange to them.

in any case the good news is that the page on github for the malicious app is removed now.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: cokroalif on December 28, 2018, 04:03:21 AM
I don't know why more people get to know BTC more and more thieves. it doesn't match the idea of satosi nakamoto, some of my friends were phishing just opened a site that was sent in email. really thieves target us, there is nothing safe in this world, even a private key or password can be known by thieves, maybe we should be more careful to secure our assets


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Initscri on December 28, 2018, 04:08:03 AM
the strange part is that people knew Electrum has no warning like that ever to tell them to upgrade their wallet but yet they clicked the link without thinking about it. also majority of those whom i know download it from the electrum.org website not github page so when they opened that link it should have looked strange to them.

in any case the good news is that the page on github for the malicious app is removed now.

Yea, I'm kind of scared to know how effective this would have been if the attacker leveraged a phishing domain w/ a similar download page compared to Github.

It might have been a hell of a lot worse


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: figmentofmyass on December 28, 2018, 04:11:11 AM
have the developers mentioned an ETA for fully closing this vulnerability?

in any case the good news is that the page on github for the malicious app is removed now.

yup, but i expect another github repository to pop up (or another download site entirely). there's still dozens of malicious servers connecting to electrum wallets and the attack has proven too fruitful not to keep trying.

I reckon this hack should be a lesson for us to start verifying all software we download.

and also a kick in the pants to run our own full node and electrum server rather than connecting randomly. if you use electrum with an offline signature scheme you should be safe here too.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Initscri on December 28, 2018, 04:14:22 AM
have the developers mentioned an ETA for fully closing this vulnerability?

This is their primary tweet + response to the incident: https://twitter.com/ElectrumWallet/status/1078319006862454785

AFAIK, no ETA released as of yet.

IMO, best solution would be to just block any notifications w/ a URL. No legitimate notification would require a URL IMO (correct me if I'm wrong though)
Or, at the very least, a message within Electrum to suggest it's a message from the server & not a message from Electrum itself (and to be careful, etc)


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: milewilda on December 28, 2018, 04:19:07 AM
the strange part is that people knew Electrum has no warning like that ever to tell them to upgrade their wallet but yet they clicked the link without thinking about it. also majority of those whom i know download it from the electrum.org website not github page so when they opened that link it should have looked strange to them.

in any case the good news is that the page on github for the malicious app is removed now.
Too much trust on such service and neglect any reviews before downloading anything is the most common mistake. Just to think downloading from other source will already give you the doubts
but surprisingly lots of electrum users still fall into the pit.This is way too unexpected and luckily i did neglect such warning.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: pooya87 on December 28, 2018, 04:22:56 AM
in any case the good news is that the page on github for the malicious app is removed now.

yup, but i expect another github repository to pop up (or another download site entirely). there's still dozens of malicious servers connecting to electrum wallets and the attack has proven too fruitful not to keep trying.

for what it's worth, this is the first time this feature of Electrum was exploited but this is not the first time a malicious fork of a popular project pops up on Github. so far in the past 2 years i have personally reported 6 or 7 of them to Github for removal because they were malicious and were abusing the name to fool people. one was even open source instead of only having a "release"!


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: thesmallgod on December 28, 2018, 05:25:24 AM
Electrum wallet has always been targeted by hackers for a long time. Almost every year we hear news like this. The same thing happened last year. I believe it is high time people start downloading sensitive wallet from official websites and not anywhere. For God sake, crypto wallet is not a crack wallet that we can look and download from any source.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: CryptoBry on December 28, 2018, 06:02:54 AM
I think that strongly agree with your opinion that "we are all targets of hackers" just how we should be more careful not to be affected.
But clearly the information you provide will add to our knowledge more carefully, thank you

All Bitcoin and cryptocurrency holders can be targeted by hackers and they are doing good business with this that is why they are always investing many new ways to get into these wallet infrastructure and victimized innocent wallet holders big time. Sadly, as of now, no technology can effectively stop good hackers from doing their crazy antics. No, not even the very technology called blockchain can be helping us. I am then hoping that something concrete can be done on this big problem.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Kakmakr on December 28, 2018, 06:16:39 AM
I am a bit disappointed with the Electrum wallet developers, because they knew about this on the 21st of December and they did nothing to warn people until today.  >:( The moment when this hack was brought under their attention, they should have placed a "warning" or popup in the software or on popular online platforms to inform people!

I hope this incident will be a wake-up call for them to react a lot quicker when something like this happens.  >:(


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: joniboini on December 28, 2018, 06:40:20 AM
I hope this incident will be a wake-up call for them to react a lot quicker when something like this happens.  >:(

Yeah, I also think they should give a warning after they found out. But the user should be more cautious too tbh. The attack includes downloading from unconfirmed sources, they should at least have suspicion when there is a pop-up showing to download. Well, let's hope this won't happen again.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Andruha1993 on December 28, 2018, 07:37:22 AM
I also use ELECTRUM and have never encountered scammers there. Yes, it is very sad that the fraudsters attack, but all have said many times that you must always be careful and check the accuracy of the information.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Juggy777 on December 28, 2018, 07:43:00 AM
I think that strongly agree with your opinion that "we are all targets of hackers" just how we should be more careful not to be affected.
But clearly the information you provide will add to our knowledge more carefully, thank you

I always believed Electrum wallet to be safe and easy to operate, and I'm surprised that hackers were able to target it. I believe a majority of these users who were targeted use the wallet on their computers/laptops, and thus became easy targets. I have been using electrum wallet app, and I did not see it asking for any update, also this is a very big lesson for all never to self update the wallet, always use the original website.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: ethereumhunter on December 28, 2018, 08:02:11 AM
I don't know why more people get to know BTC more and more thieves. it doesn't match the idea of satosi nakamoto, some of my friends were phishing just opened a site that was sent in email. really thieves target us, there is nothing safe in this world, even a private key or password can be known by thieves, maybe we should be more careful to secure our assets

Because the thieves know much things about bitcoin and they want to have bitcoin, but they do the wrong way. We need always to be careful when we want to visit the link which we don't know because the hi-jacking now become dangerous and it could get the information from many ways. Our account will be our responsibilities to protect and never to tell other people for what we did, or we might be the next target for the strange people who want our money.

Fortunately, I don't use Electrum for a long time ago but I will check my Electrum wallet, and I hope it will be fine and nothing happens inside the wallet.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: VitKoyn on December 28, 2018, 08:35:27 AM
If you are a user of electrum wallet you should always check the source of the update, if it is not a link from their website you shouldn't click or copy and paste it on your browser. But in the other side, it is really disappointing because developers they let this vulnerabilities exist without giving their users an immediate warning on what is happening. And of course there will be some victims of this because they trust electrum software to be safe. And not only electrum but also other altcoin wallets that are forks of electrum have this vulnerabilities so if you use one of those then you might also see this phishing links.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Oniko on December 28, 2018, 08:53:10 AM
I'm shocked. The market is in decline, and hackers continue to steal. I think that there is still no cryptocurrency wallet that gives reliability in use.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Kemarit on December 28, 2018, 09:05:28 AM
I'm shocked. The market is in decline, and hackers continue to steal. I think that there is still no cryptocurrency wallet that gives reliability in use.

What do you expect? They're thieves, criminals and they don't care if we are in a bear or bullish trend. As long as they can stole from someone they will do it in a heart beat.

Yeah, I also saw the post from Theymos earlier, but it's a scary thing though. We all know that Electrum by is one of the most secured wallet out there, but it didn't deter hackers to see some loopholes and exploit it. I'm sure that Electrum devs will release a new version or a patch, so for now if you have bitcoins stored in your Electrum I would suggest to just wait from the official announcement before doing anything.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Initscri on December 28, 2018, 11:59:07 PM
I'm shocked. The market is in decline, and hackers continue to steal. I think that there is still no cryptocurrency wallet that gives reliability in use.

As long as crypto has value and is above $0, there will always be intent to steal. It's always going to be extremely profitable whether BTC is worth $1 or $1000+


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: bbc.reporter on December 29, 2018, 01:08:53 AM
Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: vv181 on December 29, 2018, 03:03:12 AM
Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?

Connecting to secure and trusted Electrum would be a temporary solution for the security problem. I believe there are some identified attackers servers that have a similar sub-domain(.bitcoinplug.website domains.*.imaginarycoin.info domains.*.23734430190.pro domains.*.cryptoplayer.fun domains.*.krypto-familar.fun) as referenced in the official electrum GitHub repository.

I don't know if there is an official server for Electrum, but you can manually choose the server and avoid that sub-domain.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: 0t3p0t on December 29, 2018, 03:22:18 AM
I don't know why more people get to know BTC more and more thieves. it doesn't match the idea of satosi nakamoto, some of my friends were phishing just opened a site that was sent in email. really thieves target us, there is nothing safe in this world, even a private key or password can be known by thieves, maybe we should be more careful to secure our assets
Yeah so we need to double check whatever we are doing online most especially with our Bitcoin funds. This only means that Bitcoin is still great as a lot of lawless elements such as hackers are interested to have some of everybody's funds. The only thing we can do is to be careful as it is not always safe if we are talking about money and wealth. This is also a lesson learned to not only for the victims but all of us who has hard earned Bitcoins on our wallets.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: pooya87 on December 29, 2018, 03:28:21 AM
Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?

it doesn't matter what server you connect to. the malicious servers aren't stealing your coins, they CAN NOT do that. all they do is that they send you a message which your wallet shows and that "message" contains a link to the fake Electrum wallet.
so long as you don't click that link and don't install the fake one you are fine.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: bbc.reporter on December 29, 2018, 03:36:30 AM
@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: pooya87 on December 29, 2018, 03:45:20 AM
@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.

well then logging IP addresses and being malicious is not new, it has always been the case! and it is not only your IP addresses but also all the addresses that you own and they can link them together that way. and since that is by design, it can not be changed.
note that it is a privacy issue not security that you are bringing up here.

if you want more privacy i'm afraid running a full verification node is the only choice you have.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Artemis3 on December 29, 2018, 04:06:09 AM
Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?

From what I understand, all you have to do is ignore that stupid message to download a "newer" Electrum. Electrum should not be showing server MOTDs anyway, that is a design flaw imo. And if you are connected to a malicious server sending such messages, change it in Network settings.

In Linux we usually don't go to web pages to download software, but use packages from official repositories (which in turn most distros has them crypto signed etc). And also, the phishers are lazy and don't always provide linux binaries of their trojan versions...

If you feel unsafe using the Electrum light wallet, the "right" thing to do is download Bitcoin core wallet, use the option prune=550 (https://en.bitcoin.it/wiki/Running_Bitcoin#Bitcoin.conf_Configuration_File) to save space, and the other tips to save bandwidth (https://bitcointalk.org/index.php?topic=1377345.0).

The IP logging thing can easily be circumvented by using TOR.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Initscri on December 29, 2018, 04:48:38 AM
Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?

From what I understand, all you have to do is ignore that stupid message to download a "newer" Electrum. Electrum should not be showing server MOTDs anyway, that is a design flaw imo. And if you are connected to a malicious server sending such messages, change it in Network settings.

In Linux we usually don't go to web pages to download software, but use packages from official repositories (which in turn most distros has them crypto signed etc). And also, the phishers are lazy and don't always provide linux binaries of their trojan versions...

If you feel unsafe using the Electrum light wallet, the "right" thing to do is download Bitcoin core wallet, use the option prune=550 (https://en.bitcoin.it/wiki/Running_Bitcoin#Bitcoin.conf_Configuration_File) to save space, and the other tips to save bandwidth (https://bitcointalk.org/index.php?topic=1377345.0).

The IP logging thing can easily be circumvented by using TOR.

Yeah unfortunately there were plenty of users who weren't as familiar w/ Bitcoin and/or weren't as technically savvy, to which this exploit would have affected them more.

This will clearly have to be fixed in the future, I suspect by removing the ability to send messages or making it more clear that the messages received aren't official Electrum messages.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: gabbie2010 on December 29, 2018, 05:16:21 AM
@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.
That is one of my fear while connecting to their server I am always curious that maybe some hacking is undergoing behind the scene all these issues of hacking had become rampant these days be it blockchain, MEW and of recent electrum and the most annoying thing is that electrum has no control of the stolen btc which is irreversible.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Altero on December 29, 2018, 05:44:58 AM
@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.
That is one of my fear while connecting to their server I am always curious that maybe some hacking is undergoing behind the scene all these issues of hacking had become rampant these days be it blockchain, MEW and of recent electrum and the most annoying thing is that electrum has no control of the stolen btc which is irreversible.
Hackers could made it easily if the security of electrum isn't that strong. It is bad if they don't look into the best solution and pay even a half of the money loss by their users.
This could made awareness to all of us and might affect the entire market.  Online is prone to hacking as those hackers will do their best to crackdown keys and every single mistake we made is a big opportunity for them. That is why we should be careful especially in visiting unknown links.


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: Pursuer on December 29, 2018, 06:07:34 AM
@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.
That is one of my fear while connecting to their server I am always curious that maybe some hacking is undergoing behind the scene all these issues of hacking had become rampant these days be it blockchain, MEW and of recent electrum and the most annoying thing is that electrum has no control of the stolen btc which is irreversible.

you should always have that fear as long as your coins are on an online computer instead of being in a cold storage stored offline. and it is not just about electrum but about any other wallet that you may be using which is online. your computer can be infected easily and your coins can be lost.

in this case however the servers can only see your addresses because that is what you send them and nothing more. and this case here was only a feature that was being exploited by the scammer to mislead people into going to his malicious links and fooled them into downloading a fake wallet. so all you had to do was to not follow that link blindly!


Title: Re: Warning 200 bitcoins stolen from electrum users via malicious update
Post by: squatter on December 29, 2018, 08:35:54 AM
I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.

Regardless of this incident, that's always been a possibility. It's one of the reasons Electrum has poor privacy. It's similar to the US government running loads of Tor exit nodes. The more malicious nodes that exist, the more likely you are to connect to them.

There's only one other way to use Electrum. If you don't want to randomly connect to servers, you have to run your own full node and then run an Electrum server on top of it.