Bitcoin Forum

Bitcoin => Electrum => Topic started by: jon0190 on February 07, 2019, 03:09:17 AM



Title: just got hacked through electrum
Post by: jon0190 on February 07, 2019, 03:09:17 AM
I tried to send coins out of electrum and was stopped for upgrades, when I get back in my money is gone? I frooze the transaction and it confirmed anyway. Do they even have support to contact? I have no money now, how is this happening,


Title: Re: just got hacked through electrum
Post by: TryNinja on February 07, 2019, 03:13:48 AM
Which version were you previously using? Did you receive a “warning popup” - after trying to do a transaction -  telling you to update your Electrum from a github link?

If that’s the case, your fell for a phishing scam and your coins are gone. There is nothing you can do since BTC transactions are irreversible.

Do a clean reinstall of your OS and create a new wallet. Both your PC and walet are most likely compromised. Also, NEVER dowpoad Electrum from a website that isn’t electrum.org; That’s the ONLY legit place you can get it.


Title: Re: just got hacked through electrum
Post by: jon0190 on February 07, 2019, 03:21:05 AM
I've never been phished before, its fucked up because it comes from the app. Not being mean towards you this is fucked up. they need to pull the service if they can't run it decently


Title: Re: just got hacked through electrum
Post by: TryNinja on February 07, 2019, 03:29:02 AM
I've never been phished before, its fucked up because it comes from the app. Not being mean towards you this is fucked up. they need to pull the service if they can't run it decently
It was a vulnerability. The Electrum servers (which anyone can run due to its descentralized nature) could make the Electrum wallet connected to it show a customized error message. So, the hacker deployed a bunch of malicious servers they showed the “please update” message you say.

When dealing with money, you should never put your guard down. Verifying the signatures of the binaries should be a mandatory step when downloading/updating Electrum.

Anyways, the vulnerability has been fixed in the latest version which was launched a few days ago and that you didn’t have. Unfortunately, it’s too late now. Sorry.


Title: Re: just got hacked through electrum
Post by: elda34b on February 07, 2019, 05:54:20 AM
lol. "has been fixed in the latest version" but old users dont know about that

Well they should always verify a signature before they download and install the apps. That's the basic steps to protect yourself. Blaming everything on the software won't solve anything, help yourself by making sure you install the correct apps.


Title: Re: just got hacked through electrum
Post by: jon0190 on February 07, 2019, 07:28:54 AM
It happened because the software stopped me from proceeding you fucking idiot!


lol. "has been fixed in the latest version" but old users dont know about that

Well they should always verify a signature before they download and install the apps. That's the basic steps to protect yourself. Blaming everything on the software won't solve anything, help yourself by making sure you install the correct apps.


Title: Re: just got hacked through electrum
Post by: jon0190 on February 07, 2019, 07:42:58 AM
What’s happening is the equivalent of your bank letting you use a mobile app as your only way to bank, then not telling you hackers have taken it over and you won’t be able to withdraw your money. What good is updates on your website when you have no reason to go to the website in the first place. This is a complete crock of shit


Title: Re: just got hacked through electrum
Post by: jon0190 on February 07, 2019, 08:45:54 AM
What kind of software doesn’t tell you when important updates are required?


Title: Re: just got hacked through electrum
Post by: jossiel on February 07, 2019, 09:23:41 AM
Is this exactly the same problem that you met?
https://www.reddit.com/r/Electrum/comments/amfbie/ongoing_attack_on_electrum_cant_send_bitcoins/

Do they even have support to contact?
https://twitter.com/ElectrumWallet

when I get back in my money is gone?
Sorry for your lost mate.


Title: Re: just got hacked through electrum
Post by: HCP on February 07, 2019, 11:20:18 AM
electrum should protect its users. If op run electrum and it says "No. You are using old version and it has been hacked. It has been fixed in the latest version. Download the latest version from electrum.org" then we dont have topics like this
What kind of software doesn’t tell you when important updates are required?
And what happens when the centralised update server gets hacked... broadcasts a spam to all users that they need to update to new version and all the users blindly trust that because "it is the Electrum update server" and download a malware wallet and lose all their funds? You'd all be asking "why Electrum have forced update notification?"

"Be your own bank" implies "Be your own Bank's security department as well". Everyone is all about the "freedom" of Cryptocurrency... no-one seems to want the added responsibility that comes with that freedom.

There are ways and means to protect yourself... and the easiest is to ALWAYS verify the digital signature of the Electrum installer (or portable .exe). Even when I have downloaded it from Electrum.org, I will ALWAYS verify the digital signature of the downloaded file to confirm it is legit.

So, even if I had received the spam message, ignored the fact it redirected to github instead of the official website and downloaded the malware installer, I never would have installed it... because the malware installer would have FAILED the digital signature verification.


Title: Re: just got hacked through electrum
Post by: HCP on February 07, 2019, 08:43:30 PM
It is all rather moot anyway... it looks like you got your wish... they've added (opt-in) update notifications to Electrum, and apparently have started using "good" servers (via an ElectrumX update) to broadcast update notifications to older versions of Electrum that are vulnerable to the exploit.


Title: Re: just got hacked through electrum
Post by: pooya87 on February 08, 2019, 05:28:40 AM
What kind of software doesn’t tell you when important updates are required?

in my opinion it is mainly because there is a lot of controversy circling the wallet softwares that do alert users of new versions. so developers decide not to include such features in their software.

in any case, you are in a decentralized world using a decentralized currency with open source/free software. it is your own responsibility to follow their vulnerabilities, shortcomings,... and learn how to increase your own security as much as possible. nobody is going to take your hand and do it for you.


Title: Re: just got hacked through electrum
Post by: ml73 on February 09, 2019, 03:54:18 PM
Hi..

I think my electrum wallet is hacked too.

Yesterday i received 0.048 btc , clock 08.50 pm.

Then ,  clock 00.27 am i have send those bitcoins but i havent.

Whats going on ??


       Mika


Title: Re: just got hacked through electrum
Post by: ml73 on February 09, 2019, 03:55:47 PM
I have version 3.0.3 and i have a password when i open my wallet and send.


Title: Re: just got hacked through electrum
Post by: TryNinja on February 09, 2019, 03:58:40 PM
I have version 3.0.3 and i have a password when i open my wallet and send.
Did you download Electrum from anywhere else other than electrum.org? Like a github link?

Did you receive a popup telling you to update your Electrum after trying to make a transaction?


Title: Re: just got hacked through electrum
Post by: ml73 on February 09, 2019, 04:15:46 PM
I havent receive any popups and i downloaded from their site about two years ago.

This is the transaction what i havent made :

https://www.blockchain.com/btc/tx/785727d486869504a0e9e505b7430001ea7d0d2ce574ebde00fccc21b42e2d9c


Title: Re: just got hacked through electrum
Post by: bob123 on February 09, 2019, 04:16:36 PM
It happened because the software stopped me from proceeding you fucking idiot!

That's not completely true.

The electrum server which you were connected to (which can by run by anyone who wants to) didn't broadcast your transaction.
That's not related to the electrum wallet itself.


Instead of simply clicking on an URL to download software which you didn't even verify the signature of, you could have simply connected to a different (non-malicious) electrum server.


I don't know how often you already read that here on the forum.. but.. Verify, don't trust!





I havent receive any popups and i downloaded from their site about two years ago.

The fact that you didn't update a software which holds your money for about 2 years, is already pretty bad.

Unfortunately there is no way for you to get the money back.


Since you didn't download a malicious wallet trough a phishing attempt and since your wallet is password protected, i'd say that the most plausible explanation is that your computer is infected with malware.

Did you download any half-way-shady software within the recent days ?
Do you use a legal copy of windows (cracked versions almost always have backdoors built in) ?



Title: Re: just got hacked through electrum
Post by: ml73 on February 09, 2019, 04:18:48 PM
and i have a password in my wallet


Title: Re: just got hacked through electrum
Post by: ml73 on February 09, 2019, 04:31:52 PM
Electrum should pay me for my lost coins  !!!


Title: Re: just got hacked through electrum
Post by: ml73 on February 09, 2019, 05:33:54 PM
There is nothing what i can do ???


Title: Re: just got hacked through electrum
Post by: TryNinja on February 09, 2019, 05:36:14 PM
Stop multi-posting.

There is nothing you can do and Electrum won’t pay you anything. Your coins are are gone. Sorry, but you should just accept and move on.


Title: Re: just got hacked through electrum
Post by: HCP on February 10, 2019, 02:04:52 AM
I think my electrum wallet is hacked too.

Yesterday i received 0.048 btc , clock 08.50 pm.
Then ,  clock 00.27 am i have send those bitcoins but i havent.
Whats going on ??
Given that you haven't been a victim of the current phishing scam and downloaded a malware version of Electrum, then it is likely that your wallet seed mnemonic (12 words) have been compromised.

- Have you ever stored your Electrum 12 word seed mnemonic in a digital format? ie. text file or screenshot on your PC, email or cloud file storage?
- Have you ever entered your Electrum 12 word seed mnemonic in another wallet, website or other application for trying to access fork coins like Bitcoin Cash, Bitcoin Gold, Bitcoin Diamond etc etc?

NOTE: as TryNinja says... you cannot get your coins back... and Electrum accept no liability. The point of these questions is to try and help you understand why you lost your coins so you can avoid making the same mistakes.


Title: Re: just got hacked through electrum
Post by: HCP on February 12, 2019, 04:34:19 AM
Are you just trolling on purpose now? Or is it just that you fail to grasp that all of the things you want:

- Electrum to notify of updates
- Electrum to not display arbitrary text in error messages
- Electrum to post notification of security alerts

have already been implemented... Latest version of Electrum includes "opt-in" update notifications... it has been patched so only hardcoded error messages will be displayed... and the devs always post on the official website regarding security issues... they've even started using "good" servers to notify users of older versions that they should update.

This has been pointed out to you multiple times in multiple threads and you keep saying "not enough" ::)

What more do you want the devs to do? ???


Title: Re: just got hacked through electrum
Post by: bob123 on February 12, 2019, 08:52:45 AM
not enough

That is definitely enough.

It is MORE than you should expect.

Everyone is responsible for his own actions. If you fall for cheap phishing messages, you should consider using a hardware wallet or not using cryptocurrencies at all.

Noone and nothing stops you from receiving an email "sent by" electrum.org which says you to download a new (malicious) version, etc..
This is due to the fact that email is a broken protocol.
If YOU fall for something like this, it is YOUR fault. Same goes with downloading files without verifying the signatures.


Title: Re: just got hacked through electrum
Post by: bob123 on February 12, 2019, 11:09:45 AM
Legendary why you dont want electrum to show security alerts to users? You want to fool users?

Simple.

1)
Because it is NOT necessary. Anyone with a brain (who actually is able to use it properly) knows how to stay up-to-date.
And people who don't have any clue about security, shouldn't store cryptocurrencies on a desktop wallet at all.

2)
It creates additional attack vectors. I know that you don't understand anything regarding security/vulnerabilities.
So either just believe me or do your own research.


You fell to a very very basic phishing scam. Admit it, learn from it and move on.
I stop responding to your trolling posts now because it seems that you don't learn anything from it anyway.


Title: Re: just got hacked through electrum
Post by: actmyname on February 14, 2019, 06:13:16 AM
It seems ludicrous to cry about coins that you lost due to your own stupidity.

If you drop a thousand dollars on the street, do you run up to your bank to ask them to refund you?
If you get scammed, it is no one's fault except your own. (that, and the scammer's)


Title: Re: just got hacked through electrum
Post by: Artemis3 on February 15, 2019, 12:38:01 AM
I have version 3.0.3 and i have a password when i open my wallet and send.
Did you download Electrum from anywhere else other than electrum.org? Like a github link?

Did you receive a popup telling you to update your Electrum after trying to make a transaction?

Using v3.2.3 I saw the phishing popup yesterday from one of the rogue servers when i tried to do a tx. I'm sorry I forgot to screenshot, but it wasn't a github url. It was electrumsomething.com. Probably github kicked the phishers out and they registered another more "innocuous looking" url... I just switched to a trusted known server and did the tx fine (despite another nag saying my Electrum was "vulnerable", download a new version from electrum.org yadda, yadda.).

I already upgraded to v3.3.3... Was just waiting for the Arch package update.


Title: Re: just got hacked through electrum
Post by: HCP on February 15, 2019, 06:01:30 AM
Using v3.2.3 I saw the phishing popup yesterday from one of the rogue servers when i tried to do a tx. I'm sorry I forgot to screenshot, but it wasn't a github url. It was electrumsomething.com. Probably github kicked the phishers out and they registered another more "innocuous looking" url... .
Thanks for the report...


Can confirm that "electrumd o w n l o a d.com" (DO NOT VISIT - SCAM URL!) is a phishing URL... with version "4.0.0" available for download...

Chrome initially warned that the website was unsafe... After manually "proceeding" to the website, I attempted to download it onto the sandboxed VM... and Windows Defender detected a trojan (Trojan:Win32/Spursint.F!cl) and removed the download. After manually allowing it... I tried to GPG check the file and got "gpg: Can't check signature: No public key"

Be safe out there!


Title: Re: just got hacked through electrum
Post by: mindrust on February 15, 2019, 06:08:32 AM
This was a big kick in the balls for all electrum users. No matter how many times they fix it now, I don't think I'll ever use electrum again. The trust is lost. It is either the core wallet or nothing now.


Title: Re: just got hacked through electrum
Post by: pooya87 on February 16, 2019, 04:46:57 AM
This was a big kick in the balls for all electrum users. No matter how many times they fix it now, I don't think I'll ever use electrum again. The trust is lost. It is either the core wallet or nothing now.

just out of curiosity would you mind explaining why you ignore the vulnerabilities that have existed and do exist in bitcoin core and still trust it while your logic in this comment is that if a software has a bug it is not-trusted?

here is a list of them with their seriousness, the latest of which was a validation check which could easily be exploited and split the whole network: https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures


Title: Re: just got hacked through electrum
Post by: rokkyroad on February 16, 2019, 08:38:00 PM
This was a big kick in the balls for all electrum users. No matter how many times they fix it now, I don't think I'll ever use electrum again. The trust is lost. It is either the core wallet or nothing now.

You won't get much sympathy here. Some insist on blaming the users for not verifying the download despite the hack happening in a verified wallet.

The same crew insists its a software bug not a hack. Whatever it was, it was to the tune of 1 million bucks or more.





Title: Re: just got hacked through electrum
Post by: HCP on February 16, 2019, 09:10:45 PM
That is because it wasn't a hack... it was social engineering. The exploit simply allowed the attackers to display a message with a clickable link. It did NOT give any access to private keys or seeds.

So, any funds held in the legitimate wallet were "safe"... Funds were only lost if users then manually downloaded, installed and ran the "fake" version of the wallet (that failed digital signature validation!) that was being advertised via this software bug/exploit. Users who did nothing were safe.

If users attempted to validate the digital signature of the wallet (that they had to manually download) before they installed/ran it... then they would have found it was fake, and would have most likely avoided losing funds.