Bitcoin Forum

Bitcoin => Electrum => Topic started by: cur363 on September 03, 2020, 03:25:56 PM



Title: Electrum wallet was hacked!
Post by: cur363 on September 03, 2020, 03:25:56 PM
My Electrum wallet has been hacked and all my bitcoins have been stolen. Is there anyway to find where the money has sent to?


Title: Re: Electrum wallet was hacked!
Post by: SquirrelJulietGarden on September 03, 2020, 03:32:58 PM
My Electrum wallet has been hacked and all my bitcoins have been stolen. Is there anyway to find where the money has sent to?
You can use block explorer to check transaction history. How it was moved and where it was moved to. Unfortunately, you can not know who are owners of the receiving addresses if they did that anonymously.

Unfortunately again, Bitcoin transaction is irreversible so you can assume your Bitcoin was stolen and you did lost it.

List of useful Bitcoin block explorers (https://bitcointalk.org/index.php?topic=5197909.0)


Title: Re: Electrum wallet was hacked!
Post by: jackg on September 03, 2020, 03:35:36 PM
It's unlikely you'll be able to recover your funds.

What version of electrum were you using, did you see a popup window and follow links in that? It can you remember doing something else?


Title: Re: Electrum wallet was hacked!
Post by: SquirrelJulietGarden on September 03, 2020, 03:40:46 PM
Did you use this wallet?

Electrum vulnerability allows arbitrary messages, phishing (https://bitcointalk.org/index.php?topic=5090097.0)


Title: Re: Electrum wallet was hacked!
Post by: erikoy on September 03, 2020, 04:04:35 PM
Did you use this wallet?

Electrum vulnerability allows arbitrary messages, phishing (https://bitcointalk.org/index.php?topic=5090097.0)
Electrum was vulnerable for arbitrary messages from the attacker to phished out the wallet.
https://user-images.githubusercontent.com/29142493/50359293-8780b500-055c-11e9-8cfd-83b342edeffb.png
The attacker uses the fake site to mislead the victim to a phishing software that probably was installed.

The real links are:
https://github.com/spesmilo/electrum (the github repository hosting the code)
https://electrum.org/ (website of the project)
6694D8DE7BE8EE5631BED9502BD5824B7F9470E6 (the real PGP public key of the developer)
Try to distinguish the real links for electrum wallet and their project site here.

My Electrum wallet has been hacked and all my bitcoins have been stolen. Is there anyway to find where the money has sent to?
Sad to say no way a hacker to expose himself from the victim of their phishing activities. However, you can follow the transaction from the stated list mention above of bitcoin block explorers.


Title: Re: Electrum wallet was hacked!
Post by: NeuroticFish on September 03, 2020, 04:11:20 PM
My Electrum wallet has been hacked and all my bitcoins have been stolen. Is there anyway to find where the money has sent to?

Are you sure the "Electrum wallet has been hacked"?
Your funds can be sent away without hacking your Electrum. All the hacker needs is your seed. (I hope you didn't back it up in mail, dropbox or other electronic/online method and you used good old paper).
Also, as the others said, there's a very good chance it was you who has installed a malicious Electrum thinking you make an update.


Title: Re: Electrum wallet was hacked!
Post by: bitmover on September 03, 2020, 04:23:32 PM
My Electrum wallet has been hacked and all my bitcoins have been stolen. Is there anyway to find where the money has sent to?

Are you sure you were hacked or stolen? Your balance may not be updated due some sync problems as well.

Or, like NeuroticFish said, someone could had access to your seed.

pasting your public address in any block explorer you can to which bitcoin address your bitcoin went. However, there is no easy way to discover who owns that address (unless he sends it an exchange  which he made KYC. But a hacker would probably mix the coins first)


Title: Re: Electrum wallet was hacked!
Post by: bob123 on September 03, 2020, 05:15:21 PM
Is there anyway to find where the money has sent to?

Sure, by looking at the transaction on an explorer.
But unfortunately you'll only see which address received your coins, not who that person in control over the private key is.
If your coins have been stolen, the chance of getting them back is almost zero.

More important is to find out how your coins got stolen. If your computer is infected, more data could be at risk.

Did you receive a popup as shown by erikoy? Or where did you electrum download from?
What OS are you using and where is your mnemonic code stored (PC, paper, email, ..) ?