Bitcoin Forum

Bitcoin => Important Announcements => Topic started by: theymos on December 27, 2018, 01:17:14 PM



Title: Electrum vulnerability allows arbitrary messages, phishing
Post by: theymos on December 27, 2018, 01:17:14 PM
If you're using Electrum or a derivative, you may receive a message like this:
https://user-images.githubusercontent.com/29142493/50359293-8780b500-055c-11e9-8cfd-83b342edeffb.png

This message is false, sent to you by a hacker. If you click the link in the message and install the software, then your BTC will be stolen. If you ignore the message, then you should be OK. Version 3.3.2 (https://electrum.org/#download), released a week ago, makes the messages less readable/convincing, though you could still receive such messages.

Note that altcoin derivatives of Electrum are very common, with over 1600 forks on github, and they will also be affected.

More info:
https://github.com/spesmilo/electrum/issues/4968

Discussion:
https://bitcointalk.org/index.php?topic=5089963.0