Bitcoin Forum
May 25, 2024, 04:43:09 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Warning 200 bitcoins stolen from electrum users via malicious update  (Read 578 times)
Kemarit
Legendary
*
Offline Offline

Activity: 3094
Merit: 1354



View Profile
December 28, 2018, 09:05:28 AM
 #21

I'm shocked. The market is in decline, and hackers continue to steal. I think that there is still no cryptocurrency wallet that gives reliability in use.

What do you expect? They're thieves, criminals and they don't care if we are in a bear or bullish trend. As long as they can stole from someone they will do it in a heart beat.

Yeah, I also saw the post from Theymos earlier, but it's a scary thing though. We all know that Electrum by is one of the most secured wallet out there, but it didn't deter hackers to see some loopholes and exploit it. I'm sure that Electrum devs will release a new version or a patch, so for now if you have bitcoins stored in your Electrum I would suggest to just wait from the official announcement before doing anything.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Initscri
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 759


View Profile WWW
December 28, 2018, 11:59:07 PM
 #22

I'm shocked. The market is in decline, and hackers continue to steal. I think that there is still no cryptocurrency wallet that gives reliability in use.

As long as crypto has value and is above $0, there will always be intent to steal. It's always going to be extremely profitable whether BTC is worth $1 or $1000+

----------------------------------
Web Developer. PM for details.
----------------------------------
bbc.reporter (OP)
Legendary
*
Offline Offline

Activity: 2940
Merit: 1448



View Profile
December 29, 2018, 01:08:53 AM
 #23

Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
vv181
Legendary
*
Offline Offline

Activity: 1932
Merit: 1273


View Profile
December 29, 2018, 03:03:12 AM
 #24

Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?

Connecting to secure and trusted Electrum would be a temporary solution for the security problem. I believe there are some identified attackers servers that have a similar sub-domain(.bitcoinplug.website domains.*.imaginarycoin.info domains.*.23734430190.pro domains.*.cryptoplayer.fun domains.*.krypto-familar.fun) as referenced in the official electrum GitHub repository.

I don't know if there is an official server for Electrum, but you can manually choose the server and avoid that sub-domain.
0t3p0t
Sr. Member
****
Offline Offline

Activity: 1568
Merit: 352


★Bitvest.io★ Play Plinko or Invest!


View Profile WWW
December 29, 2018, 03:22:18 AM
 #25

I don't know why more people get to know BTC more and more thieves. it doesn't match the idea of satosi nakamoto, some of my friends were phishing just opened a site that was sent in email. really thieves target us, there is nothing safe in this world, even a private key or password can be known by thieves, maybe we should be more careful to secure our assets
Yeah so we need to double check whatever we are doing online most especially with our Bitcoin funds. This only means that Bitcoin is still great as a lot of lawless elements such as hackers are interested to have some of everybody's funds. The only thing we can do is to be careful as it is not always safe if we are talking about money and wealth. This is also a lesson learned to not only for the victims but all of us who has hard earned Bitcoins on our wallets.



BIG WINNER!
[15.00000000 BTC]


▄████████████████████▄
██████████████████████
██████████▀▀██████████
█████████░░░░█████████
██████████▄▄██████████
███████▀▀████▀▀███████
██████░░░░██░░░░██████
███████▄▄████▄▄███████
████▀▀████▀▀████▀▀████
███░░░░██░░░░██░░░░███
████▄▄████▄▄████▄▄████
██████████████████████
▀████████████████████▀
▄████████████████████▄
██████████████████████
█████▀▀█▀▀▀▀▀▀██▀▀████
█████░░░░░░░░░░░░░▄███
█████░░░░░░░░░░░░▄████
█████░░▄███▄░░░░██████
█████▄▄███▀░░░░▄██████
█████████░░░░░░███████
████████░░░░░░░███████
███████░░░░░░░░███████
███████▄▄▄▄▄▄▄▄███████
██████████████████████
▀████████████████████▀
▄████████████████████▄
███████████████▀▀▀▀▀▀▀
███████████▀▀▄▄█░░░░░█
█████████▀░░█████░░░░█
███████▀░░░░░████▀░░░▀
██████░░░░░░░░▀▄▄█████
█████░▄░░░░░▄██████▀▀█
████░████▄░███████░░░░
███░█████░█████████░░█
███░░░▀█░██████████░░█
███░░░░░░████▀▀██▀░░░░
███░░░░░░███░░░░░░░░░░
▀██░▄▄▄▄░████▄▄██▄░░░░
▄████████████▀▀▀▀▀▀▀██▄
█████████████░█▀▀▀█░███
██████████▀▀░█▀░░░▀█░▀▀
███████▀░▄▄█░█░░░░░█░█▄
████▀░▄▄████░▀█░░░█▀░██
███░▄████▀▀░▄░▀█░█▀░▄░▀
█▀░███▀▀▀░░███░▀█▀░███░
▀░███▀░░░░░████▄░▄████░
░███▀░░░░░░░█████████░░
░███░░░░░░░░░███████░░░
███▀░██░░░░░░▀░▄▄▄░▀░░░
███░██████▄▄░▄█████▄░▄▄
▀██░████████░███████░█▀
▄████████████████████▄
████████▀▀░░░▀▀███████
███▀▀░░░░░▄▄▄░░░░▀▀▀██
██░▀▀▄▄░░░▀▀▀░░░▄▄▀▀██
██░▄▄░░▀▀▄▄░▄▄▀▀░░░░██
██░▀▀░░░░░░█░░░░░██░██
██░░░▄▄░░░░█░██░░░░░██
██░░░▀▀░░░░█░░░░░░░░██
██░░░░░▄▄░░█░░░░░██░██
██▄░░░░▀▀░░█░██░░░░░██
█████▄▄░░░░█░░░░▄▄████
█████████▄▄█▄▄████████
▀████████████████████▀




Rainbot
Daily Quests
Faucet
pooya87
Legendary
*
Offline Offline

Activity: 3458
Merit: 10589



View Profile
December 29, 2018, 03:28:21 AM
 #26

Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?

it doesn't matter what server you connect to. the malicious servers aren't stealing your coins, they CAN NOT do that. all they do is that they send you a message which your wallet shows and that "message" contains a link to the fake Electrum wallet.
so long as you don't click that link and don't install the fake one you are fine.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
bbc.reporter (OP)
Legendary
*
Offline Offline

Activity: 2940
Merit: 1448



View Profile
December 29, 2018, 03:36:30 AM
 #27

@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
pooya87
Legendary
*
Offline Offline

Activity: 3458
Merit: 10589



View Profile
December 29, 2018, 03:45:20 AM
 #28

@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.

well then logging IP addresses and being malicious is not new, it has always been the case! and it is not only your IP addresses but also all the addresses that you own and they can link them together that way. and since that is by design, it can not be changed.
note that it is a privacy issue not security that you are bringing up here.

if you want more privacy i'm afraid running a full verification node is the only choice you have.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Artemis3
Legendary
*
Offline Offline

Activity: 2030
Merit: 1563


CLEAN non GPL infringing code made in Rust lang


View Profile WWW
December 29, 2018, 04:06:09 AM
 #29

Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?

From what I understand, all you have to do is ignore that stupid message to download a "newer" Electrum. Electrum should not be showing server MOTDs anyway, that is a design flaw imo. And if you are connected to a malicious server sending such messages, change it in Network settings.

In Linux we usually don't go to web pages to download software, but use packages from official repositories (which in turn most distros has them crypto signed etc). And also, the phishers are lazy and don't always provide linux binaries of their trojan versions...

If you feel unsafe using the Electrum light wallet, the "right" thing to do is download Bitcoin core wallet, use the option prune=550 to save space, and the other tips to save bandwidth.

The IP logging thing can easily be circumvented by using TOR.

██████
███████
███████
████████
BRAIINS OS+|AUTOTUNING
MINING FIRMWARE
|
Increase hashrate on your Bitcoin ASICs,
improve efficiency as much as 25%, and
get 0% pool fees on Braiins Pool
Initscri
Hero Member
*****
Offline Offline

Activity: 1554
Merit: 759


View Profile WWW
December 29, 2018, 04:48:38 AM
 #30

Would it be an acceptable temporary solution to connect only to the servers run by the Electrum development team until the malicious servers are identified and blocked? Does Electrum have official servers online?

From what I understand, all you have to do is ignore that stupid message to download a "newer" Electrum. Electrum should not be showing server MOTDs anyway, that is a design flaw imo. And if you are connected to a malicious server sending such messages, change it in Network settings.

In Linux we usually don't go to web pages to download software, but use packages from official repositories (which in turn most distros has them crypto signed etc). And also, the phishers are lazy and don't always provide linux binaries of their trojan versions...

If you feel unsafe using the Electrum light wallet, the "right" thing to do is download Bitcoin core wallet, use the option prune=550 to save space, and the other tips to save bandwidth.

The IP logging thing can easily be circumvented by using TOR.

Yeah unfortunately there were plenty of users who weren't as familiar w/ Bitcoin and/or weren't as technically savvy, to which this exploit would have affected them more.

This will clearly have to be fixed in the future, I suspect by removing the ability to send messages or making it more clear that the messages received aren't official Electrum messages.

----------------------------------
Web Developer. PM for details.
----------------------------------
gabbie2010
Sr. Member
****
Offline Offline

Activity: 2674
Merit: 326


Vave.com - Crypto Casino


View Profile WWW
December 29, 2018, 05:16:21 AM
 #31

@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.
That is one of my fear while connecting to their server I am always curious that maybe some hacking is undergoing behind the scene all these issues of hacking had become rampant these days be it blockchain, MEW and of recent electrum and the most annoying thing is that electrum has no control of the stolen btc which is irreversible.

Altero
Full Member
***
Offline Offline

Activity: 784
Merit: 123


View Profile
December 29, 2018, 05:44:58 AM
 #32

@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.
That is one of my fear while connecting to their server I am always curious that maybe some hacking is undergoing behind the scene all these issues of hacking had become rampant these days be it blockchain, MEW and of recent electrum and the most annoying thing is that electrum has no control of the stolen btc which is irreversible.
Hackers could made it easily if the security of electrum isn't that strong. It is bad if they don't look into the best solution and pay even a half of the money loss by their users.
This could made awareness to all of us and might affect the entire market.  Online is prone to hacking as those hackers will do their best to crackdown keys and every single mistake we made is a big opportunity for them. That is why we should be careful especially in visiting unknown links.
Pursuer
Legendary
*
Offline Offline

Activity: 1638
Merit: 1163


Where is my ring of blades...


View Profile
December 29, 2018, 06:07:34 AM
 #33

@pooya87. I know. However I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.
That is one of my fear while connecting to their server I am always curious that maybe some hacking is undergoing behind the scene all these issues of hacking had become rampant these days be it blockchain, MEW and of recent electrum and the most annoying thing is that electrum has no control of the stolen btc which is irreversible.

you should always have that fear as long as your coins are on an online computer instead of being in a cold storage stored offline. and it is not just about electrum but about any other wallet that you may be using which is online. your computer can be infected easily and your coins can be lost.

in this case however the servers can only see your addresses because that is what you send them and nothing more. and this case here was only a feature that was being exploited by the scammer to mislead people into going to his malicious links and fooled them into downloading a fake wallet. so all you had to do was to not follow that link blindly!

Only Bitcoin
squatter
Legendary
*
Offline Offline

Activity: 1666
Merit: 1196


STOP SNITCHIN'


View Profile
December 29, 2018, 08:35:54 AM
 #34

I do not feel safe connecting to a random Electrum server while there are malicious servers around that might log my IP address.

Regardless of this incident, that's always been a possibility. It's one of the reasons Electrum has poor privacy. It's similar to the US government running loads of Tor exit nodes. The more malicious nodes that exist, the more likely you are to connect to them.

There's only one other way to use Electrum. If you don't want to randomly connect to servers, you have to run your own full node and then run an Electrum server on top of it.

Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!