Bitcoin Forum
May 26, 2024, 07:25:00 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Electrum Hacked?  (Read 220 times)
cube42 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
August 05, 2019, 10:32:14 AM
Last edit: August 05, 2019, 11:00:35 AM by cube42
 #1

I have updated elctrum (was a pop up within electrum its elf, to upgrade...i did that...and then i transfer money, for bitcoins, from my bank to the Electrum wallet.
I recieved the bitcoins...then i want to send my bitcoins to Exodus...I did fill in the recieve adres   but the bitcoins are not delevired!  am i being hacked?


Cube
Rath_
aka BitCryptex
Legendary
*
Offline Offline

Activity: 1876
Merit: 3132



View Profile
August 05, 2019, 10:35:11 AM
Last edit: August 05, 2019, 10:45:46 AM by BitCryptex
 #2

I have updated elctrum (was a pop up within electrum its elf, to upgrade...i did that...and then i transfer money, for bitcoins, from my bank to the Electrum wallet.
I recieved the bitcoins...then i want to send my bitcoins to Exodus...I did fill in the recieve adres   but the bitcoins are not delevired!  am i being hacked?

What version of Electrum do you have right now? Old versions did not notify users of available updates. They are also vulnerable to a phising attack which tricks user to download a fake version of Electrum. Are there any entries in the History tab? Was the transaction to Exodus sent without any errors?
bitmover
Legendary
*
Offline Offline

Activity: 2310
Merit: 5963


bitcoindata.science


View Profile WWW
August 05, 2019, 10:45:51 AM
 #3

Electrum version 4.0 doesn't exist.
Did you download from Electrum.org?

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
TopTort777
Legendary
*
Offline Offline

Activity: 2310
Merit: 1444



View Profile
August 05, 2019, 10:51:28 AM
 #4

Take a look on the topic ⚠⚠️⚠~Beware on active phishing Electrum websites~⚠⚠️⚠ (Collection list updated).

Hope you didnt download your wallet from the sites in the list from that topic. You could have done it, but the hackers attacked you only now (waited till you have something on the balance).

.
.DuelbitsSPORTS.
▄▄▄███████▄▄▄
▄▄█████████████████▄▄
▄██████████████████████▄
██████████████████████████
███████████████████████████
██████████████████████████████
██████████████████████████████
█████████████████████████████
███████████████████████████
█████████████████████████
▀████████████████████████
▀▀███████████████████
██████████████████████████████
██
██
██
██

██
██
██
██

██
██
██
████████▄▄▄▄██▄▄▄██
███▄█▀▄▄▀███▄█████
█████████████▀▀▀██
██▀ ▀██████████████████
███▄███████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
▀█████████████████████▀
▀▀███████████████▀▀
▀▀▀▀█▀▀▀▀
OFFICIAL EUROPEAN
BETTING PARTNER OF
ASTON VILLA FC
██
██
██
██

██
██
██
██

██
██
██
10%   CASHBACK   
          100%   MULTICHARGER   
cube42 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
August 05, 2019, 10:54:46 AM
 #5

i use now 3.3.6   i did use an older one. I opened the programma as usual. I did something in the preferences and suddenly an pop-up appeared which saying that there is an never version of Electrum. I clicked the link showed within the pop-up. It looks as if it was an pop-up from elctrum itself.
I did update it. The only thing i noticed that the icon of the programme istself was a little bit different... i thought that it was because a new icon of a new updated programme....Everything else was exactly the same interface as the one i used to know, so no alarm bells for me. And when i send the bitcoins to an adress i noticed that everything was filled in correctly.
Rath_
aka BitCryptex
Legendary
*
Offline Offline

Activity: 1876
Merit: 3132



View Profile
August 05, 2019, 11:01:25 AM
 #6

i use now 3.3.6   i did use an older one.

That's weird because the latest version is 3.3.8. I would suggest you uninstalling this version and downloading the latest one from the official website just to be sure.

And when i send the bitcoins to an adress i noticed that everything was filled in correctly.

Does your outgoing transaction appear as unconfirmed in the History tab? Can you check if the destination address is the same as it should be?
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
August 05, 2019, 11:01:27 AM
 #7

Did you follow the security guidelines to only download electrum from https://electrum.org and to verify its signature as stated on the website ?
Verifying the signature is the only way to be sure you have the original (non-malicious) version of electrum. This is a mandatory step.

You say your BTC's haven't been delivered. Did they 'leave' your wallet ?
If you look at the history-tab, what do you see ? Do you see an outgoing transaction ? If so, does it have the correct details (e.g. output address) ?

If the transaction details are correct, head over to a block explorer (e.g. https://live.blockcypher.com) and enter the transaction ID, then check whether it is confirmed.
If the TX details are not correct (i.e. not what you have entered), your computer is somehow infected with malware (either malicious electrum or some other kind of malware).

cube42 (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
August 05, 2019, 11:15:45 AM
 #8

It did leave my wallet. But never showed up to my (exodus)adress Transaction was done but to an different adress!
How can that be? i did fill in with the correct adress
bob123
Legendary
*
Offline Offline

Activity: 1624
Merit: 2481



View Profile WWW
August 05, 2019, 11:20:18 AM
 #9

Then your computer is infected with malware.

Did you verify the transaction after pasting the address ?

Clipping malware is quite common. They check your clipping board for BTC addresses and replace them with the attackers one.
Try copying the following address and paste it somewhere (e.g. notepad):
Code:
136jLgnKfTsp94XdPdZqeHzspAqdPc5pLW

If the pasted address is not the same you have copied, you are a victim of such clipping malware.

If the pasted address is the same as the one you have copied, your machine is infected with a different kind of malware.
In this case, check your electrum version. Are you using the installed or standalone version ? Verify the signature (e.g. standalone executable or installer).

kissapig@yahoo.com
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile
August 05, 2019, 12:12:17 PM
 #10

Have been getting a new attack myself today. 
Some kind of coinminer that came from electrum-server.ninja (145.239.44.204, 5002)
traffic description TCP, Port 50002
I have version 3.3.8 and Norton so I can ignore it.
Just wanted you guys to know it was out there.
Lucius
Legendary
*
Offline Offline

Activity: 3248
Merit: 5694


Blackjack.fun🎲


View Profile WWW
August 05, 2019, 12:43:27 PM
 #11

I see OP is edited, and some information other user post are removed. The main question is what link OP visit from that pop-up window, and by his statement that he use now 3.3.6, and bitmover is posting about 4.0.0 he is for sure download fake version. Now is late for any fixing, and only thing which make sense in this situation is hard disk formatting to exclude any possibility of additional infection.

For a better understanding of this problem and how it can be avoided take a few minutes of your time and watch these two videos.

Hardware Wallet vs Malware. Demo of Electrum Phishing & Clipboard Malware
Keep you Bitcoin Safe from Phishing and Scams. Verifying Electrum Download Signatures via GPG4Win


.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Abdussamad
Legendary
*
Offline Offline

Activity: 3612
Merit: 1564



View Profile
August 05, 2019, 01:06:27 PM
 #12

Have been getting a new attack myself today. 
Some kind of coinminer that came from electrum-server.ninja (145.239.44.204, 5002)
traffic description TCP, Port 50002
I have version 3.3.8 and Norton so I can ignore it.
Just wanted you guys to know it was out there.


That's a false positive
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!