Bitcoin Forum
May 08, 2024, 06:16:05 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: The Electrum LTC website was hacked in Jul 31  (Read 886 times)
oblivi (OP)
Hero Member
*****
Offline Offline

Activity: 700
Merit: 501


View Profile
August 02, 2017, 03:52:01 PM
Last edit: August 03, 2017, 06:33:08 PM by oblivi
 #1

Im surprised that I haven't seen this mentioned. This is serious. I have always thought that falling for a man in the middle attack is extremely unlucky, but some people may have been affected. There was a brief period where the executable was compromised. If you downloaded anything from the Electrum website in Jul 31, I would definitely format my computer.

Official statement as follows:

https://electrum-ltc.org/#notice

Quote

IMPORTANT NOTICE

On July 31, around 13:00 UTC, an attacker exploited a vulnerability in the virtualization software employed by this website's host to replace the sources and Windows binaries of Electrum-LTC 2.8.3.5 with modified versions. We were made aware of the issue by 17:30 UTC, and promptly restored the original files. We then proceeded to carefully move the website to a new host that would be immune to said vulnerabilities.

If you downloaded a source distribution or a Windows binary of Electrum-LTC 2.8.3.5 from this website during the above time range, and did not verify its digital signature, your computer may have been infected by malware, and you should take action immediately. Note that the digital signatures have been available and valid all along.
1715148965
Hero Member
*
Offline Offline

Posts: 1715148965

View Profile Personal Message (Offline)

Ignore
1715148965
Reply with quote  #2

1715148965
Report to moderator
1715148965
Hero Member
*
Offline Offline

Posts: 1715148965

View Profile Personal Message (Offline)

Ignore
1715148965
Reply with quote  #2

1715148965
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715148965
Hero Member
*
Offline Offline

Posts: 1715148965

View Profile Personal Message (Offline)

Ignore
1715148965
Reply with quote  #2

1715148965
Report to moderator
1715148965
Hero Member
*
Offline Offline

Posts: 1715148965

View Profile Personal Message (Offline)

Ignore
1715148965
Reply with quote  #2

1715148965
Report to moderator
Niya
Hero Member
*****
Offline Offline

Activity: 811
Merit: 512


Enhalo Mining


View Profile WWW
August 02, 2017, 04:04:55 PM
 #2

Nobody mentioned it because that's the Electrum version for Litecoin.
Electrum for BTC and Electrum for LTC (this one you are talking about) are developed by different teams. This wallet is a forked version of Electrum (BTC) wallet which works for Litecoin. Nothing to worry about if you use Electrum for Bitcoin.
oblivi (OP)
Hero Member
*****
Offline Offline

Activity: 700
Merit: 501


View Profile
August 02, 2017, 05:25:29 PM
 #3

Nobody mentioned it because that's the Electrum version for Litecoin.
Electrum for BTC and Electrum for LTC (this one you are talking about) are developed by different teams. This wallet is a forked version of Electrum (BTC) wallet which works for Litecoin. Nothing to worry about if you use Electrum for Bitcoin.

Well, I just realized I made the mistake of thinking this was related to BTC. It is indeed the LTC wallet which I assume is just an Electrum fork for LTC...

In any case, this is a great day to be reminded of the possibility of a man in the middle attack happening.

You should always check the checksum of the executable, assuming you are not going to build the code yourself, otherwise nasty things can happen if you are extremely unlucky to be exposed to the attack while the people that host the site realize the checksums are different from what they signed.
jackfruit
Sr. Member
****
Offline Offline

Activity: 416
Merit: 250


View Profile
August 02, 2017, 08:15:46 PM
 #4

From the hacks just electrum wasnt effected with that its also effected. Who changed files on site, couldnt change the digital signatures? How we gonna know signatures are correct
oblivi (OP)
Hero Member
*****
Offline Offline

Activity: 700
Merit: 501


View Profile
August 03, 2017, 12:56:46 PM
 #5

From the hacks just electrum wasnt effected with that its also effected. Who changed files on site, couldnt change the digital signatures? How we gonna know signatures are correct


The developers of Electrum Litecoin have already confirmed that the information of the website regarding the hack of July 31 is official and confirmed. The developers have PGP keys to prove they are real. You should format your computeri f you downloaded anything during July 31 on that website, who knows what kind of gode was put on there in the brief period of time, but chances are you didn't get affected.
ThomasV80
Member
**
Offline Offline

Activity: 133
Merit: 10


View Profile
August 03, 2017, 03:04:12 PM
 #6

really ? Electrum site has been hacked?
How about the offline wallet (wallet desktop) of electrum?
harizen
Legendary
*
Offline Offline

Activity: 3122
Merit: 1398


For support ➡️ help.bc.game


View Profile
August 03, 2017, 03:12:56 PM
 #7

really ? Electrum site has been hacked?
How about the offline wallet (wallet desktop) of electrum?

As far as the above posts was concerned, it was only applied to Electrum for Litecoin and not on Electrum for Bitcoin. Im not aware of this until I read this post.

It will affect your desktop wallet (or computer) if you download anything from the website from July 31 onwards.

You should format your computeri f you downloaded anything during July 31 on that website, who knows what kind of gode was put on there in the brief period of time, but chances are you didn't get affected.


█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....LOTTERY..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
ThomasV80
Member
**
Offline Offline

Activity: 133
Merit: 10


View Profile
August 03, 2017, 04:11:04 PM
 #8

really ? Electrum site has been hacked?
How about the offline wallet (wallet desktop) of electrum?

As far as the above posts was concerned, it was only applied to Electrum for Litecoin and not on Electrum for Bitcoin. Im not aware of this until I read this post.

It will affect your desktop wallet (or computer) if you download anything from the website from July 31 onwards.

You should format your computeri f you downloaded anything during July 31 on that website, who knows what kind of gode was put on there in the brief period of time, but chances are you didn't get affected.



ok, thank you for information friend
HI-TEC99
Legendary
*
Offline Offline

Activity: 2772
Merit: 2846



View Profile
August 03, 2017, 05:29:24 PM
 #9

Nobody mentioned it because that's the Electrum version for Litecoin.
Electrum for BTC and Electrum for LTC (this one you are talking about) are developed by different teams. This wallet is a forked version of Electrum (BTC) wallet which works for Litecoin. Nothing to worry about if you use Electrum for Bitcoin.

Well, I just realized I made the mistake of thinking this was related to BTC. It is indeed the LTC wallet which I assume is just an Electrum fork for LTC...
.

Please change this thread's title to say "The Electrum-LTC website was hacked in Jul 31" instead of "The Electrum website was hacked in Jul 31".

The current title is misleading, and will make electrum for Bitcoin users unnecessarily panic. Please make it clear it was the litecoin version that was compromised.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!