Bitcoin Forum
May 03, 2024, 11:31:04 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Security Issue with Electrum Wallet  (Read 326 times)
vnck25 (OP)
Member
**
Offline Offline

Activity: 392
Merit: 11


View Profile
January 07, 2018, 03:16:32 PM
 #1

Since there is a security issue with the electrum wallet, is there  a way to check our BTC balance without signing into the wallet?
 I know there is a way for MyEtherWallet where you can use Etherscan.io to check the balance of ETH and all the ERC20 tokens in that wallet. However since electrum changes its public address after every transaction is this something possible? Can we use blockchain.info to do this? Please shed some light on this issue.

Thanks!
1714735864
Hero Member
*
Offline Offline

Posts: 1714735864

View Profile Personal Message (Offline)

Ignore
1714735864
Reply with quote  #2

1714735864
Report to moderator
There are several different types of Bitcoin clients. The most secure are full nodes like Bitcoin Core, which will follow the rules of the network no matter what miners do. Even if every miner decided to create 1000 bitcoins per block, full nodes would stick to the rules and reject those blocks.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714735864
Hero Member
*
Offline Offline

Posts: 1714735864

View Profile Personal Message (Offline)

Ignore
1714735864
Reply with quote  #2

1714735864
Report to moderator
1714735864
Hero Member
*
Offline Offline

Posts: 1714735864

View Profile Personal Message (Offline)

Ignore
1714735864
Reply with quote  #2

1714735864
Report to moderator
BitcoinSupremo
Copper Member
Hero Member
*****
Offline Offline

Activity: 1442
Merit: 529


View Profile
January 07, 2018, 03:52:53 PM
 #2

Since there is a security issue with the electrum wallet, is there  a way to check our BTC balance without signing into the wallet?
 I know there is a way for MyEtherWallet where you can use Etherscan.io to check the balance of ETH and all the ERC20 tokens in that wallet. However since electrum changes its public address after every transaction is this something possible? Can we use blockchain.info to do this? Please shed some light on this issue.

Thanks!

Yes you can. There 's no issue if you open electrum while you haven't open up any browser tab. So what you do is open electrum wallet and copy the btc address you want to check to a notepad document. Close electrum and then open up a browser, go to blockchain.info and copy the btc address you want to check. That's how you do it. However upgrade, as this is an advice from ThomasV ,the creator of Electrum.
bitperson
Full Member
***
Offline Offline

Activity: 210
Merit: 119


View Profile
January 07, 2018, 03:57:30 PM
 #3

Blockchain explorers usually allow you to check one address at a time. The blockchain doesn't 'know' which addresses 'belong' to your wallet. However, https://www.blockonomics.co allows you to paste in several addresses at once, making it a convenient tool for checking your wallet balance.

How to ask questions the smart way
When you’re happy with the answers in a thread you have started, please click ‘lock topic’ to prevent spam.
1AWrZWnN4ThpGB5z24WTzsoZRMqvLpDGYU
ranochigo
Legendary
*
Offline Offline

Activity: 2954
Merit: 4165


View Profile
January 07, 2018, 11:04:26 PM
Last edit: January 08, 2018, 08:50:06 AM by ranochigo
 #4

Since there is a security issue with the electrum wallet, is there  a way to check our BTC balance without signing into the wallet?
 I know there is a way for MyEtherWallet where you can use Etherscan.io to check the balance of ETH and all the ERC20 tokens in that wallet. However since electrum changes its public address after every transaction is this something possible? Can we use blockchain.info to do this? Please shed some light on this issue.

Thanks!

Yes you can. There 's no issue if you open electrum while you haven't open up any browser tab. So what you do is open electrum wallet and copy the btc address you want to check to a notepad document. Close electrum and then open up a browser, go to blockchain.info and copy the btc address you want to check. That's how you do it. However upgrade, as this is an advice from ThomasV ,the creator of Electrum.
You should do this offline actually. With the exploit, anyone can get your seeds by guessing the correct port. Anyone can run an attack on your IPs actually, doesn't have to be a website. The website method is for the attacker to target anyone who goes to the website.

Sorry, the RPC is open to the local machine only. This would only work where there is either a malicious program on your computer or if you accessed a website and they used CORS to scan and connect to your computer.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
leopard2
Legendary
*
Offline Offline

Activity: 1372
Merit: 1014



View Profile
January 07, 2018, 11:09:43 PM
Merited by ABCbits (1)
 #5

no need to be complicated just use Electrum 304 which is fixed...

Truth is the new hatespeech.
vnck25 (OP)
Member
**
Offline Offline

Activity: 392
Merit: 11


View Profile
January 08, 2018, 12:31:07 AM
 #6

no need to be complicated just use Electrum 304 which is fixed...

Thank you very much for your reply!
keyboard warrior
Sr. Member
****
Offline Offline

Activity: 266
Merit: 251


View Profile
January 08, 2018, 02:30:59 AM
 #7

no need to be complicated just use Electrum 304 which is fixed...

Thank you very much for your reply!

It's now version 3.0.5 you need to upgrade to. They rushed version 3.0.4 then a day later discovered the bug wasn't completely fixed in it.
zenyfomax1
Jr. Member
*
Offline Offline

Activity: 98
Merit: 1


View Profile
January 08, 2018, 06:01:37 AM
 #8

no need to be complicated just use Electrum 304 which is fixed...

Thank you very much for your reply!

It's now version 3.0.5 you need to upgrade to. They rushed version 3.0.4 then a day later discovered the bug wasn't completely fixed in it.

electrum is one of the (if not *the*) most popular desktop wallets for bitcoin right? this doesn't look very good...
Kakmakr
Legendary
*
Offline Offline

Activity: 3444
Merit: 1957

Leading Crypto Sports Betting & Casino Platform


View Profile
January 08, 2018, 07:15:07 AM
 #9

no need to be complicated just use Electrum 304 which is fixed...

Thank you very much for your reply!

It's now version 3.0.5 you need to upgrade to. They rushed version 3.0.4 then a day later discovered the bug wasn't completely fixed in it.

electrum is one of the (if not *the*) most popular desktop wallets for bitcoin right? this doesn't look very good...

I beg to differ. I think the most used wallet is the Blockchain.info wallet and that site has had it's fair share of troubles in the past and it is still standing. ^smile^

You have to worry, when exploits like this is not discovered and people start losing coins on these platforms. Most of these wallet providers are using Open Source software, so it is pretty hard to hide these exploits. ^smile^ 

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
TheQuin
Hero Member
*****
Offline Offline

Activity: 2576
Merit: 882


Freebitco.in Support https://bit.ly/2I9BVS2


View Profile WWW
January 08, 2018, 09:18:53 AM
 #10

It's now version 3.0.5 you need to upgrade to. They rushed version 3.0.4 then a day later discovered the bug wasn't completely fixed in it.

That is not entirely correct. They released 3.0.4 which disabled the RPC server vulnerability so it is safe to use. The 3.0.5 is a fix rather than just disabling. Either version means you are safe. The rushed 3.0.4 to get a safe version available as soon as possible they didn't discover "the bug wasn't completely fixed in it", they always knew that they would then release the full fix later.



freebitcoin.TO WIN A  LAMBORGHINI!..

.
                                ▄▄▄▄▄▄▄▄▄▄███████████▄▄▄▄▄
                    ▄▄▄▄▄██████████████████████████████████▄▄▄▄
                    ▀██████████████████████████████████████████████▄▄▄
                    ▄▄████▄█████▄████████████████████████████▄█████▄████▄▄
                    ▀████████▀▀▀████████████████████████████████▀▀▀██████████▄
                      ▀▀▀████▄▄▄███████████████████████████████▄▄▄██████████
                           ▀█████▀  ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀  ▀█████▀▀▀▀▀▀▀▀▀▀
                   ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
ranochigo
Legendary
*
Offline Offline

Activity: 2954
Merit: 4165


View Profile
January 08, 2018, 10:01:04 AM
Merited by ABCbits (1)
 #11

That is not entirely correct. They released 3.0.4 which disabled the RPC server vulnerability so it is safe to use. The 3.0.5 is a fix rather than just disabling. Either version means you are safe. The rushed 3.0.4 to get a safe version available as soon as possible they didn't discover "the bug wasn't completely fixed in it", they always knew that they would then release the full fix later.
It wasn't fixed. Even though CORS is disabled, the vulnerability can still be exploited by using POST request. It's just made more difficult for websites to exploit but it's still possible. 3.0.4 disables the ability to trigger a CORS preflight but didn't disable JsonRPC. 3.0.5 disabled JSONRPC commands.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
zenyfomax1
Jr. Member
*
Offline Offline

Activity: 98
Merit: 1


View Profile
January 08, 2018, 10:47:10 AM
 #12

no need to be complicated just use Electrum 304 which is fixed...

Thank you very much for your reply!

It's now version 3.0.5 you need to upgrade to. They rushed version 3.0.4 then a day later discovered the bug wasn't completely fixed in it.

electrum is one of the (if not *the*) most popular desktop wallets for bitcoin right? this doesn't look very good...

I beg to differ. I think the most used wallet is the Blockchain.info wallet and that site has had it's fair share of troubles in the past and it is still standing. ^smile^

You have to worry, when exploits like this is not discovered and people start losing coins on these platforms. Most of these wallet providers are using Open Source software, so it is pretty hard to hide these exploits. ^smile^ 

blockchain.info is web-based, am i correct? i was specifically referring to desktop wallet.
lionelho
Full Member
***
Offline Offline

Activity: 135
Merit: 100



View Profile
January 08, 2018, 01:00:20 PM
 #13

That is not entirely correct. They released 3.0.4 which disabled the RPC server vulnerability so it is safe to use. The 3.0.5 is a fix rather than just disabling. Either version means you are safe. The rushed 3.0.4 to get a safe version available as soon as possible they didn't discover "the bug wasn't completely fixed in it", they always knew that they would then release the full fix later.
It wasn't fixed. Even though CORS is disabled, the vulnerability can still be exploited by using POST request. It's just made more difficult for websites to exploit but it's still possible. 3.0.4 disables the ability to trigger a CORS preflight but didn't disable JsonRPC. 3.0.5 disabled JSONRPC commands.

So now 3.0.5 completely fixed the problem? BTW, is the Android wallet required to upgrade also?

DeepOnion    ▬▬  Anonymous and Untraceable  ▬▬    ENJOY YOUR PRIVACY  •  JOIN DEEPONION
▐▐▐▐▐▐▐▐   ANN  Whitepaper  Facebook  Twitter  Telegram  Discord    ▌▌▌▌▌▌▌▌
Get $ONION  (✔Cryptopia  ✔KuCoin)  |  VoteCentral  Register NOW!  |  Download DeepOnion
ranochigo
Legendary
*
Offline Offline

Activity: 2954
Merit: 4165


View Profile
January 08, 2018, 01:46:22 PM
 #14

So now 3.0.5 completely fixed the problem? BTW, is the Android wallet required to upgrade also?
Yes. The problem stems from the fact that the JSONRPC wasn't password protected. Android is affected in the same way, you have to update. The latest version disables the JSONRPC for Android.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
joshfraser
Newbie
*
Offline Offline

Activity: 9
Merit: 0


View Profile WWW
January 08, 2018, 11:21:45 PM
 #15

Where can I read more about this security issue?
exstasie
Legendary
*
Offline Offline

Activity: 1806
Merit: 1521


View Profile
January 08, 2018, 11:56:17 PM
 #16

Where can I read more about this security issue?

You can read about the issue on Electrum's Github here:
Quote
The JSONRPC interface is currently completely unprotected, I believe it should be a priority to add at least some form of password protection.

no need to be complicated just use Electrum 304 which is fixed...

Less than a day later, a new version was released, and the developers stated that 3.0.4 didn't fully address the vulnerability. That's why my gut reaction to these disclosures is to shut everything down, make sure networks are completely disabled, and shelter in place.

My Electrum funds are all in forced-HODL mode right now. I'll see how things look in a week or two. Tongue

Captain_Planet
Full Member
***
Offline Offline

Activity: 448
Merit: 102



View Profile
January 09, 2018, 01:01:42 AM
 #17

I have upgraded the electrum wallet. now let me know what should I do next? May I move my funds out or avoid loggin in anymore for a few days or after updating problem is solved and I am safe now? Please let me know.
dado7
Full Member
***
Offline Offline

Activity: 322
Merit: 141


View Profile
January 10, 2018, 07:33:54 AM
 #18

Blockchain explorers usually allow you to check one address at a time. The blockchain doesn't 'know' which addresses 'belong' to your wallet. However, https://www.blockonomics.co allows you to paste in several addresses at once, making it a convenient tool for checking your wallet balance.

Always check your balance this way. For Ethereum and ERC20 coins you can use Ethporer or Etherscan. Never input your private keys anywhere more then absolutely neccessary.
Also, 3.0.5. version of Electrum wallet was upgraded to clear the risk so you can download it and safely use.

Also, just as a simple security advice - never open a browser and bitcoin wallet at the same time.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!