|
SuperInvestor (OP)
Jr. Member
Offline
Activity: 66
Merit: 2
|
|
December 27, 2018, 03:23:10 AM |
|
anyeone? please help me , i am willing to pay ones my funds will get back to me
|
|
|
|
TryNinja
Legendary
Offline
Activity: 3024
Merit: 7443
Top Crypto Casino
|
|
December 27, 2018, 03:24:16 AM |
|
This isn't the original Electrum. You fell for a fake version of it. Unfortunately, there is nothing you can do. Your coins are gone and your computer is compromised. Reinstall your OS and create a new wallet from the ORIGINAL Electrum. This is the ONLY legit Github link: https://github.com/spesmilo/electrum
|
|
|
|
|
SuperInvestor (OP)
Jr. Member
Offline
Activity: 66
Merit: 2
|
|
December 27, 2018, 03:29:16 AM |
|
This isn't the original Electrum. You fell for a fake version of it. Unfortunately, there is nothing you can do. Your coins are gone and your computer is compromised. Reinstall your OS and create a new wallet from the ORIGINAL Electrum. This is the ONLY legit Github link: https://github.com/spesmilo/electrumsir but i swear, i do really received an notification on my old electrum original that it needs to be updated.. then i do follow the link given from there.. oh no ... sir does electrum company can help me with this>? do they own this https://github.com/electrum-project or not?
|
|
|
|
Abdussamad
Legendary
Offline
Activity: 3682
Merit: 1580
|
|
December 27, 2018, 03:32:17 AM |
|
spesmilo one is the real one. also there are no update notifications anymore. that was removed many versions back because of privacy concerns. you downloaded a fake electrum from some site and then updated the fake electrum! the latest version is 3.3.2 https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES
|
|
|
|
SuperInvestor (OP)
Jr. Member
Offline
Activity: 66
Merit: 2
|
|
December 27, 2018, 03:40:10 AM |
|
i just woked up very happy this evening after isleep a few hour only, i dont know this was going to happen. cant stop crying now , it takes me 15 days for those funds to be earned. i cant believe this. i downloaded that wallet from https://electrum.org/ , anyways i need to accept this. by the way i am Jack Henry from texas, im 68 years old. Thankyou for the answers. have a nice day to all
|
|
|
|
|
Heydude1
Newbie
Offline
Activity: 10
Merit: 10
|
|
December 27, 2018, 05:04:45 AM |
|
spesmilo one is the real one. also there are no update notifications anymore. that was removed many versions back because of privacy concerns. you downloaded a fake electrum from some site and then updated the fake electrum! the latest version is 3.3.2 https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTESJust to be clear this just happened to me as well. I just made an account to comment here actually. I have the same version of electrum i always use, nothing changed today. Went to go send coin and received a pop up error message WITHIN THE REAL ELECTRUM that i cannot sent the payment until i upgrade due to security issues. I am usually diligent about this stuff but it was a long day and i was in a hurry. Github even has the links verified on that phishing one so i just downloaded. Sent the payment again in the new one and the money was gone 10 minutes later. It's my fault for using that one without doing more verification...but something happened where someone was able to send an alert/pop up through the real electrum. I don't understand how that happened.
|
|
|
|
SuperInvestor (OP)
Jr. Member
Offline
Activity: 66
Merit: 2
|
|
December 27, 2018, 05:44:50 AM |
|
spesmilo one is the real one. also there are no update notifications anymore. that was removed many versions back because of privacy concerns. you downloaded a fake electrum from some site and then updated the fake electrum! the latest version is 3.3.2 https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTESJust to be clear this just happened to me as well. I just made an account to comment here actually. I have the same version of electrum i always use, nothing changed today. Went to go send coin and received a pop up error message WITHIN THE REAL ELECTRUM that i cannot sent the payment until i upgrade due to security issues. I am usually diligent about this stuff but it was a long day and i was in a hurry. Github even has the links verified on that phishing one so i just downloaded. Sent the payment again in the new one and the money was gone 10 minutes later. It's my fault for using that one without doing more verification...but something happened where someone was able to send an alert/pop up through the real electrum. I don't understand how that happened. Exactly happened to me last hour. the popup message said that my electrum needs to be updated, and if not i cant send out funds so i followed the displayed link on that popup notification and its https://github.com/electrum-project/electrum/releases/tag/3.4.1 , so yeah. Electrum seems not secured enough, i am not saying the main wallet but that popup notification. How the hell gets it there inside the ORIGINAL SOFTWARE OF ELECTRUM? by the way, i reformat my pc and i go here to download new electrum ORIGINAL AND VERIFIED . https[Suspicious link removed] but seems cant access the site. 'This site can’t be reached' what's happening?
|
|
|
|
Heydude1
Newbie
Offline
Activity: 10
Merit: 10
|
|
December 27, 2018, 05:48:03 AM |
|
Yea i am not sure but also cannot download electrum from the site right now either.
My original electrum that i got the pop up on has been on here since 3.2.3 was released. i haven't updated or downloaded any new ones before tonight so i don't understand where the popup came from as it was original software
|
|
|
|
TryNinja
Legendary
Offline
Activity: 3024
Merit: 7443
Top Crypto Casino
|
Electrum seems not secured enough, i am not saying the main wallet but that popup notification. How the hell gets it there inside the ORIGINAL SOFTWARE OF ELECTRUM?
It was an exploit the hacker found out. He created a few Electrum servers which handled a customized error message when you tried to send a transaction. Unfortunately, you could make the custom error message show up as an Electrum pop up message. So the hacker created the fake "update right now" warning and made it show up for those who were connected to his server. This was already fixed in the latest version 3.3.2, but unfortunately, you were one of the victims of the hacker. More info here: https://github.com/spesmilo/electrum/issues/4968
|
|
|
|
Heydude1
Newbie
Offline
Activity: 10
Merit: 10
|
|
December 27, 2018, 07:04:52 AM |
|
Electrum seems not secured enough, i am not saying the main wallet but that popup notification. How the hell gets it there inside the ORIGINAL SOFTWARE OF ELECTRUM?
It was an exploit the hacker found out. He created a few Electrum servers which handled a customized error message when you tried to send a transaction. Unfortunately, you could make the custom error message show up as an Electrum pop up message. So the hacker created the fake "update right now" warning and made it show up for those who were connected to his server. This was already fixed in the latest version 3.3.2, but unfortunately, you were one of the victims of the hacker. More info here: https://github.com/spesmilo/electrum/issues/4968Yep, although i am usually good about catching things like this i foolishly fell for it this time. And i downloaded and opened the 3.4.1 file. Looked just like electrum and so i sent payment and my wallet got drained. now i am just worried if there was something else attached to the file but i don't think so as of now because it opened just like regular electrum did with one single file in the drive/folder(on mac). i think it was just an exploited client that routed all payments sent to them. like i said before i may end up wiping my drive just in case
|
|
|
|
adaseb
Legendary
Offline
Activity: 3878
Merit: 1733
|
|
December 27, 2018, 09:15:42 AM |
|
Shouldn't this exploit be made into a sticky since it seems like a severe security concern?
Wonder if it only stole from those who used electrum as an online wallet instead of electrum offline (cold storage). Would cold storage save you in this case?
Its possible the fake software could display the correct destination BTC you entered, get you to sign the transaction offline BUT if you don't pay attention on the offline computer, there might be a entirely different destination BTC entered there that gets signed and later broadcasted online and funds get stolen.
|
|
|
|
Lucius
Legendary
Offline
Activity: 3430
Merit: 6152
Crypto Swap Exchange🈺
|
|
December 27, 2018, 11:20:27 AM |
|
It's not fixed yet,: Hours after we were sent the screenshot, we silently made mitigations in 5248613 and 5dc240d; and released 3.3.2. This is not a true fix, but the more proper fix of using error codes would entail upgrading the whole federated server ecosystem out there...
We did not publicly disclose this until now, as around the time of the 3.3.2 release, the attacker stopped; however they now started the attack again. So latest version of Electrum is still 3.3.2 https://electrum.org/#download and this attack is still possible, only change is how it is display to users now. I must admit that this is something that what was never supposed to happen, cheap trick for for naive users. Download Electrum only from official site, and even then check and verify files. Do not download any update for Electrum, even if you get warning from legit Electrum wallet, it is expolit that hacker use to get your seed/private keys!
|
|
|
|
bitcoinfuck
Full Member
Offline
Activity: 634
Merit: 106
Europe Belongs To Christians
|
|
December 27, 2018, 01:03:14 PM |
|
looks like he already scammed 15 BTC, sad brother, but there is nothing that will help you now
|
|
|
|
|
bittraffic
|
|
December 27, 2018, 02:32:19 PM |
|
Jesus! Well its all gone now, you couldn't expect the hacker to return it of course. Consider it lost forever. All the while you thought its safe when it can actually be faked, its actually easy to fall for it because it looks very legit. I thought its just the online wallet that can be used for phishing, installing a desktop wallet was the safest I know but now, it can be subjected to suspicions.
|
|
|
|
killerjoegreece
Legendary
Offline
Activity: 1680
Merit: 1010
Professional Native Greek Translator (2000+ done)
|
|
December 27, 2018, 02:48:02 PM |
|
Jesus! Well its all gone now, you couldn't expect the hacker to return it of course. Consider it lost forever. All the while you thought its safe when it can actually be faked, its actually easy to fall for it because it looks very legit. I thought its just the online wallet that can be used for phishing, installing a desktop wallet was the safest I know but now, it can be subjected to suspicions.
The Bitcoin codebase is still so young right now and comparable to the early internet. Devs will learn from these mistakes and carry on. I hope no more people loose money to this exploit.
|
|
|
|
bL4nkcode
Copper Member
Legendary
Offline
Activity: 2142
Merit: 1307
Limited in number. Limitless in potential.
|
|
December 27, 2018, 03:17:28 PM |
|
Jesus! Well its all gone now, you couldn't expect the hacker to return it of course. Consider it lost forever. All the while you thought its safe when it can actually be faked, its actually easy to fall for it because it looks very legit. I thought its just the online wallet that can be used for phishing, installing a desktop wallet was the safest I know but now, it can be subjected to suspicions.
The Bitcoin codebase is still so young right now and comparable to the early internet. Devs will learn from these mistakes and carry on. I hope no more people loose money to this exploit. Obviously, hardware wallet can prevent this to happen if ever people have them, even though they can afford to buy it but due to some reason in which they prioritized, they didn't and they lost this much.
|
|
|
|
|