shasan (OP)
Copper Member
Legendary
Offline
Activity: 2394
Merit: 1304
Playbet.io - Crypto Casino and Sportsbook
|
|
April 30, 2019, 10:35:11 AM |
|
Electrum Wallet Botnet Infects 150,000 Machines, Steals $4.6 Million in User Funds. See details by clicking on the image:
|
|
|
|
suchmoon
Legendary
Offline
Activity: 3864
Merit: 9090
https://bpip.org
|
|
April 30, 2019, 12:30:29 PM |
|
Again, not a scam accusation. Move.
|
|
|
|
shasan (OP)
Copper Member
Legendary
Offline
Activity: 2394
Merit: 1304
Playbet.io - Crypto Casino and Sportsbook
|
|
April 30, 2019, 12:34:32 PM |
|
Again, not a scam accusation. Move.
Thanks, just moved to bitcoin discussion from scam accusation board. I think now it is okay, if not let me know. Thanks a lot.
|
|
|
|
DeathAngel
Legendary
Offline
Activity: 3304
Merit: 1617
#1 VIP Crypto Casino
|
|
April 30, 2019, 01:36:13 PM |
|
I don’t know why anybody is still using Electrum, this happens all the time. People download a gogus update & BAM, their coins are gone. Makes me sad to see it.
|
|
|
|
BitBustah
|
|
April 30, 2019, 01:47:40 PM |
|
Is this real? Yet another problem with Electrum.
Time to switch to a different wallet, this is unacceptable.
|
|
|
|
TryNinja
Legendary
Offline
Activity: 3024
Merit: 7443
Top Crypto Casino
|
I don’t know why anybody is still using Electrum, this happens all the time. People download a gogus update & BAM, their coins are gone. Makes me sad to see it.
I thought that happened with every kind of software and website? Visit a fake website and BAM, accounts stolen. Download a fake software and BAN, rip passwords, coins and personal data. It’s up for the user to identify what is real/safe and what is not. Core has infected impersonators.
Is this real? Yet another problem with Electrum.
Time to switch to a different wallet, this is unacceptable.
It’s a DDoS attack ffs. Nothing really changed from last time. Did you try reading the article?
|
|
|
|
Beerwizzard
|
|
April 30, 2019, 02:02:10 PM |
|
Again, not a scam accusation. Move.
Thanks, just moved to bitcoin discussion from scam accusation board. I think now it is okay, if not let me know. Thanks a lot. There is a special board on this related to Electrum wallet. There you can even stay in contact with Electrum developers: https://bitcointalk.org/index.php?board=98.0Also it is better to add a link to the source of those news. I would like to see more details. I don’t know why anybody is still using Electrum, this happens all the time. People download a gogus update & BAM, their coins are gone. Makes me sad to see it.
I guess, the same thing would keep happening with every popular Bitcoin wallet or crypto related service. The more people use it - the bigger piece of cake it would be for scammers.
|
|
|
|
shasan (OP)
Copper Member
Legendary
Offline
Activity: 2394
Merit: 1304
Playbet.io - Crypto Casino and Sportsbook
|
|
April 30, 2019, 02:04:45 PM |
|
It is already on the board you mentioned. Also it is better to add a link to the source of those news.
Probably you have not read my post. You can see source link if you click on the image. Thanks.
|
|
|
|
bob123
Legendary
Offline
Activity: 1624
Merit: 2481
|
|
April 30, 2019, 02:16:15 PM |
|
The 'electrum botnet' (what a stupid name chosen from you) doesn't infect anything with malware.
I might get a lot of hate for this statement, but.. People who can't use their common sense and simply just click on 'download' and 'install' just because there is a known name mentioned somewhere, should stay far far away from crypto and should never store any sensitive (or for them valuable) information on an electronic device.
Not just that the phishing attempt is very low-skilled, currently there is just a DoS going on.. no infection, no malware, no stealing funds. If you have your wallet updated to v3.3.3+ (which you should..), you won't even get the cheap phishing message.. just switch to a different server and everything is fine..
|
|
|
|
Genemind
|
|
April 30, 2019, 02:16:21 PM |
|
I used to have electrum wallet, but since previous attacks on it despite their efforts to update their security, it seems that it's really not ideal to use electrum. Stay safe, better to secure your bitcoin on hardware wallet than online wallets.
|
|
|
|
|
JollyGood
Legendary
Offline
Activity: 2730
Merit: 1822
Top Crypto Casino
|
|
April 30, 2019, 07:16:52 PM |
|
I used to have electrum wallet, but since previous attacks on it despite their efforts to update their security, it seems that it's really not ideal to use electrum. Stay safe, better to secure your bitcoin on hardware wallet than online wallets.
What were the previous issues with Electrum and when did they occur?
|
|
|
|
pooya87
Legendary
Offline
Activity: 3640
Merit: 11041
Crypto Swap Exchange
|
|
May 01, 2019, 02:41:26 AM |
|
I used to have electrum wallet, but since previous attacks on it despite their efforts to update their security, it seems that it's really not ideal to use electrum. Stay safe, better to secure your bitcoin on hardware wallet than online wallets.
What were the previous issues with Electrum and when did they occur? the issue was that the electrum servers you connected to could send you any message they liked with any arbitrary contents and your wallet would have shows these messages as received. so some malicious people started exploiting it and started sending links through that message and encouraged people to download a malicious software disguised as "new version" with a fake link. people who fell for that and downloaded this malicious binary without checking the link and the signature of the file (as they should have) lost money. it happened on December last year ( https://github.com/spesmilo/electrum/issues/4968)
|
|
|
|
traderethereum
|
|
May 01, 2019, 04:18:20 AM |
|
I think we need to prevent from the thief that wants to steal our bitcoin from the electrum wallet. I already move all of my bitcoin from electrum to another wallet, and I hope that soon after the developer has fixed the problem, it will not get trouble in the future. But if the wallet is fine and people download the wrong wallet, then the mistake will be on the user side, and they need to double check the links to get the wallet or download the update.
|
|
|
|
moha sasa
Jr. Member
Offline
Activity: 35
Merit: 2
|
|
May 01, 2019, 05:47:23 AM |
|
- I think Electrum was under attack, cause it is one of the best wallet out there. It attract users and so are thieves.
- Any wallet/exchange could suffer from such an attack, the standard here is your knowledge, if you're educated enough you wouldn't lose a single satoshi.
|
|
|
|
Lucius
Legendary
Offline
Activity: 3430
Merit: 6169
Eternal Thanks and Glory to the City of Heroes
|
|
May 01, 2019, 09:23:50 AM |
|
People who can't use their common sense and simply just click on 'download' and 'install' just because there is a known name mentioned somewhere, should stay far far away from crypto and should never store any sensitive (or for them valuable) information on an electronic device.
Exactly, situation with Electrum has just shown that users know a little about basic use of cryptocurrency or just about using PC / internet in a safe way. Fact that even after all warnings and the time that have passed since the beginning of phising attacks some users still become victims, speaks for itself. I would say that some other solution is far better option for crypto wallet, but users who get tricked with this will probably at some point lost coins even with HW by keeping seed in an unsafe way, or by typing it on some fake software like fake Ledger Live.
|
|
|
|
JollyGood
Legendary
Offline
Activity: 2730
Merit: 1822
Top Crypto Casino
|
|
May 01, 2019, 10:11:38 AM |
|
What were the previous issues with Electrum and when did they occur?
the issue was that the electrum servers you connected to could send you any message they liked with any arbitrary contents and your wallet would have shows these messages as received. so some malicious people started exploiting it and started sending links through that message and encouraged people to download a malicious software disguised as "new version" with a fake link. people who fell for that and downloaded this malicious binary without checking the link and the signature of the file (as they should have) lost money. it happened on December last year ( https://github.com/spesmilo/electrum/issues/4968) I see. Thank you for the explanation. If that issue is now over and has been fixed then I see no problem with using Electrum. In the event of using Bitcoin just for checking say for example on a server for ecommerce (address generating and payment checking) purposes where a UI would not even be needed, it would still be a great asset to utilise.
|
|
|
|
pooya87
Legendary
Offline
Activity: 3640
Merit: 11041
Crypto Swap Exchange
|
|
May 02, 2019, 04:23:08 AM |
|
What were the previous issues with Electrum and when did they occur?
the issue was that the electrum servers you connected to could send you any message they liked with any arbitrary contents and your wallet would have shows these messages as received. so some malicious people started exploiting it and started sending links through that message and encouraged people to download a malicious software disguised as "new version" with a fake link. people who fell for that and downloaded this malicious binary without checking the link and the signature of the file (as they should have) lost money. it happened on December last year ( https://github.com/spesmilo/electrum/issues/4968) I see. Thank you for the explanation. If that issue is now over and has been fixed then I see no problem with using Electrum. In the event of using Bitcoin just for checking say for example on a server for ecommerce (address generating and payment checking) purposes where a UI would not even be needed, it would still be a great asset to utilise. there was never a problem with using Electrum before either. the user had to ignore a bunch of very important security measures to actually lose his coins. they had to go to a malicious website which was not the official website they had downloaded Electrum before, then they had to install a software while ignoring the importance of checking digital signatures. and to top it off they had to be holding their coins in an online wallet instead of cold storage. when it comes to wallets the security is not always about how safe the wallet itself is, but it is about how safe and cautious the user is. by simply checking digital signatures and using cold storage more than 90% of the loss cases (in general not just with Electrum) would have been eliminated.
|
|
|
|
JollyGood
Legendary
Offline
Activity: 2730
Merit: 1822
Top Crypto Casino
|
|
May 02, 2019, 10:59:20 AM |
|
there was never a problem with using Electrum before either. the user had to ignore a bunch of very important security measures to actually lose his coins. they had to go to a malicious website which was not the official website they had downloaded Electrum before, then they had to install a software while ignoring the importance of checking digital signatures. and to top it off they had to be holding their coins in an online wallet instead of cold storage.
when it comes to wallets the security is not always about how safe the wallet itself is, but it is about how safe and cautious the user is. by simply checking digital signatures and using cold storage more than 90% of the loss cases (in general not just with Electrum) would have been eliminated. I will not sync a full Bitcoin chain on my hard drive, that is why I prefer Electrum.
|
|
|
|
shasan (OP)
Copper Member
Legendary
Offline
Activity: 2394
Merit: 1304
Playbet.io - Crypto Casino and Sportsbook
|
|
May 02, 2019, 11:21:20 AM |
|
there was never a problem with using Electrum before either. the user had to ignore a bunch of very important security measures to actually lose his coins. they had to go to a malicious website which was not the official website they had downloaded Electrum before, then they had to install a software while ignoring the importance of checking digital signatures. and to top it off they had to be holding their coins in an online wallet instead of cold storage.
when it comes to wallets the security is not always about how safe the wallet itself is, but it is about how safe and cautious the user is. by simply checking digital signatures and using cold storage more than 90% of the loss cases (in general not just with Electrum) would have been eliminated. I will not sync a full Bitcoin chain on my hard drive, that is why I prefer Electrum. If you use electrum then it will not occur any problem until you open any phishing link. If you open any phishing link then you may loss all of your funds.
|
|
|
|
|