Bitcoin Forum
December 09, 2019, 03:09:48 PM *
News: Latest Bitcoin Core release: 0.19.0.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: How to avoid Electrum Hack?  (Read 144 times)
jupiter9
Jr. Member
*
Offline Offline

Activity: 62
Merit: 6


View Profile
November 27, 2019, 01:56:13 AM
 #1

Hi! I'm new and i would like to install Electrum. But when i was reading Electrum threads i found out that Electrum had a very clever hack. How to avoid that? I'm noob at this, i don't have any computer skills. Just some basic knowledge. Am i safe just to download the newest version of Electrum? Is the hack only found on the older versions?
1575904188
Hero Member
*
Offline Offline

Posts: 1575904188

View Profile Personal Message (Offline)

Ignore
1575904188
Reply with quote  #2

1575904188
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1575904188
Hero Member
*
Offline Offline

Posts: 1575904188

View Profile Personal Message (Offline)

Ignore
1575904188
Reply with quote  #2

1575904188
Report to moderator
1575904188
Hero Member
*
Offline Offline

Posts: 1575904188

View Profile Personal Message (Offline)

Ignore
1575904188
Reply with quote  #2

1575904188
Report to moderator
1575904188
Hero Member
*
Offline Offline

Posts: 1575904188

View Profile Personal Message (Offline)

Ignore
1575904188
Reply with quote  #2

1575904188
Report to moderator
jackg
Copper Member
Legendary
*
Offline Offline

Activity: 1582
Merit: 1358


https://bit.ly/2FR9nyn - free python tutorials


View Profile
November 27, 2019, 02:13:38 AM
Merited by jupiter9 (1)
 #2

Yeah the "hack" (phishing attack) only affected electrum versions before 3.3.4. Any new versions are safe to download and install from the electrum.org website.

You can also learn how to verify signatures of the release on that site too which is recommended to keep your funds safer (you only have to do it once when you install and each time you upgrade).

HCP
Legendary
*
Offline Offline

Activity: 1176
Merit: 1984

<insert witty quote here>


View Profile
November 27, 2019, 02:48:31 AM
 #3

You can also learn how to verify signatures of the release on that site too which is recommended to keep your funds safer (you only have to do it once when you install and each time you upgrade).
And there is a very thorough, step by step guide (with screenshots) on how to verify the digital signatures of Electrum releases for Windows available here: https://bitcoinelectrum.com/how-to-verify-your-electrum-download/

And it also provides guidance for verifying the signatures on Linux, Android and MacOS

pooya87
Legendary
*
Offline Offline

Activity: 1848
Merit: 2105


Remember tonight for it's the beginning of forever


View Profile
November 27, 2019, 05:40:37 AM
Merited by mocacinno (1)
 #4

keep in mind that this is not an Electrum specific problem and what you are referring to as "electrum hack" was not a hack at all. the problem is a common among every software one that means whenever you download the fake application instead of the real one you are at risk. and that was the problem, people were downloading the fake Electrum version from a fake website and installed that without checking its validity.
so obviously the solution to fight this problem is checking "authenticity" of what you download and that check is done using PGP signatures as others explained.

jupiter9
Jr. Member
*
Offline Offline

Activity: 62
Merit: 6


View Profile
November 27, 2019, 09:13:56 AM
 #5

keep in mind that this is not an Electrum specific problem and what you are referring to as "electrum hack" was not a hack at all. the problem is a common among every software one that means whenever you download the fake application instead of the real one you are at risk. and that was the problem, people were downloading the fake Electrum version from a fake website and installed that without checking its validity.
so obviously the solution to fight this problem is checking "authenticity" of what you download and that check is done using PGP signatures as others explained.
Ok, thank you all. I understand it's because downloading the fake application but many didn't notice that because it was very well designed. Because i'm a noob at this things i wanted to ask you how to avoid that. So if i download the latest version i should be fine? Or at least it was safer before to download the newest version?
HCP
Legendary
*
Offline Offline

Activity: 1176
Merit: 1984

<insert witty quote here>


View Profile
November 27, 2019, 09:35:57 AM
 #6

Yes... download the latest version... currently 3.3.8 from https://electrum.org/#download

Then follow the instructions as outlined above to make sure that you verify that you have indeed downloaded a "real" version of Electrum and not a fake one, by verifying the digital signature of the downloaded file.

Pmalek
Legendary
*
Offline Offline

Activity: 1148
Merit: 1185



View Profile
November 27, 2019, 10:09:31 AM
 #7

Just make sure that you never click on any links in Electrum or in any other software that can lead to you downloading a fake version that will result in loss of funds. Same thing goes for emails. Don't expect free money and use your sound judgement. You have to work for your money in real life so don't believe those who promise you free money online.

Always double check any information you are not sure about on official sources and only rely on official sources. Electrum website in this case. Ask on the forum before doing something you might regret.   

████████████████████████████
████████▀▀ █▀ █▀ ▀██████████
█████████▄ ▄▄▄▄▄▄███████████
██████████▀     ▀  ▀████████
███████▀ ▀  ▄█▀▀▀█▀▀████████
██████▄      █▄  ▀▀  ▀██████
██████         ▄▄█▄ ▄ ▀█████
█████ ▄         ▀▀ ▄ ▀ █████
██████▌          █▀█▀ ▐█████
███████  ▄▌         ▄ ██████
████████▄█         ▄████████
█████████▀     ▄▄ ▄█████████
████████████████████████████
.JACKMATE'S...........
.
MAJESTIC..
████████████████████████
███████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
.
..WIN 1 BITCOIN ON EVERY PREMIER LEAGUE MATCHDAY..
████████████████████████████████
████████████▀█▀ ▀█▀█▀███████████
███████████▄ ▄▄▄▄▄▄▄████████████
███████████▀▀▄▄▄▄▄▄▄▄███████████
█████████▀▄ ██▀▄▄▄ ▀ ▄▀█████████
███████▀ ▀█████▄▄▄█▄▄▄██████████
███████▀▄████████▀  ▀█ █▐███████
███████ ▀█████████▄█▀▀██ ███████
████████ ███▀██████ ▄ ██ ███████
████████▌▐▀▄ ██████████ ▄███████
█████████▄██▌▐█████▀██ █████████
████████████▄▀▀▀▀▀▄ ▀▄██████████
████████████████████████████████
.
.JOIN US - IT'S FREE! .
Lucius
Legendary
*
Offline Offline

Activity: 1624
Merit: 1404


Fortis Fortuna Adiuvat


View Profile WWW
November 27, 2019, 11:46:02 AM
 #8

jupiter9, if you have a clean device (PC or smartphone), and you download from official site+verify files, then you may consider yourself relatively safe. You should know that Electrum is a very popular crypto wallet, and hackers are constantly looking for ways to steal users' coins.

For some small amounts of coins, a desktop wallet is something that can be recommended, but if you have plans to be your own bank and keep a few hundred or thousands of dollars worth crypto, my advice is to invest in hardware wallet. Price for Ledger Nano S is just around $45 in the next few days.

BitMaxz
Legendary
*
Offline Offline

Activity: 1638
Merit: 1278


Beware on fake ledger nano, trezor and electrum.


View Profile WWW
November 27, 2019, 04:23:06 PM
 #9

Additional to the above posts:

Not only verifying and downloading the Electrum to official website is the way to avoid from hack the other thing you need to avoid are don't share the backup seed to someone or upload your wallet file publicly and don't deal with newbies if ever you ask a help related to your Electrum wallet in the future don't take newbies offer to help you about your wallet they are most likely scammer so be careful.

And always keep following https://twitter.com/ElectrumWallet to get latest updates about the Electrum wallet they always post in twitter if there is electrum wallet vulnerability issues.

RapTarX
Sr. Member
****
Offline Offline

Activity: 322
Merit: 341


Crypto Exchange - Secure & Anonymous


View Profile WWW
November 28, 2019, 07:13:06 AM
 #10

As long as hackers are there, they will find a way to hack your wallet unless you are not much aware about that. I had tried to highlights the most probable way hackers use to hack. You can follow the this as a basic for avoiding the probable hack.
Probable precaution of using Electrum- https://bitcointalk.org/index.php?topic=5183671.msg52423155#msg52423155

█▀▀▀











█▄▄▄
|
▄▄█████▄▄
▄███████████▄
▄███████████████▄
▄██▀███████████▀██▄
▄█████▀███████▀█████▄
████████▀███▀████████
██████████████████
████████▄███▄████████
▀▀▀▀██████▄██████▀▀▀▀
█████████
▀███████████████▀
▀███████████▀
▀▀█████▀▀
▄▄█████▄▄
▄███████████▄
▄███████████████▄
▄█████████████████▄
▄████████████████▀██▄
██████████████▄██████
█████████████████████
████████████▀████████
▀█████████████▄█████▀
▀█████████████████▀
▀███████████████▀
▀███████████▀
▀▀█████▀▀
.
Trusted by ✔
MONERO
& DASH
|◆  OVER 115 COINS
◆  FIXED RATE
◆  NO REGISTRATION
▀▀▀█











▄▄▄█
█████
██
██
██
██
██
██
██
██
██
██
██
█████
█████
██
██
██
██
██
██
██
██
██
██
██
█████
rdluffy
Full Member
***
Offline Offline

Activity: 630
Merit: 122



View Profile
December 06, 2019, 01:17:35 AM
 #11

Be careful because from time to time some people have their BTC stolen using Electrum, because you have to understand some things

I'm not saying Electrum is not safe, but you have to take some precautions to be safe, I suggest you to start using Electrum with a small amount of BTC to understand about, after some time you can use with more BTC

It's basic stuff, like never download from another site, verify the signature, never upgrade with pop-ups windows, always check the adress when you use CTRL C + CTRL V etc

Pmalek
Legendary
*
Offline Offline

Activity: 1148
Merit: 1185



View Profile
December 06, 2019, 09:24:41 AM
 #12

Electrum is perfectly safe as long as it has ONLY been downloaded from the official website, the user has verified the signature and has a clean, malware/virus free machine. It is even better in connection with a hardware wallet since no private keys are revealed that way. The user only has to focus on checking that the receiving/sending address in the software is the same as the one being displayed on the screen of the hardware wallet. 

████████████████████████████
████████▀▀ █▀ █▀ ▀██████████
█████████▄ ▄▄▄▄▄▄███████████
██████████▀     ▀  ▀████████
███████▀ ▀  ▄█▀▀▀█▀▀████████
██████▄      █▄  ▀▀  ▀██████
██████         ▄▄█▄ ▄ ▀█████
█████ ▄         ▀▀ ▄ ▀ █████
██████▌          █▀█▀ ▐█████
███████  ▄▌         ▄ ██████
████████▄█         ▄████████
█████████▀     ▄▄ ▄█████████
████████████████████████████
.JACKMATE'S...........
.
MAJESTIC..
████████████████████████
███████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
████████████████████████
.
..WIN 1 BITCOIN ON EVERY PREMIER LEAGUE MATCHDAY..
████████████████████████████████
████████████▀█▀ ▀█▀█▀███████████
███████████▄ ▄▄▄▄▄▄▄████████████
███████████▀▀▄▄▄▄▄▄▄▄███████████
█████████▀▄ ██▀▄▄▄ ▀ ▄▀█████████
███████▀ ▀█████▄▄▄█▄▄▄██████████
███████▀▄████████▀  ▀█ █▐███████
███████ ▀█████████▄█▀▀██ ███████
████████ ███▀██████ ▄ ██ ███████
████████▌▐▀▄ ██████████ ▄███████
█████████▄██▌▐█████▀██ █████████
████████████▄▀▀▀▀▀▄ ▀▄██████████
████████████████████████████████
.
.JOIN US - IT'S FREE! .
bob123
Legendary
*
Offline Offline

Activity: 1106
Merit: 1580



View Profile WWW
December 07, 2019, 01:50:13 PM
 #13

Be careful because from time to time some people have their BTC stolen using Electrum

This doesn't just apply to electrum, but to every software wallet as lont as it is not completely offline - cold storage.

There are quite a few wallets which have some security vulnerabilities and therefore are less secure than electrum.
The 'problem' with electrum is, that it is one of the most used wallet and therefore is an attractive goal for phishing campaigns.

If you keep your software and OS up-to-date and use your brain properly, the chance of losing money is extremely low.

rdluffy
Full Member
***
Offline Offline

Activity: 630
Merit: 122



View Profile
December 07, 2019, 06:13:50 PM
 #14

Be careful because from time to time some people have their BTC stolen using Electrum

This doesn't just apply to electrum, but to every software wallet as lont as it is not completely offline - cold storage.

There are quite a few wallets which have some security vulnerabilities and therefore are less secure than electrum.
The 'problem' with electrum is, that it is one of the most used wallet and therefore is an attractive goal for phishing campaigns.

If you keep your software and OS up-to-date and use your brain properly, the chance of losing money is extremely low.

I said this because we are on a thread talking about Electrum...
I agree with you, the same problems occurs to every wallet, nothing in world is 100% safe, even hardware wallets or offline wallets, there always some risks that we want to minimize

use your brain properly - this is the best tip

naska21
Hero Member
*****
Offline Offline

Activity: 1246
Merit: 553


CryptoTalk.Org - Get Paid for every Post!


View Profile
Today at 08:17:30 AM
 #15

Hi! I'm new and i would like to install Electrum. But when i was reading Electrum threads i found out that Electrum had a very clever hack. How to avoid that? I'm noob at this, i don't have any computer skills. Just some basic knowledge. Am i safe just to download the newest version of Electrum? Is the hack only found on the older versions?

First and foremost,  before installing Electrum make sure you have downloaded the official distributive by checking its PGP signature as well as the  fingerprint of the relevant PGP key. 

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
Pages: [1]
  Print  
 
Jump to:  

Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!