Bitcoin Forum
August 14, 2026, 01:32:22 AM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Electrum 4.8.0 - 4.8.x family releases.  (Read 161 times)
satscraper (OP)
Legendary
*
Offline

Activity: 1554
Merit: 2885



View Profile
July 13, 2026, 01:49:54 PM
Last edit: July 13, 2026, 05:50:30 PM by satscraper
Merited by NeuroticFish (1)
 #1

Electrum was elevated to v.4.8.0

 Main changes: BIP-70 payment identifiers removed, LNURL LUD-17 support added, wallet renaming on Android, and Android's minimum OS bumped to 8.0, Trezor Safe 7 pairing added. Lightning gets several trampoline/routing improvements plus early groundwork for BOLT12. Plus  one low-severity security fix (SPV verification, CVE-2012-2459). All changes are described here.


▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Karl_3000
Full Member
***
Offline

Activity: 378
Merit: 196


Bitcoin a wealth preserver


View Profile WWW
July 15, 2026, 01:56:36 AM
 #2

I noticed that there are some changes on the user interface of the Android Electrum, it may not first be noticable, but if you use it to send coins or you use it to access the preferences, you will notice this.

But I still need two things that should be done on Android Electrum to make it very complete which are sending to many addresses and also able to select the coins that can be sent in a transaction.

nc50lc
Legendary
*
Offline

Activity: 3234
Merit: 8977


Self-proclaimed Genius


View Profile
July 15, 2026, 05:02:42 AM
 #3

But I still need two things that should be done on Android Electrum to make it very complete which are sending to many addresses and also able to select the coins that can be sent in a transaction.
For some reason, those features aren't popular in the repo's issues tab.
That Android version feature: coin-control has two but it's not being pushed by the authors, try to bump them if you like:

There's a workaround though, read the comment in #7790, that's for the old Kivy GUI.
The option is quite hidden in QML since it'll only show if you hodl the listed UTXO in "WalletName->Addresses/Coins->Show:Coins".

For the "pay-to-many" option in Android, I can't see any "Feature Request" issue posted for it.

Karl_3000
Full Member
***
Offline

Activity: 378
Merit: 196


Bitcoin a wealth preserver


View Profile WWW
July 16, 2026, 01:44:13 PM
 #4

There's a workaround though, read the comment in #7790, that's for the old Kivy GUI.
The option is quite hidden in QML since it'll only show if you hodl the listed UTXO in "WalletName->Addresses/Coins->Show:Coins".
You mean to hold the coins or addresses which will let the coin or addresses to freeze in a way no coin that is freezed will be spent? That it is true I have used the feature before, but coin control in a way I can be able to select the coins to spend directly will be better and easy. There are some dust coins that I just freeze on the wallet.

nc50lc
Legendary
*
Offline

Activity: 3234
Merit: 8977


Self-proclaimed Genius


View Profile
July 17, 2026, 03:23:33 AM
 #5

There's a workaround though, read the comment in #7790, that's for the old Kivy GUI.
The option is quite hidden in QML since it'll only show if you hodl the listed UTXO in "WalletName->Addresses/Coins->Show:Coins".
You mean to hold the coins or addresses which will let the coin or addresses to freeze in a way no coin that is freezed will be spent? That it is true I have used the feature before, but coin control in a way I can be able to select the coins to spend directly will be better and easy.
Yeah, and that's why I labeled it as a "workaround" rather than a solution.

Unfortunately, it seems like it's not in their priority list.
I'll bump the remaining open feature request, maybe the main developer for QML GUI will notice the issue once it's on top of the list.

satscraper (OP)
Legendary
*
Offline

Activity: 1554
Merit: 2885



View Profile
August 12, 2026, 01:38:52 PM
 #6

Today Electrum was elevated to 4.8.1

This  is mostly bugfix release, i.e. Lightning routing which had the fee budget bug that let it skip enforcing fee limits is now fixed, along with several liquidity-hint and channel-collision fixes. Also several JSON wallet database corruption/crash bugs were patched, and hardware wallet screenshot protection for WIF keys was improved. Better to learn about all fixes by  yourself here.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Pmalek
Legendary
*
Offline

Activity: 3584
Merit: 9455



View Profile
August 12, 2026, 05:44:52 PM
 #7

Today Electrum was elevated to 4.8.1
...
There is one interesting line in Electrum's release notes for the 4.8.1 release:
Quote
* Security fixes and disclosures:
   - This release contains important security fixes. Details will be disclosed later.

Something that impacts the security of the software has been identified and fixed but the developers haven't released what exactly it is. I doubt it's something critical that has caused loss of funds because we would have heard about it already. Perhaps the devs took a closer look at their codebase considering what happened to Coldcard, BTCPay Server and several other services recently and found things that needed fixing and aren't yet ready to discuss it publicly.

▄▄███████████████████▄▄
▄███████████████████████▄
████████████████████████
█████████████████████████
████████████████████████
████████████▀██████▀████
████████████████████████
█████████▄▄▄▄███████████
██████████▄▄▄████████████
████████████████████████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
| 🏀
 
🏈 🏓
 
🎯 🥊
 
 🎾
 
 🏐
 
🏏 🏎️
|


███████▄▄███████████
████▄██████████████████
██▀▀███████████████▀▀███
▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌██▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
▀█████████████████████▀██
██▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████

....HIGHEST....
VIP REWARDS

  G U A R A N T E E D   
| 
 🜲 
KING OF
THE CASTLE

$200K in prizes
| 
..PLAY NOW..
Cricktor
Legendary
*
Offline

Activity: 1582
Merit: 4247



View Profile
August 12, 2026, 07:35:43 PM
 #8

There is one interesting line in Electrum's release notes for the 4.8.1 release:
Quote
* Security fixes and disclosures:
   - This release contains important security fixes. Details will be disclosed later.
That's a bit odd and I don't like it. So some security fixes are important, but likely not urgent, as if urgent I'd expect a more stricter warning to update as soon as possible. And devs don't want to disclose it yet, which is understandable when disclosure brings more harm than rescue. Still odd to me...

I tend to delay x.y.0 versions of Electrum longer than other, depending on what is new and if I want those new features. Sometimes I skip the x.y.0 version entirely and update only to the first maintenance release x.y.1+

Curious to find out what it is that they don't want to disclose yet.

NotATether
Legendary
*
Offline

Activity: 2422
Merit: 10119


┻┻ ︵㇏(°□°㇏)


View Profile WWW
August 13, 2026, 03:14:58 AM
 #9

That's a bit odd and I don't like it. So some security fixes are important, but likely not urgent, as if urgent I'd expect a more stricter warning to update as soon as possible. And devs don't want to disclose it yet, which is understandable when disclosure brings more harm than rescue. Still odd to me...

This is why the code is open source, so we don't have to trust the maintainers.

This is a release related to fixing security vulnerabilities in Lightning. If you use Lightning, you should definitely update, otherwise it's not necessary but still recommended.

This commit (https://github.com/spesmilo/electrum/commit/ad208f93f85b68688ac440241c90dd59f9386976) it lowers the maximum allowed cltv expiry threshold used in submarine swaps to around 435 blocks (around 3 days). And the MINIMUM cltv expiry threshold is still 432 blocks. So essentially now it's 3 blocks difference.

The previous maximum allowed value was 4032 blocks, or 28 days (4 weeks).
The reason for this commit is to prevent malicious peers issuing BOLT11 invoices with very long swap expiry times in order to lock funds.

41daa2a additionally warns whether expiremental Lightning routing is enabled on mainnet.

There are others, I will just copy the output ChatGPT gave me before I post a detailed write-up on X

Quote
Submarine swap mining-fee prepayment sanity check — cbdaa03. This is probably the biggest one besides CLTV. The commit explicitly says a malicious provider could specify a negative percentage fee plus a huge mining fee, causing Electrum to send a huge trusted prepayment. The new check caps/sanity-checks that amount. This is directly a malicious swap-provider → loss-of-funds scenario.
Forward-swap refund reorg safety — 908f1ed. Previously Electrum failed the incoming HTLCs after only 1 confirmation of its refund transaction. If that refund got reorged out, the counterparty could notice and potentially claim the on-chain swap after Electrum had already failed the Lightning HTLCs. 4.8.1 waits for 6 confirmations before failing them.
Don't fund a swap when the expected HTLCs never arrived — d91d615. The old flow could time out because the HTLCs were absent, but if the user didn't manually cancel, Electrum could later broadcast the funding transaction despite never having received the corresponding HTLCs. The new code fails the swap when the invoice expires.
Cancel-vs-broadcast race — 87f04e6. There was a race where one thread could cancel/delete a swap while another simultaneously broadcasts its funding transaction. The commit describes the bad outcome explicitly: Electrum could fund the swap, delete its local swap state, and become unable to refund itself.
Forward-swap locktime lower-bound validation — b6241d5. Adds validation against an unreasonably low client forward-swap locktime.
Forward-swap on-chain amount lower-bound check — 7b96366. More validation of values supplied/negotiated during swap setup.
Reverse-swap CLTV limit — 2908d33 / merge ad208f9, the one we were discussing: swap invoices go from the generic 4032-block maximum down to 435 blocks.
Electrum-server resource-exhaustion hardening — PR #10821. The release notes explicitly describe this as “interface: hardening against resource exhaustion.” That is security/DoS hardening against a hostile Electrum server.
TrustedCoin malicious-server CPU DoS — #10822. This one's release-note description is unusually explicit: “billing_index: mitigate against CPU DOS from malicious server.” So a malicious TrustedCoin backend response could make the client consume excessive CPU.
Nostr swap transport duplicate-reply crash — 1cf7dae / #10833. A server sending duplicate replies could cause Future.set_result() on an already-completed future and crash the transport. That's remotely triggerable DoS in the swap communication path.
Lightning channel-ID collision check — #10819. If Electrum is configured to accept incoming channels, it now explicitly checks for channel-ID collisions.
Lightning HTLC dust off-by-one — 3bcb39e / #10820. HTLCs exactly equal to the dust threshold were incorrectly trimmed. That's consensus/commitment-transaction correctness territory, so although the release notes call it a normal bugfix, it is certainly safety-relevant.
Android private-key screenshot protection — #10799. WIF/private keys are now protected from screenshots in additional UI locations. That's straightforward secret-leakage hardening.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!