Pages:
Author

Topic: Electrum BUG - all Bitcoins stolen (Read 588 times)

legendary
Activity: 3472
Merit: 10611
May 08, 2018, 10:17:01 PM
#27
Why is it that people come here, saying "Electrum is scam, bitcoins stolen" and yet they never give the full story.

It would really help if they posted where they downloaded it, the hash of the executable file, if they kept it on an online PC or offline.

We would investigate and help them out. But they usually never come back to comment.

those who don't come back usually have made a silly mistake. for example many don't let their wallet sync so they don't see their funds, then they think they have been robbed. when it is fixed they forget about everything and go away.
but it is also possible that they got if fixed elsewhere. there are other forums like reddit[1], there is Github[2], there is also an IRC channel[3] for Electrum. and when you fix it somewhere else you don't just go back to a random forum you visited once (bitcointalk) and update a topic you made with a throwaway account!
of course there is always an occasional troll too!

[1] https://www.reddit.com/r/Electrum/
[2] https://github.com/spesmilo/electrum/issues
[3] irc://irc.freenode.net/electrum
HCP
legendary
Activity: 2086
Merit: 4361
May 08, 2018, 09:48:13 PM
#26
Why is it that people come here, saying "Electrum is scam, bitcoins stolen" and yet they never give the full story.
It would really help if they posted where they downloaded it, the hash of the executable file, if they kept it on an online PC or offline.
We would investigate and help them out. But they usually never come back to comment.
Generally... if they're smart enough to be able to work out what the hash of the executable file is... or even know what a "hash" is, they'll be smart enough to know how to find the official Electrum website and not be fooled by the scam sites in the first place.

Also, the people who generally fall for the scam versions of Electrum etc, don't really know that this information is helpful for people trying to help them out... they only know they've lost their coins and are obviously angry and upset and just want to vent.

I would not be surprised if the general sequence of events is:

1. "Newbie" user claims Electrum is a scam and stole their BTC
2. Helpful users here ask the usual "where did you download it from? what version was it? did you run malware/virus scans?" questions
3. Victim goes off to find the information requested and discovers they've downloaded a scam version from a scam site
4. Victim is too embarrassed to come back and admit what has happened and disappears into the Ether
legendary
Activity: 3808
Merit: 1723
May 08, 2018, 02:47:19 PM
#25
Why is it that people come here, saying "Electrum is scam, bitcoins stolen" and yet they never give the full story.

It would really help if they posted where they downloaded it, the hash of the executable file, if they kept it on an online PC or offline.

We would investigate and help them out. But they usually never come back to comment.
member
Activity: 162
Merit: 10
May 07, 2018, 02:32:04 PM
#24
i feel sorry for people who think antivirus keeps people safe, antivirus in many cases is a virus
legendary
Activity: 3472
Merit: 10611
May 01, 2018, 11:03:45 PM
#23
Could it be that the electrum site was hacked
the possibility of this is extremely small because if electrum.org was actually hacked then we would have heard about it already!

Quote
It's time to make it easy to secure cryptocurrencies such as wallets or settings in the blockchain that require multisignatories on certain amounts in total per transaction and in a monthly period.  Even e-mail confirmation from one or two signatories would increase security and prevent these kinds of thefts.
i disagree. we do not need either of these. we need people to learn more before they jump on board. and the basics are simple. and by the way in case you download a wrong wallet from a malicious website multisignature is still not going to save you because the wallet is still using the attacker's seed and he still is going to have access to your funds.
and restricting the amounts per transaction and things like that is simply not possible because bitcoin needs to stay permission-less.
newbie
Activity: 35
Merit: 0
May 01, 2018, 03:50:46 PM
#22
It's really hard to say what happened but very sorry to the OP that it did.  Could it be that the electrum site was hacked or the more likely possibility others mentioned that the poor OP visited a very good looking scam site?
It's time to make it easy to secure cryptocurrencies such as wallets or settings in the blockchain that require multisignatories on certain amounts in total per transaction and in a monthly period.  Even e-mail confirmation from one or two signatories would increase security and prevent these kinds of thefts.
legendary
Activity: 1624
Merit: 2481
May 01, 2018, 03:32:51 PM
#21
i have this problem too.
i have install electrum 3.0.3 at 26.01.2018
after 2 days i have see a output transaction and all my bitcoin lost.
don't use electrum! shit!
From where you downloaded? Did you checked the PGP signature?

from official site and not 3.0.3 version but 3.0.5

Version 3.0.5 didn't contain any vulnerability.
The most probable scenario is that your pc got infected by malware which led to a theft of your coins.
Did you check the signature? Or at least comparing the hashes? This could exclude a malicious version of electrum.
Was your wallet password protected?

You should definetely run some anti virus checks.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
April 28, 2018, 04:12:40 AM
#20
i have this problem too.
i have install electrum 3.0.3 at 26.01.2018
after 2 days i have see a output transaction and all my bitcoin lost.
don't use electrum! shit!

There are several ways you have lost your BTC,and the one that is most likely is that you download Electrum from fake site.At that time there is many fake Electrum sites shown at the top of search results and if you not careful and check site you got fake Electrum.The only legitimate site for download Electrum BTC is https://electrum.org/#home

Other way is that you have some RAT(remove access trojan) on your device,so hacker is get your private keys/seed.Electrum is completely safe if it is download from official site and if user device is clean from virus/malware.
full member
Activity: 148
Merit: 100
April 28, 2018, 01:55:55 AM
#19
i have this problem too.
i have install electrum 3.0.3 at 26.01.2018
after 2 days i have see a output transaction and all my bitcoin lost.
don't use electrum! shit!
From where you downloaded? Did you checked the PGP signature?

from official site and not 3.0.3 version but 3.0.5
member
Activity: 137
Merit: 10
April 27, 2018, 08:20:05 PM
#18
i have this problem too.
i have install electrum 3.0.3 at 26.01.2018
after 2 days i have see a output transaction and all my bitcoin lost.
don't use electrum! shit!
From where you downloaded? Did you checked the PGP signature?
full member
Activity: 148
Merit: 100
April 27, 2018, 03:13:15 PM
#17
i have this problem too.
i have install electrum 3.0.3 at 26.01.2018
after 2 days i have see a output transaction and all my bitcoin lost.
don't use electrum! shit!
full member
Activity: 168
Merit: 120
January 25, 2018, 09:05:28 PM
#16
You must have downloaded a fake electrum wallet because last time I checked there is no updates regarding the electrum wallet you are stating. Also, you may try cleaning up your PC and it installed by a strong anti-virus to avoid getting accessed with these kinds of malicious sites, maybe your relying on free anti-virus which is very much weak and cannot be considered as mere protection against these type of attacks.
I guess they download wrong electrum wallet, because if they download the original wallet they cannot experience problem. I also used electrum wallet and the problem I can see in this wallet is charges or payment is very high compared with the other wallet. Because when I withdraw my amount stored in this wallet almost half of my bitcoin will be used for payment.
member
Activity: 126
Merit: 14
January 19, 2018, 07:34:57 PM
#15
You must have downloaded a fake electrum wallet because last time I checked there is no updates regarding the electrum wallet you are stating. Also, you may try cleaning up your PC and it installed by a strong anti-virus to avoid getting accessed with these kinds of malicious sites, maybe your relying on free anti-virus which is very much weak and cannot be considered as mere protection against these type of attacks.
hero member
Activity: 1330
Merit: 569
January 19, 2018, 07:52:44 AM
#14
In all of this, I think the bone of contention is one should be careful of where to download the wallet as even the vulnerability scare makes amateurs hackers carry out their activities because they know everyone who has an Electrum wallet will be in a haste to upgrade and not even bother to verify the site in which the download is to be made. Some other people because of the pressure and the amount involved just typed in Google in other to upgrade ASAP only to discover that it was at the point of trying to become more secure that they become way more vulnerable. The onus is on us to exercise much more patience even in the face of unending pressure.
legendary
Activity: 2926
Merit: 1386
January 18, 2018, 01:54:29 AM
#13
I checked alle downloads with an Electrum developer, all downloads are ok.

For the record: I am the Electrum developer who answered this user's emails, and we only checked his 3.0.5 download, because he claims to have deleted 3.0.3



yes right, but I checked in the browser download history, this was the right software from the correct website, there was no other Electrum 3.0.3, I am not stupid, I have never used a wrong download before. Also I checked my PC with an windows server administrator and a java/delphi programmer now. I have a 100% clean computer. I have used 6 different desktop wallets at this time, everyone is ok. But only this problem with Electrum. coincidence? stupidity? Sorry, but I do not believe in coincidences and I did not do anything wrong, quite the opposite. I am always careful, it is still a mystery to me and my friends. Fact is, now I was robbed by whoever and I used Electrum and nobody can help me.

Let me say first that I feel for your loss, and my advice to you is to get your bitcoins off of computers and onto either hardware wallet like Trezor or paper wallets.

It may interest you, I have just now been writing a fictional scenario where an intruder activates the camera on her target's PC, and simply reads the password the target enters and then reads the numbers on the 2FA authentication device.  The intruder types the 2FA in quicker than he does, and locks him out.

Yes I made that up. It's fiction. Now I've publicly stated it, so maybe tomorrow the bad guy tries it out.

Do we know all the routes a bad guy might take? Nope, you cannot.
legendary
Activity: 3472
Merit: 10611
January 16, 2018, 12:50:46 AM
#12
~
they said =Note: Some old versions of Windows might need to install the KB2999226 Windows update.
i don't want to install something that i don't understand including this KB2999226.

what is there to understand? it is a Windows update released by Microsoft the same company that released the Windows you are already using! and you download it through Microsoft itself.
it is an update for Universal C Runtime (CRT) in Windows. if you are curious about the details read the kb article from Microsoft official website:
https://support.microsoft.com/en-us/help/2999226/update-for-universal-c-runtime-in-windows
sr. member
Activity: 404
Merit: 257
January 15, 2018, 11:36:41 AM
#11
I checked alle downloads with an Electrum developer, all downloads are ok.
I checked my PC with an Security Expert, no problems.
I have more than one wallet software and coins. Only my Bitcoin from Electrum wallet are effected.

fact:
The transfer was only visible with Electrum 3.0.5 on Monday morning (8.1.2018) - 3 days later!!!
The transfer was actually on Friday midday (5.1.2018 11:33), BUT I still see all my bitcoin in the orig. Electrum 3.0.3 on Friday evening, houres lates, all bitcoins are ok at this moment.

conclusion: you can't trust dektop wallets, you can't trust Electrum!!!

(and i'm a master in computer science since 2003 / administrator and programmer since more than 14 years - i'm not a computer dummy)

when i was trying to download new version 3.0.5 from my old electrum wallet i clicked  the help button and the link  is www.electrum.org because i though i clicked from my old electrum i don't mind although i read from theymos this is the link,electrum.org.i tried to download the 3.0.5 version for windows but  it's just not working at all.and then i download again from electrum.org still not working for my windows so my solution is using   Standalone Executable download and i can open eletrum wallet but this is not install in my computer.from there i  transfer all my fund to other exchange.lucky everything went smooth.
they said =Note: Some old versions of Windows might need to install the KB2999226 Windows update.
i don't want to install something that i don't understand including this KB2999226.lucky i do what what i think the best solution for me.
legendary
Activity: 1896
Merit: 1353
January 15, 2018, 11:05:23 AM
#10
I checked alle downloads with an Electrum developer, all downloads are ok.

For the record: I am the Electrum developer who answered this user's emails, and we only checked his 3.0.5 download, because he claims to have deleted 3.0.3

legendary
Activity: 1624
Merit: 2481
January 15, 2018, 07:42:31 AM
#9
maybe browser open, but my wallet was saved with a password!!!

Well there are two options:
1. Your password was very very weak
2. This theft is not related to the vulnerability in electrum

The exploitation of the vulnerability needs an website to actively exploit this vulnerability.
It doesn't 'just happen' when browsing youtube.

Did you verify the signature of your downloaded file?
You can find all relevant data on electrum's site (https://electrum.org/#download)


no no no, no malware, I have a clean pc, no keylogger possible, ..

How can you be that sure that its not possible for your pc to be compromised?
Just because you have an AV and windows says 'firewall' in the bottom right corner, that doesn't mean you are safe at all.
Did you check your system? What AV's did you use to check your pc ?
Did you have a digital backup of your seed?
legendary
Activity: 1896
Merit: 1353
January 15, 2018, 05:37:46 AM
#8
since your wallet was protected with a password, it is unlikely that this theft is related to the vulnerability exposed last week.

Quote
In the other Version of Electrum 3.0.3 my bitcoins are still there (Friday night, after the alleged transfer !!!), my bitcoins are ok at this moment. After I opened in Electrum 3.0.5 all is lost, 3 days later.

you should definitely explain what you mean by that.
did 3.0.3 display a history where the theft transaction is missing?

is version 3.0.3 still installed on your machine?
if yes, please check the sha256 of the file you downloaded.

also, better stop using that computer and have it investigated by a security expert.
Pages:
Jump to: