Author

Topic: Electrum Hacked? (Read 246 times)

legendary
Activity: 3710
Merit: 1586
August 05, 2019, 08:06:27 AM
#12
Have been getting a new attack myself today. 
Some kind of coinminer that came from electrum-server.ninja (145.239.44.204, 5002)
traffic description TCP, Port 50002
I have version 3.3.8 and Norton so I can ignore it.
Just wanted you guys to know it was out there.


That's a false positive
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
August 05, 2019, 07:43:27 AM
#11
I see OP is edited, and some information other user post are removed. The main question is what link OP visit from that pop-up window, and by his statement that he use now 3.3.6, and bitmover is posting about 4.0.0 he is for sure download fake version. Now is late for any fixing, and only thing which make sense in this situation is hard disk formatting to exclude any possibility of additional infection.

For a better understanding of this problem and how it can be avoided take a few minutes of your time and watch these two videos.

Hardware Wallet vs Malware. Demo of Electrum Phishing & Clipboard Malware
Keep you Bitcoin Safe from Phishing and Scams. Verifying Electrum Download Signatures via GPG4Win

newbie
Activity: 3
Merit: 0
August 05, 2019, 07:12:17 AM
#10
Have been getting a new attack myself today. 
Some kind of coinminer that came from electrum-server.ninja (145.239.44.204, 5002)
traffic description TCP, Port 50002
I have version 3.3.8 and Norton so I can ignore it.
Just wanted you guys to know it was out there.
legendary
Activity: 1624
Merit: 2481
August 05, 2019, 06:20:18 AM
#9
Then your computer is infected with malware.

Did you verify the transaction after pasting the address ?

Clipping malware is quite common. They check your clipping board for BTC addresses and replace them with the attackers one.
Try copying the following address and paste it somewhere (e.g. notepad):
Code:
136jLgnKfTsp94XdPdZqeHzspAqdPc5pLW

If the pasted address is not the same you have copied, you are a victim of such clipping malware.

If the pasted address is the same as the one you have copied, your machine is infected with a different kind of malware.
In this case, check your electrum version. Are you using the installed or standalone version ? Verify the signature (e.g. standalone executable or installer).
newbie
Activity: 4
Merit: 0
August 05, 2019, 06:15:45 AM
#8
It did leave my wallet. But never showed up to my (exodus)adress Transaction was done but to an different adress!
How can that be? i did fill in with the correct adress
legendary
Activity: 1624
Merit: 2481
August 05, 2019, 06:01:27 AM
#7
Did you follow the security guidelines to only download electrum from https://electrum.org and to verify its signature as stated on the website ?
Verifying the signature is the only way to be sure you have the original (non-malicious) version of electrum. This is a mandatory step.

You say your BTC's haven't been delivered. Did they 'leave' your wallet ?
If you look at the history-tab, what do you see ? Do you see an outgoing transaction ? If so, does it have the correct details (e.g. output address) ?

If the transaction details are correct, head over to a block explorer (e.g. https://live.blockcypher.com) and enter the transaction ID, then check whether it is confirmed.
If the TX details are not correct (i.e. not what you have entered), your computer is somehow infected with malware (either malicious electrum or some other kind of malware).
legendary
Activity: 1876
Merit: 3139
August 05, 2019, 06:01:25 AM
#6
i use now 3.3.6   i did use an older one.

That's weird because the latest version is 3.3.8. I would suggest you uninstalling this version and downloading the latest one from the official website just to be sure.

And when i send the bitcoins to an adress i noticed that everything was filled in correctly.

Does your outgoing transaction appear as unconfirmed in the History tab? Can you check if the destination address is the same as it should be?
newbie
Activity: 4
Merit: 0
August 05, 2019, 05:54:46 AM
#5
i use now 3.3.6   i did use an older one. I opened the programma as usual. I did something in the preferences and suddenly an pop-up appeared which saying that there is an never version of Electrum. I clicked the link showed within the pop-up. It looks as if it was an pop-up from elctrum itself.
I did update it. The only thing i noticed that the icon of the programme istself was a little bit different... i thought that it was because a new icon of a new updated programme....Everything else was exactly the same interface as the one i used to know, so no alarm bells for me. And when i send the bitcoins to an adress i noticed that everything was filled in correctly.
legendary
Activity: 2520
Merit: 1496
August 05, 2019, 05:51:28 AM
#4
Take a look on the topic ⚠⚠️⚠~Beware on active phishing Electrum websites~⚠⚠️⚠ (Collection list updated).

Hope you didnt download your wallet from the sites in the list from that topic. You could have done it, but the hackers attacked you only now (waited till you have something on the balance).
legendary
Activity: 2352
Merit: 6089
bitcoindata.science
August 05, 2019, 05:45:51 AM
#3
Electrum version 4.0 doesn't exist.
Did you download from Electrum.org?
legendary
Activity: 1876
Merit: 3139
August 05, 2019, 05:35:11 AM
#2
I have updated elctrum (was a pop up within electrum its elf, to upgrade...i did that...and then i transfer money, for bitcoins, from my bank to the Electrum wallet.
I recieved the bitcoins...then i want to send my bitcoins to Exodus...I did fill in the recieve adres   but the bitcoins are not delevired!  am i being hacked?

What version of Electrum do you have right now? Old versions did not notify users of available updates. They are also vulnerable to a phising attack which tricks user to download a fake version of Electrum. Are there any entries in the History tab? Was the transaction to Exodus sent without any errors?
newbie
Activity: 4
Merit: 0
August 05, 2019, 05:32:14 AM
#1
I have updated elctrum (was a pop up within electrum its elf, to upgrade...i did that...and then i transfer money, for bitcoins, from my bank to the Electrum wallet.
I recieved the bitcoins...then i want to send my bitcoins to Exodus...I did fill in the recieve adres   but the bitcoins are not delevired!  am i being hacked?


Cube
Jump to: