Author

Topic: Electrum Phishing Update (Read 242 times)

legendary
Activity: 2870
Merit: 7490
Crypto Swap Exchange
December 29, 2018, 03:22:29 PM
#8
so as of now, if i open electrum as is and dont send btc, i will not see any message correct?

Yes

should i update to the new electrum on the website right now?

Yes, especially because older version have serious bug. Make sure you download from official website at http://electrum.org/

should i bother trying to send the small amount of btc i have now in my electrum wallet so i dont keep anything there?

No, it's not necessary

the thing is if i do try to send btc from electrum right now, will i get that message that others got or not?  If i do, can i x it out and ignore it?  im hesitant to even open electrum b/c of this now.

Only if you connected to the malicious server, but you can close/ignore the malicious message without any risks.

Im also confused here.  So when the ppl downloaded that software, i read they gave you a link to download it and you had to copy and paste it right?  However, was that directly from electrums website or a fake website?  So if you downloaded electrum from the legit site when this occurred, there would been no issue?

The link leads to fake Electrum repository (place where developer share their source code). There won't be any issue if you download Electrum from legit website.

So those that downloaded it, did they had to put their seed into it as copy and paste it?  If not, how did that occur then?

No, AFAIK it occurs when user enter password of their Electrum wallet (which is necessary to decrypt wallet and obtain seed/private key)

Also someone mentioned a while back that you could use the nano ledger s with electrum.  I never done this.  But if you do it this way, i heard electrum acts as a watching only wallet.  But if you had download this, it would not affect it since you are still using the nano ledger?

To be accurate, Electrum also generate unsigned transaction and broadcast signed transaction.

Malicious wallet can't steal your Bitcoin on Ledger Nano S, but i don't remember if they would broadcast transaction.
full member
Activity: 1750
Merit: 186
December 29, 2018, 02:29:58 PM
#7
Also someone mentioned a while back that you could use the nano ledger s with electrum.  I never done this.  But if you do it this way, i heard electrum acts as a watching only wallet.  But if you had download this, it would not affect it since you are still using the nano ledger?
full member
Activity: 1750
Merit: 186
December 29, 2018, 02:28:19 PM
#6
Im also confused here.  So when the ppl downloaded that software, i read they gave you a link to download it and you had to copy and paste it right?  However, was that directly from electrums website or a fake website?  So if you downloaded electrum from the legit site when this occurred, there would been no issue?


So those that downloaded it, did they had to put their seed into it as copy and paste it?  If not, how did that occur then?
full member
Activity: 1750
Merit: 186
December 29, 2018, 02:21:20 PM
#5
so as of now, if i open electrum as is and dont send btc, i will not see any message correct?

should i update to the new electrum on the website right now?

should i bother trying to send the small amount of btc i have now in my electrum wallet so i dont keep anything there?  the thing is if i do try to send btc from electrum right now, will i get that message that others got or not?  If i do, can i x it out and ignore it?  im hesitant to even open electrum b/c of this now.
legendary
Activity: 1946
Merit: 1427
December 29, 2018, 10:22:53 AM
#4
So in resume as long the user dont download the software in the notification the transactions can be done safely?

I believe so yes. If you get a pop-up, i think the best thing you can do is force-close electrum, and connect to another server.


The only way to lose your funds AFAIK, is to download the fake electrum, and then run it.

It might be possible that it can only steal your credentials (seed, private key) after you entered them in the "Fake" Electrum wallet, but i wouldn't be so sure of that, especially if your original electrum wallet file wasn't encrypted.
newbie
Activity: 11
Merit: 0
December 29, 2018, 10:15:17 AM
#3
So in resume as long the user dont download the software in the notification the transactions can be done safely?
legendary
Activity: 3682
Merit: 1580
December 29, 2018, 02:04:23 AM
#2
Download 3.3.2 from electrum.org and install that if you like. Don't respond to any in app update notifications because there are no such legit notifications. The only notification you get is because of a bug that a scammer is exploiting. All he can do is show you a notification. Just x out of it. There are no auto updates.

The fake notification looks like this: https://github.com/spesmilo/electrum/issues/4968#issue-394260722

full member
Activity: 1750
Merit: 186
December 29, 2018, 12:47:11 AM
#1
I notice several threads of this where people mentioned they tried to send btc and it got a message and it ask to update electrum.


I use electrum very rarely now but still have some btc there.  Does that mean if i try to send btc with electrum, i will get this message?  If so, how does it look and does it update it for you if you click yes or something like that?  Or you have to visit the website to download it? 


I opened electrum few times from my laptop recently and had no issue but i have not sent any btc from it recently.  From what i read, ppl who are trying to send btc get this message.  So did this affect all electrum users?  Someone mentioned i believe its only if you didn't put a password on electrum?  Or its only electrum users from a current version?  I'm using 3.0.5 if that matters?  I don't want to open electrum and then try to send btc and then get an update message and have no clue what to click.  Like does it ask you yes or no?  Or its just a message and you have to X it out?  And where do you do the update?
Jump to: