Author

Topic: PSA: New electrum.org phishing attempt (Read 254 times)

legendary
Activity: 2170
Merit: 1789
July 29, 2019, 10:11:28 PM
#8
There is another possible attack vector by malware messing your dns or hosts file, so it might resolve electrum.org to a rogue phishing site. So no, not even that is safe enough (and actually searching it might give you the real IP address instead).

Another way to solve this is to use a live OS to access the website, download the files and verify it.

Installing anti-phishing malware might also help to prevent you accidentally access a punycode website, but of course, that won't work if your DNS was hijacked.
legendary
Activity: 2030
Merit: 1569
CLEAN non GPL infringing code made in Rust lang
July 29, 2019, 09:46:57 PM
#7
How did you find that electrum site?  Was it through google or electrum?  Because if you type in manually yourself

www.electrum.org

You should be fine right?

This is fine but its not the end of the story. There is another possible attack vector by malware messing your dns or hosts file, so it might resolve electrum.org to a rogue phishing site. So no, not even that is safe enough (and actually searching it might give you the real IP address instead).

I think the only way to be sure is doing the gpg signature check:

legendary
Activity: 2534
Merit: 6080
Self-proclaimed Genius
July 10, 2019, 10:27:52 PM
#6
How did you find that electrum site?  Was it through google or electrum?  Because if you type in manually yourself
www.electrum.org
You should be fine right?
Yes.

FYI, the "eļectrum.org" is the ASCII version of punycode: "xn--eectrum-9hb.org" <--- Warning: phishing site.
It will be displayed as the latter if you're using Firefox with show_punycode enabled.

Try to type the original url on the right box here: https://www.punycoder.com/ then press "<" and it will be displayed as eļectrum.org.
full member
Activity: 1750
Merit: 186
July 10, 2019, 07:38:25 PM
#5
How did you find that electrum site?  Was it through google or electrum?  Because if you type in manually yourself


www.electrum.org


You should be fine right?
hero member
Activity: 3150
Merit: 636
DGbet.fun - Crypto Sportsbook
June 29, 2019, 05:02:11 PM
#4
I remember that there's also same character of that letter 'L' that has been used as Binance phishing site before. Thanks for the warning.

I see that there's also a post like this on Beginners and Help.

Warning: Another Electrum phishing site
legendary
Activity: 3024
Merit: 2148
June 29, 2019, 06:00:17 AM
#3
Nice catch, and nice tip about Firefox!

Also, people really shouldn't be googling or clicking on some links to websites after their first visit - important sites should always be bookmarked and accessed with bookmark. Same goes for typing - autocomplete can lead to a fake site, or you can make a typo and get to hacker's site. And before visiting the site for the first time, always google search what the official site is, and check people's discussions first - never simply click on one of the results.
jr. member
Activity: 37
Merit: 4
June 29, 2019, 04:01:38 AM
#2
Thanks for the heads up.
legendary
Activity: 2898
Merit: 1823
June 29, 2019, 02:55:23 AM
#1
Be careful electrum users/newbies. Scammers, hackers, and thieves are becoming more active because of the new Bitcoin rally.

You are all targets, especially newbies.

https://twitter.com/electrumwallet/status/1144678604523147265?s=21

Quote

Do you see that little fleck of dust under the domain name in the left screenshot? Actually not dust. Enable show_punycode in Firefox in order to avoid phishing URLs.


Jump to: