This thread presents basic steps to do verifications. For more details, please read more sources.
There are so many bad guys around, and there are so many phishing sites on which you can see and download dangerous faked cryptocurrency wallets. If you get trapped by faked wallets, I am sure that your funds will be stolen. It's just a matter of time that how long bad guys will steal your fund after you installing and storing your fund in faked wallets.
Days ago, the news about
the compromise on Monero site gives me a reminder to make the thread for newbies. Honestly, it is a very good opportunity for me to learn more about verification. Previously, I only knew and did verification for Electrum wallet. Now, when I made this thread, I have read more sources, from Bitcoin Core to Dash, and Monero; and I definitely and fortunately learned more valuable things.
This is another lesson for newbies: Learn first to improve; then help others. From progress to learn and help, you will become more knowledgeable; then you will be more safely in crypto.
Why do you have to verify wallets before using them as storage of your fund?
"Prevention is better than cure".
Basic steps:You should verify three steps. More things to do if you want (if yes, read more in mentioned sources).
- Hash values
- Developers' public keys
- Verify the installer signature.
- All things you use to verify, get them by yourself. Don't trust what I quoted below
Download
gpg4win software at
https://www.gpg4win.org/After downloading, checking integrity (verify) the downloaded file first.
Yes, you must verify first, don't trust even you download GPG4win from its official website. It is very terrible for you to download a phishing gpg4win software to verify any cryptocurrency wallets.
You can see how to install gpg4win software
Verify binaries on Windows (beginner), hereThe full guide is here:
https://www.gpg4win.org/package-integrity.htmlThere are 5 methods to do that. I would like to recommend you to read the section: Download and Install Gpg4win:
Get it SHA1 hash value here:
https://www.gpg4win.org/package-integrity.htmlCopy and paste the hash value you get from the Command prompt to using Find on that page to compare your hash value with the one provides on official site of gpg42win.
They are matched so I download a legit GPG4win software.
In addition, you can use the Windows PowerShell (Admin) - for Windows 10 - instead of the Command prompt.
ElectrumDownload it at:
https://electrum.org/#downloadSignature: get it here
https://download.electrum.org/3.3.8/electrum-3.3.8-setup.exe.ascThere you go: GPG verification results I get by clicking on dashcore-0.14.0.3-osx.dmg.asc (assuming you have GPG Tools installed and codablock's key imported into it already) on top of Downloads with the binary itself and this signature file on top of Github releases page with both these files lilsted
Dash Github's TagsCredits to qwizzie and UdjinM6: You can read more details of unofficial guides from two users
here
MoneroFollow the guide below to verify both hash file and binary file.
Sources:https://bitzuma.com/posts/how-to-verify-an-electrum-download-on-windows/https://bitzuma.com/posts/how-to-verify-an-electrum-download-on-mac/http://www.differencebetween.net/technology/software-technology/difference-between-pgp-and-gpg/Verifying Bitcoin Core (theymos). I don't use Bitcoin Core but if you use it, you know what to do: Verify first, don't trust.