Author

Topic: [WARNING] Another Electrum fake app on AppStore!!! (Read 350 times)

legendary
Activity: 2254
Merit: 2852
#SWGT CERTIK Audited
-snip-
Besides that its always helpful to use strong passwords and activate 2FA. Hardware wallets would add another layer of security ofc.

However, if you refer to the thread's topic, Electrum mobile, which is currently only available for Android smartphones, doesn't even support hardware wallets, as far as I know.
A small note: wallets with 2FA on Electrum have a fee to use this feature. Further information can be seen here: https://api.trustedcoin.com/#/faq.

-snip-



Please be careful. Some time ago, the fake Electrum application: 'Electrum Wallet Management' was removed from the AppStore. This time, I saw another fake Electrum application in the AppStore: 'Electrum Wallet Finance'.

legendary
Activity: 1260
Merit: 1954
yesterday, the Electrum devs published a very good summary of the most common malware attacks on your wallet.
check out this github link and read it carefully. i hope that this will now reach more users who may have been more careless with the whole thing so far!

Malware (and other avenues of losing money)

It always depends on the users themselves. If you want to make sure you are using the right software, you need to verify the wallet software. There are very simple tips that you should follow:

Always download Electrum from the official website and verify the software's digital signatures. This ensures that the software is authentic and hasn't been tampered with.
Keep your Electrum wallet updated to the latest version. Developers regularly update the software to patch vulnerabilities.

Besides that its always helpful to use strong passwords and activate 2FA. Hardware wallets would add another layer of security ofc.

And ofc dont get fooled by any emails or websites that pretend to be Electrum.
legendary
Activity: 3122
Merit: 7618
Cashback 15%
yesterday, the Electrum devs published a very good summary of the most common malware attacks on your wallet.
check out this github link and read it carefully. i hope that this will now reach more users who may have been more careless with the whole thing so far!

Malware (and other avenues of losing money)
hero member
Activity: 854
Merit: 1031
Only BTC
Really sad to see this keep happening, we only can pretend to share the knowledge from so no more guys fall into this, but is really difficult.
There are so many people who use BTC, but they do not know much about what they are doing, they do not even know that Electrum doesn't have an ios version. Members' of this forum will easily know things like these, but for people who are not here, it is hard for them.

I just checked for the scam application in my ios device and i can confirm that it has been taken down. I know that nobody should ever download their wallet through Playstore or App store, but maybe Google and Apple have to do better, phishing applications are too much in Playstore and some are now finding their way into App store, just like 'Electrum wallet management' did.
sr. member
Activity: 462
Merit: 263
CONTEST ORGANIZER
Really sad to see this keep happening, we only can pretend to share the knowledge from so no more guys fall into this, but is really difficult.

I try to push for the companies like Google and Apple were more careful with this things, but they cant do so much asides of register the most important brands who make wallets like electrum fo example, and forbid others with similar names, but you can just fall in legal problems.

The main problem here is they by-pass the troyan analisys because the software in that kind of terms is good, but is more like a social enginering hacking. And the companies of the stores cant do so much about it (sadly). Another thing they can do is to erase fast this app from the store.

legendary
Activity: 1484
Merit: 1024
#SWGT CERTIK Audited
many new users don't understand if Electrum can create 1st time (new) wallet offline. If they understand it, it can avoid to recorded online.
I do not want to assume that new users who don't understand if to make new swallows can be offline a lot of them. I want before going to investment and trade, beginners are required to learn how to use a wallet and how to choose a wallet to be able to avoid things that cause losses to the mistakes made by themselves.

Don't be surprised to see users like me too busy in the wallet by asking things that are understood by other users.

Because I was here for a long time and know that the new user doesn't care about how to create a wallet offline, they just think of profit and selling their bitcoin at the right time. That in fact, the new user is going to be busy learning business (Alt), they never care how to save it offline. If they know it, whatever phishing site out there, they will carefull to do not trap it, because they already know how to secure the investment.

The new user always asking many time already questions like he was expecting something here.
hero member
Activity: 854
Merit: 1031
Only BTC
the stolen 0.89 BTC have now been sent from the 1LGou2... address to another following address: https://mempool.space/address/bc1q6xqsh33unk7e3l985awkt9jfs2trn46dkrztfs
this address contains further transactions that have taken place since november 9th and this address has received 2.7 BTC so far
The total received BTC's has gone up from that, it is now above 5 BTC, but the scammer has sent out nearly everything from that address to different addresses and in different transactions. So many people are still falling for this scam and who knows how many people would lose their BTC's, before apple takes this scam app down.
CAN I SUE APPLE FOR THIS? Even if just small claims.
I'm not sure you will achieve much if you do this all by yourself, Apple is a giant company and i am sure you will run out of funds if you enter a lawsuit with them. So many people have and are losing money from this scam app, so if they can all collectively make their case on this matter, it may be more productive.
legendary
Activity: 2828
Merit: 1213
Call your grandparents and tell them you love them
this address contains further transactions that have taken place since november 9th and this address has received 2.7 BTC so far
I took the opportunity to borrow a friend's iPad and found this scammer app on the app store on Apple still existing and there is literally no way for a normal user who has not downloaded the app to report it to the store authorities.

However the app did not come on its own when searched for "Electrum" but specifically for "Electrum management" and hence there must some method by which the scammers are SEOing the terms in order to point the users to the second one.
legendary
Activity: 3122
Merit: 7618
Cashback 15%

and it looks like this is the scammer address: https://mempool.space/address/1LGou2YkuYLoFkkixLAd3HK6bVvUqX5BLz


the stolen 0.89 BTC have now been sent from the 1LGou2... address to another following address: https://mempool.space/address/bc1q6xqsh33unk7e3l985awkt9jfs2trn46dkrztfs
this address contains further transactions that have taken place since november 9th and this address has received 2.7 BTC so far
sr. member
Activity: 322
Merit: 306
Farewell LEO o_e_l_e_o
I ask as above because up to now Electrum does not support iOS but macOS (desktop). So, when iPhone users find Elcetrum app in mobile appstore can clearly know that the app is a scam because Electrum mobile is available on Android devices.
On the contrary, beginners do not know the wallet link and may search on Google for a Bitcoin wallet or on the App Store (there are no phishing apps compared to Google Play), and then the site will appear to them as the first result with positive reviews, so some may use it.

Then, what will happen? Smiley Risk of Self -responsibility Smiley


This means that the seed phrase given when creating a new wallet is recorded with all of them (the perpetrators) so that users who cannot distinguish between genuine Electrum and fake ones will lose their stored Bitcoin assets.
many new users don't understand if Electrum can create 1st time (new) wallet offline. If they understand it, it can avoid to recorded online.

I do not want to assume that new users who don't understand if to make new swallows can be offline a lot of them. I want before going to investment and trade, beginners are required to learn how to use a wallet and how to choose a wallet to be able to avoid things that cause losses to the mistakes made by themselves.

Don't be surprised to see users like me too busy in the wallet by asking things that are understood by other users.
legendary
Activity: 1484
Merit: 1024
#SWGT CERTIK Audited
I think this could be a solution, but unfortunately, it requires an Apple ID to report. I'm not an Apple user, but I really want to contribute and report the app.
As I know, to have an Apple ID is not a must you have an Apple gadget. you can create an Apple ID on website: https://appleid.apple.com/account or when you use Windows PC, follow This link, but you must have iTunes already installed on your PC, and also have phone number to register.

This means that the seed phrase given when creating a new wallet is recorded with all of them (the perpetrators) so that users who cannot distinguish between genuine Electrum and fake ones will lose their stored Bitcoin assets.
many new users don't understand if Electrum can create 1st time (new) wallet offline. If they understand it, it can avoid to recorded online.
legendary
Activity: 3122
Merit: 7618
Cashback 15%
✂️
This was unfortunately me 🤦‍♂️

holy shit!!!
unfortunately, i can't answer whether you should take the giant Apple to court because of this. but maybe there are users here who are more familiar with this than i am

but losing over 0.7 BTC in one fell swoop really hurts and I wouldn't want to be in your shoes right now...
why didn't you go directly to downloads on the official Electrum website (even if there is no official app for ios) - what was your train of thought at that moment?
newbie
Activity: 2
Merit: 0
newbie
Activity: 2
Merit: 0
This just happened to me. I am the one who was scammed in tx 8d03c5214fc3cab5ff1c22d58a935a14f3ef7b4ab2f9eea092e6a912abd10b2f

I have the seed to the original wallet. The tx is still unconfirmed because I had a pending transaction coming in which was delayed for over 3 days going on 4 now. Went on AppStore to try and download electrum to initiate CPFP and after entering seed phrase in this app it doesn’t do anything I quickly realize what’s happened but it was too late they took that along with another amount that was already on the wallet tx 258f73f68402188ca9fcc328d1531966721b9167b345af53d5284f832f3feeb4 and right after they themselves initiated the CPFP transaction before I could do anything.

Can I make a small claims with Apple in court over this? Literally this is a problem they know about the app has reviews which are posted since Nov. 1 stating it’s fake and it’s been reported and it’s been 2 weeks with no action. On top of the fact that they have let many customers lose millions to these same known scams.

CAN I SUE APPLE FOR THIS? Even if just small claims.
legendary
Activity: 2506
Merit: 3645
Buy/Sell crypto at BestChange
I ask as above because up to now Electrum does not support iOS but macOS (desktop). So, when iPhone users find Elcetrum app in mobile appstore can clearly know that the app is a scam because Electrum mobile is available on Android devices.
On the contrary, beginners do not know the wallet link and may search on Google for a Bitcoin wallet or on the App Store (there are no phishing apps compared to Google Play), and then the site will appear to them as the first result with positive reviews, so some may use it.
legendary
Activity: 3122
Merit: 7618
Cashback 15%
legendary
Activity: 3234
Merit: 2943
Block halving is coming.
Actually, there's no Electrum installer for iPhone they only support macOS, Android, Linux, and Windows.
And it seems Electrum developers do not have a plan to develop Electrum app on IOS because even if they do release Electrum for iPhone you can't able to install the app if it came from directly on electrum.org.

There's news making the rounds that Apple has plans to enable support for 3rd party app stores (but only for users in Europe). Although I don't know how that would work, I suppose this means that something like the equivalent of F-Droid can be made by some people, and Electrum can publish their app on platform, or even provide a binary that you can download, but opens with that app store by default for the purpose of installation.
It seems that I found the news you talking about here Apple may plan to appeal against the EU App Store law it was published 3 days ago.
According to it "Apple’s engineers have already developed tools to permit third-party stores and app sideloading on its systems, at least in Europe"

That's good news for those who live in Europe but how about other countries? Actually, you can install apps from 3rd party the only problem is you will need to jailbreak the unit to be able to install apps outside the appstore but it's not permanent once you turn off and on the device, the jailbreak is gone and all 3rd party apps won't work.
And another problem is we do not know how safe is jailbreaking just like on Android phones if you root your phone you are vulnerable to any attacks online just like what happened to my old phone which has lots of malware and ads when you connect online.

I hope that Apple decides to support other countries too so that we don't need to use any tools just to jailbreak the unit.
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
Being paranoid with fake apps on Google Play?

Protect yourself from fake wallet software (guide)
The paranoid user's security guide for using Electrum safely.

People got fake apps because they don't visit an official website to get download links. They also don't verify wallet, PGP key of developers. Only download an application and use it immediately.

They will have more chance to get fake applications if they directly search in Google Play.

Some websites to check wallet applications and I mean for double checking. Verify PGP key is most important.
https://walletscrutiny.com/
https://www.cryptowisser.com/wallets/

This one https://bitcoin.org/en/choose-your-wallet, with some filters to choose a Bitcoin wallet. Below is some filters I used to narrow down the list of wallets to Electrum.
https://bitcoin.org/en/wallets/mobile/android/electrum/?step=5&platform=android&user=experienced&important=control,fees&features=bech32,lightning,multisig,segwit
sr. member
Activity: 322
Merit: 306
Farewell LEO o_e_l_e_o
What about users who download the application and choose to create a new wallet instead of selecting the I already have a wallet option? Will they lead to a Mnemonic or private key request like importing from an existing wallet.

When you create a new wallet, you will generate a new Seed phrase. It is no different from the import wallet option. Because the Seed phrase is still input there. I'm sure it will also be sent to the scammer.

This means that the seed phrase given when creating a new wallet is recorded with all of them (the perpetrators) so that users who cannot distinguish between genuine Electrum and fake ones will lose their stored Bitcoin assets.

What is clear, make sure to download using the link from the official Electrum website (https://electrum.org/#download), even for the Android version of Electrum. Don't search manually on Playstore or other stores such as AppStore. Moreover, until now, there is no Electrum for iOS users.

I ask as above because up to now Electrum does not support iOS but macOS (desktop). So, when iPhone users find Elcetrum app in mobile appstore can clearly know that the app is a scam because Electrum mobile is available on Android devices.


https://electrum.org/#download

Thank you Husna QA
hero member
Activity: 1358
Merit: 538
paper money is going away
The scammer is pretty clever... they didn't embed any malware or other threats that AppStore reviewers could catch. Most likely, its function is just to import private keys. So, the focus of the review process before accepting it for launch on the AppStore, like ransomware, spam, spyware, trojan, ad bots, and other virus types, was intentionally left out.

But it's quite surprising too. Why a major platform like the AppStore did not recognize Electrum and checking deeper into verifying it? Does simply having 'Management' in the app's name make it seem like a new and non-suspicious brand here?

Yesterday, I reported the fake Electrum wallet application to Apple (https://reportaproblem.apple.com/).
I think this could be a solution, but unfortunately, it requires an Apple ID to report. I'm not an Apple user, but I really want to contribute and report the app.
legendary
Activity: 2254
Merit: 2852
#SWGT CERTIK Audited
What about users who download the application and choose to create a new wallet instead of selecting the I already have a wallet option? Will they lead to a Mnemonic or private key request like importing from an existing wallet.

When you create a new wallet, you will generate a new Seed phrase. It is no different from the import wallet option. Because the Seed phrase is still input there. I'm sure it will also be sent to the scammer.

What is clear, make sure to download using the link from the official Electrum website (https://electrum.org/#download), even for the Android version of Electrum. Don't search manually on Playstore or other stores such as AppStore. Moreover, until now, there is no Electrum for iOS users.
legendary
Activity: 1568
Merit: 6660
bitcoincleanup.com / bitmixlist.org
Actually, there's no Electrum installer for iPhone they only support macOS, Android, Linux, and Windows.
And it seems Electrum developers do not have a plan to develop Electrum app on IOS because even if they do release Electrum for iPhone you can't able to install the app if it came from directly on electrum.org.

There's news making the rounds that Apple has plans to enable support for 3rd party app stores (but only for users in Europe). Although I don't know how that would work, I suppose this means that something like the equivalent of F-Droid can be made by some people, and Electrum can publish their app on platform, or even provide a binary that you can download, but opens with that app store by default for the purpose of installation.
hero member
Activity: 854
Merit: 1031
Only BTC
The iPhone, which is said to be superior to Android in terms of security, turns out to be easy to penetrate fake applications like this.
People should not rely on that, and only download their wallet from the original website. Apple app store may be better than Playstore in terms of security, but it doesn't mean that it is impossible to download phishing applications from Apple app store.
What about users who download the application and choose to create a new wallet instead of selecting the I already have a wallet option? Will they lead to a Mnemonic or private key request like importing from an existing wallet.
I do not want to download this scam application into my ios device to find out, but from what Husna QA posted below, i think the scam application would redirect the person to input their recovery phrase or private keys, so their coins can be swept by the scammers into their own wallet.
sr. member
Activity: 322
Merit: 306
Farewell LEO o_e_l_e_o
Yesterday, I reported the fake Electrum wallet application to Apple (https://reportaproblem.apple.com/).

Thanks for doing a great job Husna QA.

I tried downloading the application to see what it contained (just curious, not to be followed -DWYOR). And like other phishing applications, after I tried to open several existing menu buttons (some menus didn't work), they all directed the user to input the Mnemonic or Private Key.

       

The iPhone, which is said to be superior to Android in terms of security, turns out to be easy to penetrate fake applications like this.

What about users who download the application and choose to create a new wallet instead of selecting the I already have a wallet option? Will they lead to a Mnemonic or private key request like importing from an existing wallet.

I ask this so that most iPhone users reading are in the position of not wanting to try installing for fear of something happening.
legendary
Activity: 2254
Merit: 2852
#SWGT CERTIK Audited
I can confirm that this scam application is in Apple app store, this is a screenshot i just took from my IOS device:
✂️

the bad thing is that Apple has not yet removed this fake version from their appstore and therefore victims continue to fall for this scam
today, for example, a user was stolen just over 0.025BTC
https://mempool.space/tx/45e9510feb824cfb78bb074feae39f9fde2884035093f2d39c79b5e6e21ab44b

Yesterday, I reported the fake Electrum wallet application to Apple (https://reportaproblem.apple.com/).


-snip-

I tried downloading the application to see what it contained (just curious, not to be followed -DWYOR). And like other phishing applications, after I tried to open several existing menu buttons (some menus didn't work), they all directed the user to input the Mnemonic or Private Key.

       

legendary
Activity: 3122
Merit: 7618
Cashback 15%
I can confirm that this scam application is in Apple app store, this is a screenshot i just took from my IOS device:
✂️

the bad thing is that Apple has not yet removed this fake version from their appstore and therefore victims continue to fall for this scam
today, for example, a user was stolen just over 0.025BTC
https://mempool.space/tx/45e9510feb824cfb78bb074feae39f9fde2884035093f2d39c79b5e6e21ab44b
hero member
Activity: 854
Merit: 1031
Only BTC
I can confirm that this scam application is in Apple app store, this is a screenshot i just took from my IOS device:

The name of this scam wallet: 'Electrum wallet management' should be suspicious to people because of the word 'management', there is no such thing as Electrum wallet management. Anyway people who do not know what they are doing can fall for this, they wouldn't know that Electrum doesn't have an IOS version and wallet softwares should only be downloaded from the orginal Electrum wallet [1] and verified [2] after download

[1] https://electrum.org/
[2] https://bitcointalksearch.org/topic/m.54223763
legendary
Activity: 2506
Merit: 3645
Buy/Sell crypto at BestChange
So the appstore is now slowly becoming as bad as playstore.
I think they used the word "Management" to fool the Apple Store team, but I am surprised that they are so careless.
Without reports explaining that they are scammers and Apple’s desire to remove any fraudulent content related to Bitcoin, I do not think they will be removed soon.
So they are not bad, but they may want to leave a negative impression of cryptocurrencies, just as here is the slowness in removing any scam crypto video content on YouTube.
hero member
Activity: 1428
Merit: 836
Top Crypto Casino
So its from App Store knowing they claim they are strict on allowing apps to be avoided by their users and here we heard a shitty doing of them from their side. They should be accountable if someone lost their funds by using such fake app.
hero member
Activity: 2002
Merit: 633
Your keys, your responsibility
This fake app has the last label "Management" = Electrum Wallet Management.
And what needs to be noted here is that fake apps are not only electrum.
Quote
LUMI WALLET MANAGEMENT
SAMOURAIWALLET MANAGEMENT
JAXX LIBERTY TRADE
JAXX LIBERTY WALLET MANAGEMENT
FANTOM WALLET MANAGEMENT
AAVE PROTOCOL ASSETS TRADE
https://nitter.net/oscpacey/status/1723758807224893953#m

So the appstore is now slowly becoming as bad as playstore.
legendary
Activity: 3122
Merit: 7618
Cashback 15%
✂️
2. Since Twitter/X is owned by you-know-who and we lazy people dont have accounts on it and hate to create more, please use nitter.net to replace the x.com or twitter.com and be able to view the page easily without logging in. Its a great alternative, do try it.

thank you!
i didn't even have this service on my radar and from now on i will also refer to it or the nitter links in my posts so that all users can benefit from it, of course
as it should be, i have now replaced my opening post with the nitter links Wink
legendary
Activity: 2828
Merit: 1213
Call your grandparents and tell them you love them
Two things I would like to point out here.

1. The official Electrum client for Android is published by Electrum Technologies GmbH and that is the legit one.
For Apple store, I have no idea because I dont use any such device (poor guy here Cheesy). But this should be a point of awareness for common Electrum users to not search for any such apps on Apple store either, they might land up on the scam app.

2. Since Twitter/X is owned by you-know-who and we lazy people dont have accounts on it and hate to create more, please use nitter.net to replace the x.com or twitter.com and be able to view the page easily without logging in. Its a great alternative, do try it.
legendary
Activity: 3234
Merit: 2943
Block halving is coming.
It is worth mentioning that the best place to download Electrum is the Electrum official site. https://electrum.org/

Actually, there's no Electrum installer for iPhone they only support macOS, Android, Linux, and Windows.
And it seems Electrum developers do not have a plan to develop Electrum app on IOS because even if they do release Electrum for iPhone you can't able to install the app if it came from directly on electrum.org.

So if you found the Electrum app on the AppStore don't install it because it's a fake Electrum wallet.
sr. member
Activity: 406
Merit: 443
They have a rating of 4.7 in the store, which are ratings that may deceive some beginners. Reporting the application and leaving a negative rating will give an indication that it is a fraudulent service. Unfortunately, many do not verify the signature, but rather trust the default that the Apple Store is safe. I found some reviews from OCT so it's been about a month without this scam being shut down.
legendary
Activity: 1512
Merit: 4795
It is worth mentioning that the best place to download Electrum is the Electrum official site. https://electrum.org/

To know if the wallet is not a fake one, in a way the site was not compromised to include a fake wallet by hackers, verify the PGP signature. [GUIDE] How to Safely Download and Verify Electrum [Guide]

On app stores, if a wallet that supposed to have over 500 thousand to millions of downloads, but having like 1000 downloads, it is clearly a fake wallet.
legendary
Activity: 3122
Merit: 7618
Cashback 15%
as the twitter/x user @oscpacey informs us with his tweet, there is another fake app from Electrum on the Apple AppStore. the whole offer is very similar to the original app.
you can see the whole process and what happened under the following link: https://nitter.net/oscpacey/status/1723758796806263043

and it looks like this is the scammer address: https://mempool.space/address/1LGou2YkuYLoFkkixLAd3HK6bVvUqX5BLz
the first transaction took place on 08-11 and the last on 12-11 and a total of ~0.42BTC was stolen by these scammers

you can repeat yourself over and over again - be careful with all these apps and double/triple check everything until you install something
Electrum has also already confirmed it


https://nitter.net/ElectrumWallet/status/1724006226785140935
Jump to: