Author

Topic: when sending payment electrumbay msg comes (Read 224 times)

legendary
Activity: 2576
Merit: 1655
August 06, 2019, 09:29:16 AM
#13
That is a phishing site, you can read it here, [Warning]: Another Electrum Phishing site on the loose.
legendary
Activity: 2758
Merit: 6830
I never try to click that info, and I doubt many users will use that option after everything that has happened and is still happening with older versions. Fact is that they now use digitally signed messages to show that message, but is there any possibility that official server is hacked and used by hackers to show fake links again?
Through this new feature? Very unlikely due to the fact that they sign these messages. The first one already got fixed and I don’t see another exploit like that coming through.

If there is the slightest chance of it, then the only correct option is to verify signature no matter from where it is downloaded from.
That should always be a necessary step.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
I never try to click that info, and I doubt many users will use that option after everything that has happened and is still happening with older versions. Fact is that they now use digitally signed messages to show that message, but is there any possibility that official server is hacked and used by hackers to show fake links again?

If there is the slightest chance of it, then the only correct option is to verify signature no matter from where it is downloaded from.
HCP
legendary
Activity: 2086
Merit: 4361
HCP, all I see in Electrum is notification that new version is available, but not in any pop-up window, it is just message in main window. Is this option to automatically check for software updates only gives information about new version, or it is possible to update to new version via Electrum wallet directly?
I've found that if you click on this notification:



It will pop-up a window that has the update notification:



You can click on the blue link and it will take you automatically to the download page on electrum.org


You can test this quite easily by downloading an older "portable" version... say 3.3.6 from here: https://download.electrum.org/3.3.6/
Run it, and click "yes" when asked if you want to be notified of new versions. You should see the update notification at the bottom of the Electrum window as shown above and should be able to click through from there.
legendary
Activity: 3234
Merit: 5637
Blackjack.fun-Free Raffle-Join&Win $50🎲
August 02, 2019, 05:38:54 AM
#9
najeeb76, please edit your post with link to fake Electrum site (delete link or put it in the code), so some other user is not click on it and download fake wallet.

I hope that we will see more examples like this, more coins safe in user wallets, less in hackers pockets.



HCP, all I see in Electrum is notification that new version is available, but not in any pop-up window, it is just message in main window. Is this option to automatically check for software updates only gives information about new version, or it is possible to update to new version via Electrum wallet directly?
HCP
legendary
Activity: 2086
Merit: 4361
August 02, 2019, 12:13:07 AM
#8
Don't forget to turn off this



Just to make sure that the fake notification won't pop up again.
Fake notifications are not likely to happen again. This particular feature was actually added AFTER the server message vulnerability was patched... it also uses digitally signed messages (with a hardcoded server URL) so that only the official server is able to notify of an update: https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES#L111-L112

Advising people to switch this off may actually result in them missing notifications of new versions that fix critical vulnerabilities... which is kind of why this feature was added in the first place! Tongue
legendary
Activity: 3122
Merit: 1398
For support ➡️ help.bc.game
August 01, 2019, 02:25:39 PM
#7

At last! Someone asked here first before attempting to make a transaction.

Honestly, I understand why others fall on this especially newbies. The popped-up message really looks like an official one.

Good thing OP became curious.

Please do take note of suggestions here. Also, be vigilant to other apps as well.
legendary
Activity: 3374
Merit: 3095
Playbet.io - Crypto Casino and Sportsbook
August 01, 2019, 02:05:03 PM
#6
~snip~

Don't forget to turn off this



Just to make sure that the fake notification won't pop up again.

You can find this under tools>preferences>General>automatically check for software update. Always download the latest Electrum directly to the original website. Electrum.org and learn "How to verify Electrum (for Windows, Linux and Mac)"
jr. member
Activity: 175
Merit: 2
August 01, 2019, 01:14:55 PM
#5

thanks for the new info at least for me:) i just upgraded to latest version and its all working fine now
legendary
Activity: 2870
Merit: 7490
Crypto Swap Exchange
August 01, 2019, 01:11:06 PM
#4
For reference, you can check list of known Electrum server at https://uasf.saltylemon.org/electrum and https://1209k.com/bitcoin-eye/ele.php

If you're curious about this vulnerability, see https://bitcointalksearch.org/topic/electrum-vulnerability-allows-arbitrary-messages-phishing-5090097
jr. member
Activity: 175
Merit: 2
August 01, 2019, 01:10:57 PM
#3
i know electrumbay is a cheat but how i make payment now

Download the latest version of Electrum from the official website. Alternatively, you can try switching to a different server but the update will get rid of such fake messages. Congratulations for not falling for this scam.

let me try it:)

i m saved thanks to GOD then this forum as i keep reading here new things and news Smiley
legendary
Activity: 1876
Merit: 3132
August 01, 2019, 01:08:35 PM
#2
i know electrumbay is a cheat but how i make payment now

Download the latest version of Electrum from the official website. Alternatively, you can try switching to a different server but the update will get rid of such fake messages. Congratulations for not falling for this scam.
jr. member
Activity: 175
Merit: 2
August 01, 2019, 01:06:10 PM
#1
i am using electrum 3.3.2 its working fine for incoming payment but today as i tried to make payment and confirming it

this message pops up

Quote
The server returned an error when broadcasting the transaction.
RPCError(1, '                                                                                                                         
Transaction Denied. Important Electrum Security Vulnerability.                                                                                                                         Transactions can only be sent after upgrading to version 4.0.0
Official Website: https://www.electrumbay.com
')


and payment dont go through

i know electrumbay is a cheat but how i make payment now
Jump to: