Electrum: BTC Stolen

Created on 5 Feb 2019  路  71Comments  路  Source: spesmilo/electrum

They stole 0,09 btc from me
Why Electrum shows me that I have to update software ?
I was using it for 1 year and this fucking message came from Electrum server

Adress:
bc1qvr93mxj5ep58wlchdducthe89hcmk3a4uqpw3c

phishing 馃帲

Most helpful comment

It is not an excuse from Electrum. it is a simple explanation from me, personally.

Where did you download the first Electrum from? electrum.org

The second one was downloaded from a different source. Electrum.org clearly states do not download from other sources.

Your protection program cannot recognize the fake side, because the attack is simple and is not related to a security exploit, it just sends a message that QT parses as rich text.

You can receive such messages by any other channel, like email, phone, sms, etc. - if you follow the malicious link the effect is still the same, so yes I sincerely think it's the responsibility of the users. Running out of date software is not recommended especially security software or finance software. Installing unverified binaries from untrusted sources is even worse, and there's absolutely nothing that those app developers can do to protect you against this.

Electrum does not earn any money from it. If Electrum was malicious, I assure you funds would have been taken in a smarter way and not via the oldest scam in the history of the internet: phishing, which happens every day to ALL online services...

All 71 comments

Is a fucking action, since they had no password, etc.

Delete everything and reinstall it.

We are sorry for this, but this message is confusing and too alarming and causes panic among users.

Electrum doesn't have a bug that can be exploited, it cannot be controlled remotely, it has no open vulnerability that can cause loss without user's action. Electrum was no more "hacked" or "exploited" than gmail, yahoo, outlook and all financial institutions (banks, etc.) as well as various other online services are every day.

Because of how peer discovery works in Electrum, there is not much we can do for old versions, since we can't prevent them with 100% success rate to run into a malicious server. This is because, unlike other lightweight wallets, Electrum decided to not have only few harcoded servers that will be responsible for the privacy of all users, and act as single point of failure, but instead allow users to run their own servers or use servers that they trust. Electrum takes user privacy very seriously, which is why proper peer to peer discovery without central authority arbitration was adopted, instead of anything else. This way an attacker cannot keep an Electrum user offline, or isolate him, or pull various attacks.

While the entire Electrum team is doing absolutely everything possible to protect the users, such as:

  • patch Electrum wallet to not display rich text, and don't allow arbitrary messages, only strict codes;

  • patch ElectrumX server implementation to detect sybil (malicious servers that send the phishing message) and not further broadcast them to clients;

  • implement blacklist logic to maintain malicious servers outside the view of the clients;

  • heavily advertise on social, website and all communication forms existent with the users that they should always run the latest version and always only install from the official source (electrum.org), accessed over secure protocol (https) with prior verifications of the PGP signature;

...the sad truth is that nothing can be truly done to protect an user from its own actions. If you are willing to install Electrum from a different source, when the official is electrum.org, and you don't verify signatures, even with the latest patch that does not display rich text you are still vulnerable as you can receive an email or text message with the same phishing message, and install a backdoored Electrum.

After all, when you install and use security software and finances software such as Electrum the first rule is to make sure you are running a version that has no discovered vulnerabilities and your build is signed and genuine.

I know this is not pleasant to read after loss of funds, and we are sorry, but this is the sad truth. This is not a vulnerability in Electrum, so we are going to respectfully close such issues / tickets on github because we are already doing everything possible to limit the effects of phishing attacks, and such issues do not provide any new information.

A nice excuse from Electrum. Have the wallet displayed, update as it is synonymous with many other programs that
was led directly from the wallet to the homepage. This deportation of responsibility to users is an insolence. Even my protection program did not recognize the fake side. Choose another provider, since the comment page Electrum is a naughtiness !!!!!
Ciao Electrum
Fuckup Electrum - Electrum still earns money from it!!!!

It is not an excuse from Electrum. it is a simple explanation from me, personally.

Where did you download the first Electrum from? electrum.org

The second one was downloaded from a different source. Electrum.org clearly states do not download from other sources.

Your protection program cannot recognize the fake side, because the attack is simple and is not related to a security exploit, it just sends a message that QT parses as rich text.

You can receive such messages by any other channel, like email, phone, sms, etc. - if you follow the malicious link the effect is still the same, so yes I sincerely think it's the responsibility of the users. Running out of date software is not recommended especially security software or finance software. Installing unverified binaries from untrusted sources is even worse, and there's absolutely nothing that those app developers can do to protect you against this.

Electrum does not earn any money from it. If Electrum was malicious, I assure you funds would have been taken in a smarter way and not via the oldest scam in the history of the internet: phishing, which happens every day to ALL online services...

bc1qcygs9dl4pqw6atc4yqudrzd76p3r9cp6xp2kny stole me 0.00796663 BTC

I just lost 1,400 BTC via the same method described above.

bc1qcygs9dl4pqw6atc4yqudrzd76p3r9cp6xp2kny is the receivers address.

I just lost 1,400 BTC via the same method described above.

Could you provide more details about how it happened?

I had 1,400 BTC in a wallet that I had not accessed since 2017. I foolishly installed the old version of the electrum wallet. My coins propagated. I attempted to transfer about 1 BTC however was unable to proceed. A pop-up displayed stating I was required to update my security prior to being able to transfer funds.

I installed the update which immediately triggered the transfer of my entire balance to a scammers address.

They may not have stolen your BCH and BSV yet.

I recommend moving those to another wallet using ANOTHER COMPUTER. Yours is possibly compromised.

They may not have stolen your BCH and BSV yet.

I recommend moving those to another wallet using ANOTHER COMPUTER. Yours is possibly compromised.

@1400BitcoinStolen If you need quick help to do that, contact me

@1400BitcoinStolen I would recommend you install:

Then import your seed, and sweep the BCH/BSV somewhere else and dump them for BTC to reclaim some value. The value of your fork coins are currently worth just over $500k.

I can't comment on the code quality of those Electrum forks but I had a quick look and they appear to be genuine. I'd say it's worth the risk considering the situation.

I accessed the BCH back in 2017 when I moved the BTC into the new electrum wallet.

I appreciate the productive thoughts guys.

Cheers

@1400BitcoinStolen Please join #electrum on freenode to discuss this further

Furthermore BSV and BCH, you can extract more forks, if you need help I can advice you

@1400BitcoinStolen I would recommend you install:

Then import your seed, and sweep the BCH/BSV somewhere else and dump them for BTC to reclaim some value. The value of your fork coins are currently worth just over $500k.

I can't comment on the code quality of those Electrum forks but I had a quick look and they appear to be genuine. I'd say it's worth the risk considering the situation.

Care to explain? I thought that Bitcoin SV was a fork from Bitcoin Cash. You can still claim the coins with your Bitcoin seed?

Care to explain? I thought that Bitcoin SV was a fork from Bitcoin Cash. You can still claim the coins with your Bitcoin seed?

If you haven't touched your BCH UTXOs since the fork then yes, you'll also have the same UTXOs on BSV and the same seed can be used to spend the funds on both chains.

Care to explain? I thought that Bitcoin SV was a fork from Bitcoin Cash. You can still claim the coins with your Bitcoin seed?

If you haven't touched your BCH UTXOs since the fork then yes, you'll also have the same UTXOs on BSV and the same seed can be used to spend the funds on both chains.

Ah, check. I claimed my BCH and sold them already. :-) So, nothing left there for me.

Hacker changed the code of new Electrum version or update link.. i remember long time ago Electrum notify about this bug!

@1400BitcoinStolen Please join #electrum on freenode to discuss this further

can you plese give me a link to the site?

I'm having the same issue

@1400BitcoinStolen I鈥檓 so so sorry man, this is so disheartening, $17 million gone. you still have some unclaimed forked coins. If you need any help with that, I could help you.

Just here to pay respects.

Sickening sorry bro

@1400BitcoinStolen I really wish the best for you! Good luck with recovering your bitcoin.

I'm just here to grief with you. I'm truly sorry for your loss.
Good luck with the UTOx forks claims, if any
Best regards from Norway

@1400BitcoinStolen please report the theft to the police.

@1400BitcoinStolen you could also claim your HEX :

Have a heart, he's already been scammed once today...

@1400BitcoinStolen Sorry mate, just going to add depending on where you're from, I'd definitely go to the police with this.

@1400BitcoinStolen Sorry mate, just going to add depending on where you're from, I'd definitely go to the police with this.

Hi, what value is reporting it to police? Is there a global online system where one can report such losses?

Just here to pay respects.

Thanks

You still have $20k worth of coins to claim according to http://www.findmycoins.ninja/
It might not be much, but it鈥檚 something I guess?

@1400BitcoinStolen

thats 14m $ gone. wow.
may I know how are you feeling ?

@itsukiuehara i assume not too great, no matter his/her total net worth. what do you expect the answer to be??

@jeffwalsh he is too nonchalant about it. I assume he is holding more bitcoins perhaps a 10k more bitcoins...

Hmmm, the question did make me laugh which was a positive. Not sure what else to say.

The 1,400 was the vast vast majority of my holdings.

@jeffwalsh he is too nonchalant about it. I assume he is holding more bitcoins perhaps a 10k more bitcoins...

I am preserving my energy for the day that I locate the team that scammed me. They have begun moving my coins around. The battle has just begun.

@1400BitcoinStolen
if you don't mind please update us !

You still have $20k worth of coins to claim according to http://www.findmycoins.ninja/
It might not be much, but it鈥檚 something I guess?

Thanks for the heads up.

Best of luck ! I got scammed myself for a couples Ethereum back in the day.

Let us know if we can help you out !!

You still have $20k worth of coins to claim according to http://www.findmycoins.ninja/
It might not be much, but it鈥檚 something I guess?

Thanks for the heads up.

Sure thing. If you need any help with claiming, just let me know.

I am preserving my energy for the day that I locate the team that scammed me. They have begun moving my coins around. The battle has just begun.

Hey, Siam here,

The person who took coins from this address bc1qcygs9dl4pqw6atc4yqudrzd76p3r9cp6xp2kny put has put them into 5 separate addresses, as of now they still have bitcoin in them.

https://blockchair.com/bitcoin/address/bc1qs54aqpcx3729cty3tuad4kzsru65l62mdja7hs (468.50325600 BTC)
https://blockchair.com/bitcoin/address/bc1qf8a68mrn93qv7s8r5lgusyqf5cpdka2yuf0crp (500.77155513 BTC)
https://blockchair.com/bitcoin/address/bc1q5fvlcfg33ae6wvuf7dz8fpnj9w7qfplekedqf0 (113.85565800 BTC)
https://blockchair.com/bitcoin/address/bc1qt4w97nlatj40ya8fkkxeng235earyr0lh0j079 (236.14417365 BTC)
https://blockchair.com/bitcoin/address/bc1qyzxepepphr4f53577v8mrn5quyk0jjvjxh34mx (86.30408664 BTC)

Keep an eye on em if they move to exchange addresses. Contact exchanges to blacklist addresses etc.

I am preserving my energy for the day that I locate the team that scammed me. They have begun moving my coins around. The battle has just begun.

Really sorry to hear this. I can't imagine what it feels like to lose that much. Have you considered contacting an investigations company? A quick Google search turned up a bunch of them.

I am preserving my energy for the day that I locate the team that scammed me. They have begun moving my coins around. The battle has just begun.

Really sorry to hear this. I can't imagine what it feels like to lose that much. Have you considered contacting an investigations company? A quick Google search turned up a bunch of them.

I have contacted coinfirm to date and am waiting for them to get back to me. Do you have any other suggestions?

I am preserving my energy for the day that I locate the team that scammed me. They have begun moving my coins around. The battle has just begun.

Really sorry to hear this. I can't imagine what it feels like to lose that much. Have you considered contacting an investigations company? A quick Google search turned up a bunch of them.

I have contacted coinfirm to date and am waiting for them to get back to me. Do you have any other suggestions?

Glad to hear that. I've worked with a company called Cipherblade in the UK. They're pretty good.

@1400BitcoinStolen With regards to reporting to the police: Which country / jurisdiction are you in, if you can share at all.

I am in a western country however wish not to say in this open forum.

@1400BitcoinStolen With regards to reporting to the police: Which country / jurisdiction are you in, if you can share at all.

I am in a western country however wish not to say in this open forum.

Don't $ROPE

@pbandlotsofj Go fuck yourself. You鈥檙e a disgraceful pile of elephant shit.

@spesmilo time to lock the comments on this I think. Scammers have found this thread and are exploiting it. The hex scam, someone posting a fake recovery service, and now @fiubit begging for money.

@rbrooklyn I agree.. Lock it down..

For the record.. @1400BitcoinStolen
As of yesterday..Out of what i read.. Binance and other exchanges are now Black listing the TxId, and address that touch them.
Nothing much more to do about this tragic story.

@1400BitcoinStolen there is a police investigation going on in Germany and in the UK.
we will report your loss, but it will have more weight if you report it too.

Hello
I had a similar situation 2 months ago.
36.5 Bitcoin was stolen from my address 36xej1oQw82Jz51kjBhcmV3Eb8a8vkwtrw to bc1qy303ar4jjy2x0efn00aqdlfvn48a0gddj355fv - https://blockchair.com/bitcoin/transaction/34ce7a78c6379d3176200deffd26798901dba1c726663e177d6ca9c1cf18643e

Now stolen Bitcoin are at addresses:
bc1qpk0w9pvhqrxn29vzpxpjl87w4g9hlvmv0jkmv0 (9.8181 BTC)
bc1qwtanse4pk26v0kvxcpxrfnzmnjgcxl9vkkw05t (5.4984 BTC)
bc1qstdm72hj07fxwn30j3cecxrfxnzh6ssx02thqa (4.93063517 BTC)
bc1q9wt8rfmk473nz7nh7hpgl7euhrem3n8kmag0e8 (7.83 BTC)
bc1qxn4xt0sfev5snxdgr0anrjtt5346att0gedaxz (5.55171966 BTC)

Some of the stolen Bitcoin went to Binance, but they ignore my appeals and do not return.
Cover up fraudsters.

@1400BitcoinStolen there is a police investigation going on in Germany and in the UK.
we will report your loss, but it will have more weight if you report it too.

How so? How do you know an investigation has kicked off?

Working with Electrum wallet is not easy.
I have been using it since 2014. I managed to save assets. There is a safe work algorithm.
Interesting to b2b-buy coins. // t.me finist4x

The HEX snapshot was on December 2nd 2019, you have until November 19th to claim with your electrum wallet. These people are not being helpful, your Bitcoin is gone forever join t.me/HEXCrypto and we'll help you with claiming HEX.

Whoever is deleting HEX comments is a scammer, you can claim it free just like any other hard fork.

Alternatively DM @RichardHeartWin and discuss it.

@1400BitcoinStolen there is a police investigation going on in Germany and in the UK.
we will report your loss, but it will have more weight if you report it too.

How so? How do you know an investigation has kicked off?

We (electrum developers) have reported the phishing attack to the police about a year ago.
I cannot make any comments about the progress of the investigation, but it helps if victims report it independently.
If you live in Germany you should contact the cybercrime unit of the LKA Berlin

That hurts mate 馃槱

The lesson for others? Use a hardware wallet if your BTC(others apply as well) holdings worth more than you afford to lose. Probably anything more than 1k$ should be stored on a hardware wallet. There are plenty of them.

The lesson for others? Use a hardware wallet if your BTC(others apply as well) holdings worth more than you afford to lose. Probably anything more than 1k$ should be stored on a hardware wallet. There are plenty of them.

Might be a stupid question here. It is possible for the software that's connected to the Hardware Wallet (Ledger Live, electrum etc) to be hacked? Even though the hardware wallet is saying it is going to a certain address is is actually going to a hacker address.

2FA wallet or Hardware wallet helps of course - you still need to verify where you send your coins, there is clipboard changing malware which will replace the recipient address...

Most importantly: Don't click on links in popups in Electrum (new versions won't have popups). Don't download updates from sites other than the offical site (electrum.org) and verify your release. There are youtube videos and tutorials how to do so.

Came here to pay respects, too. F

1400 BTC and using electrum. Stop Drama. Stop Lie !
buy u a Leger Nano cost 0.0014BTC

too many naive people, or it's the same person?

don't randomly trust people on the internet

he probably own an alternative wallet and want to spread rumors/fuds

(Off-topic and will remove this post on 6 Sep:) @1400BitcoinStolen please email me, on the topic of making a difference for others and the future.

and the ads are starting :trollface:

the ads are starting

Indeed.

Locked for now. Not much more can be said here.

Was this page helpful?
0 / 5 - 0 ratings