16 ms·
Users report losing Bitcoin in clever hack of Electrum wallets
- magma17 8y agoThis justify my paranoia about choosing 'random server'
- maria-j 8y agoI also fell victim to this scam and lost quit a lot of my money in bitcoins. They kept pressure me to deposit more money and when I refused, They stopped picking my calls. I have tried a couple of recovery rooms and they are all scams! I finally came across a professional on the dark net who finally was able to help me recover all my money. Lesson learnt! Happy to share my experience. You can reach out to me on recoverbitcoin001@gmail.com.
- yqh 8y agoJust by looking at the screenshot I already knew the "Electrum" client was written using Qt. :P QMessageBox displays text as HTML (formatting, links and all) by default, which I've always thought is a terrible choice.
- ziont 8y agoif this was a bank, he wouldve gotten it all back. decentralize for the sake of it is foolish.
- onetimemanytime 8y agoFor Banks press 1. For Not-Banks press number 2 or stay on the line. The entire point of Bitcoin is decentralization, the rest is growing pains and price of doing business.
- trophycase 8y agoOk? That's the trade off. Some people understand that having freedom has consequences.
- xpaulbettsx 8y agoIt's bananas that people are downmodding you on this point. A financial system or security / commodity that literally has no recourse in the face of crime or even simple clerical error, is an unusable financial system. Can you imagine if everyone who had a credit card stolen was just liable for anything bought?
- Klathmon 8y agoAnd a financial system that allows some group somewhere to decide if i'm allowed to buy (or sell!) some things, can lock my funds at any time for many reasons, and can track and sell information about what and where I bought things to any number of various 3rd parties is also similarly "unusable" for some. It's a tradeoff like anything else. For some people, the risk is worth the benefit. For others it's not. Still more find the risk worth the benefits for a subset of their money, and not for the rest. All of these "financial systems" can happily coexist, and none of them are completely broken, they just prioritize different things and make different tradeoffs. Also, bitcoin doesn't require being a lawless land where everyone can do anything all the time. It's like cash, but electronic. If a thief breaks into your house and steals $10,000 in cash, will the police give you $10,000? If they find the guy and he still has it, sure! But what if he burned it? or spent it? now you are fucked. It's the same with bitcoin. if they catch the person who did this, the courts can force him to return the money with threat of lots of jail time and more. If he doesn't have it, then the users that had it stolen are fucked.
- ziont 8y agoyou are comparing apples to oranges.
- wan23 8y agoCash has the same properties and people have been using it for millennia.
- satsuma 8y agocash is a physical entity, though -- i'm not sure there's a parallel to be drawn there
- 46456hfgfg 8y agoYes, and we would all pay for this persons mistakes through increased insurance premiums. What if I don't want to have to pay for someone elses mistakes? What if there was a world in which one had to take responsibility for their money? No do overs. This is cryptocurrency.
- giornogiovanna 8y agoOkay, but you realize that most people want insurance, right? In this case, it wasn't even the guy's fault that Electrum displayed the hacker's message as something official. Do you really want a society where some other person's stupid mistakes can destroy your life?
- wallacoloo 8y ago> most people I’m pretty sure GP isn’t trying to say that everyone should use Bitcoin. The thing that gets annoying is that there is a crowd that campaigns this, and then other people (particularly in this comment section) fight back saying nobody should use Bitcoin. The obvious fact which I feel is somehow being overlooked here is that different people have different needs and there is no one-size-fits-all solution to banking today.
- Nursie 8y agoAnd those people will be perfectly happy until it affects them. As a society, we tend to protect people from themselves because the other option is to let them die on the streets when they lose it all. Making people have insurance and using banks and payment systems that have built-in protection, is far cheaper than providing welfare for those that would otherwise be scammed out of every penny, irreversibly. You can be a self-serving ubermensch the same day you opt out of all social help.
- feanaro 8y agoOpting out of all social help usually doesn't exist as an option at all.
- lawn 8y agoNot when it's the bank or government who takes your money.
- spookthesunset 8y ago> Not when it's the bank or government who takes your money. With Ethereum it was the core developers / top of the pyramid who stole wealth from the the DAO "hacker" who cleverly found a loophole in the "Code Is Law" contract everybody agreed to and used it to their advantage. The Ethereum devs, coupled with mob rule, clawed back all the transactions and literally stole the funds back. I'd rather have due process provided by a government than mob rule.
- Tehnix 8y agoIncredible to read how dismissive people in the thread are about the shortcomings of decentralization, up to the point where it feels like people are just praising gospel without ever having given it a critical thought. There is still quite a valley between feasibility of crypto currencies in real world settings, and the current state of affairs.
- trophycase 8y agoCryptocurrency is feasible and is being used in "real world settings" right now. So many things are ruined by people preferring safety over freedom so I don't thinn this sort of thing bothers a freedom loving person.
- ceejayoz 8y agoI suspect it somewhat bothers the freedom loving person (or people) who's out 200 BTC.
- rejschaap 8y agoIt is unlikely anyone lost 200 BTC, we can't say for sure because Bitcoin wallets are pseudonymous. But what happened is that someone received a lot of BTC from a lot of different wallets. I would hope that someone who owns 200 BTC would put a little thought into how to secure it and would not be affected by this hack.
- root_axis 8y agoAnd this is why BTC will never be mainstream. All it takes is a single misstep to lose all of your money forever. Why would average citizens take that deal over the security guarantees provided by the incumbent financial institutions?
- acct1771 8y agoIf cryptocurrencies were the main currency, do you think anyone would feel bad if someone kept their entire net worth in a single wallet? This would be the social prudence equivalent of walking around 24/7 with all of your life savings in cash.
- tdons 8y agoThe related GitHub issue: https://github.com/spesmilo/electrum/issues/4968 https://github.com/spesmilo/electrum/issues/4968
- ErikAugust 8y agoI decided to stay far away from Electrum after Tavis from Project Zero reported a big time bug in Electrum's JSON-RPC back in January. I remember him claiming his dealings with the team were frustrating as well (gist: they didn't understand the problem). Source: https://blockexplorer.com/news/electrum-releases-update-google-project-zero-researcher-discovers-2-year-old-vulnerability-wallet-client/ https://blockexplorer.com/news/electrum-releases-update-goog...
- chabes 8y agoAnother reminder to run your own full node. If you use SPV wallets, you have to trust the nodes you connect to. Electrum lets you connect to your own node.
- lawn 8y agoThis has nothing to do with SPV wallets. A full node client could suffer from the same vulnerability.
- chabes 8y agoNo. The malicious links were from malicious nodes. You can run your own node, and connect only to your node. https://github.com/chris-belcher/electrum-personal-server https://github.com/chris-belcher/electrum-personal-server
- fabian2k 8y agoIf I understand this correctly, this is quite a flaw in the design of the client. The message is shown in the client, but is simply the response of an essentially random server in the network. That response is displayed with full formatting in the client as if it were an error message by the client itself. I never used any of this, but it really doesn't look to me like it is unreasonable to assume that error messages like this are created by the client, not an untrusted server. Untrusted servers should not be able to inject content like this.
- zuck9 8y agoThis is another reminder of why people should be using hardware wallets. It is relatively super cheap compared to the value of 1 BTC.
- dcosson 8y agoIt all depends what you calculate to be the biggest risks that you're protecting against. If it's collapse of world civilization, or at least your own country's institutions, then storing your own coins makes sense, and yeah a hardware wallet is a better way to store it than on your computer. On the other hand, if you're more worried about getting hacked or simply losing your private keys, having your house broken into and the wallet stolen, etc. you're probably better off putting it in Coinbase with a strong password and 2FA enabled. The same way you protect other things you care about like your bank account and 401k. It's odd to me that this is so highly frowned upon in the cryptocurrency communities though. People with very little knowledge about computers or infosec are constantly pressured into storing their own coins, which is fundamentally pretty user-unfriendly just due to the irreversible nature of it where you can't make a single mistake.
- rocqua 8y agoI guess this is a response to mtgox and other exchanges that turned out to be insolvent. Moreover, it prevents the situation where an ill regulated institution denies you access to your credit. See also the stories about PayPal accounts being frozen.
- splintercell 8y ago> you're probably better off putting it in Coinbase with a strong password and 2FA enabled. The same way you protect other things you care about like your bank account and 401k. This is not a good idea. There is a big difference between your bank account/401k and crypto. If Coinbase gets hacked, you aren't really getting your crypto back. If your 401k account gets hacked, there is at least some recourse.
- JumpCrisscross 8y ago> If it's collapse of world civilization, or at least your own country's institutions, then storing your own coins makes sense Why would cryptocurrencies of all things hold value amidst a collapse of world civilization? In those environments, food, guns and ammunition rule.
- Meekro 8y agoThis is actually super-clever, let me try to explain. Electrum is unique in that it's not a "real" bitcoin wallet. To save time and computer resources, it doesn't download the entire blockchain but rather connects to an Electrum Server which will do the blockchain stuff on your behalf. The Electrum Servers (anyone can run one) can check your balance and send bitcoin on your behalf. Thanks to the magic of cryptography, this is all perfectly safe. If you send bitcoin through them, they couldn't redirect it to themselves. The worst they could do is refuse to send it. Turns out Electrum Servers are allowed to return custom error messages to the client, though. So this guy set up a bunch of these servers and had them always return a message saying "Please update your electrum here: http://github.com/my-hostile-electrum/steal-yo-coins.git" http://github.com/my-hostile-electrum/steal-yo-coins.git". What's worse, because Electrum is using the QT QMessageBox, these errors are displayed with full HTML rendering, making them look even more convincing. So, crap. Bitcoin is, as they say, a bug bounty on the entire world.
- sleepybrett 8y agoIs this just a roundabout way to get paid for finding the bug ;)
- Kaveren 8y agoHere is a picture from the Reddit thread [0]. Absolutely unacceptable design not to account for something like that when programming software. There should be an explicit notice of where the message is coming from. I see people blaming users for trusting a new GitHub repository, but the fault rests solely on the contributors to the project responsible for this. [0] https://user-images.githubusercontent.com/29142493/50359293-8780b500-055c-11e9-8cfd-83b342edeffb.png https://user-images.githubusercontent.com/29142493/50359293-...
- Meekro 8y agoYou're right, and Electrum actually has a history of severe security bugs. I think there was one a while back where any website you visit could use JS to connect to Electrum's RPC interface and do things on your behalf.
- 8y ago
- InGodsName 8y agoLet me ask the experts before i lose my 2000 bitcoins. Before this, i was about to store them in electrum wallet, glad i didn't do that. Where would you store your bitcoins to avoid being hacked? I store those coins somewhere and i haven't been looking at them since i think accessing them again and again get them hacked. So where should we store bitcoins?
- tylersmith 8y agoA hardware wallet like Trezor or Ledger. I use both and both are great. Nothing is fool-proof but an offline hardware wallet is your best bet.
- ceejayoz 8y agoCareful where you buy them, though. https://techcrunch.com/2018/03/21/a-15-year-old-hacked-the-secure-ledger-crypto-wallet/ https://techcrunch.com/2018/03/21/a-15-year-old-hacked-the-s...
- Scoundreller 8y agoWhat’s wrong with an offline softwallet?
- cypherpunks01 8y agoI lost 1 btc due to an early Trezor UI bug ("bug in 3rd party cryptographic javacript library used by mytrezor.com on OS X"). Fixed years ago and they did reimburse me, their team is great. I fully support the product, but yes it's evidence that nothing is perfect.
- greenshackle2 8y agoCall me paranoid but if I owned a bunch of btc I wouldn't go around announcing it on public forums, there are have been targeted attacks against people who own a lot.
- berberous 8y agoIf you want to avoid being hacked, the best first step is probably to avoid posting to a technical forum the fact you have 2000 bitcoins, using a non-burner account that includes your gmail and other personal info. In all seriousness, if you really have that many bitcoin (I suspect you may have meant $2k worth of bitcoin), seriously consider your opsec. Make sure you have 2FA on your gmail and other important accounts, with no phone number linked (i.e. software 2FA only; people are porting phone numbers and then resetting 2FA).
- shiado 8y agoLooking at the commit, I am wondering if there is still a vulnerability in sending error messages. What if the malicious server DOS'd the client by sending an extremely long error message crashing the client when it tries to render it. This also doesn't stop a simple plaintext message that has a phishing message like "Your machine has been hacked and your keys have been compromised, please transfer x BTC to y address within 5 minutes to prevent your private keys from being immediately drained".
- leppr 8y agoYea, only allowing servers to send a naked error code matched against a list of preloaded human-readable strings on the clients seems to be the only option that's actually social-engineering proof. If custom error messages are really needed, you could allow them as a special option while making it obvious through the client UI that this is sent from an untrusted source (field hidden by default, warning displayed when full error message is expanded). The safest option now is just to consider Electrum as insecure by default. Same with Ethereum's Parity desktop and Metamask. They're convenient for day to day use but don't trust them with big amounts. EDIT: Seems that's already been discussed in the issue: https://github.com/spesmilo/electrum/issues/4968#issuecomment-450169512 https://github.com/spesmilo/electrum/issues/4968#issuecommen...
- ccnafr 8y agoWell-explained ZDNet article about it: https://www.zdnet.com/article/users-report-losing-bitcoin-in-clever-hack-of-electrum-wallets/ https://www.zdnet.com/article/users-report-losing-bitcoin-in... You should have shared this link instead of that Reddit thread.
- ccnafr 8y agoMaybe a mod can replace the link
- AlexCoventry 8y agoIt looks like it's been replaced. Was this the original link? https://www.reddit.com/r/CryptoCurrency/comments/a9yji3/electrum_wallet_hacked_200_btc_stolen_so_far/ https://www.reddit.com/r/CryptoCurrency/comments/a9yji3/elec...
- dang 8y agoOk, we've changed to that from https://www.reddit.com/r/CryptoCurrency/comments/a9yji3/electrum_wallet_hacked_200_btc_stolen_so_far/ https://www.reddit.com/r/CryptoCurrency/comments/a9yji3/elec.... Thanks! Please don't break the site guidelines by calling names or being personally rude though: https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html. It's enough to offer a better link.
- ccnafr 8y agoThanks. Will do.
- deleted 8y ago[deleted]
- 21 8y agoI wonder how long it will take until people understand why nobody is "their own bank" with their cash. Getting hacked is one worry, I would worry even more about someone with a wrench in my apartment.
- pera 8y agohttps://github.com/spesmilo/electrum/issues/4968 https://github.com/spesmilo/electrum/issues/4968 This bug is absolutely atrocious: who decided that displaying error messages (with rendered HTML!) from untrusted third-party servers was a good idea? It's a shame since SPV wallets are a great solution for most users, and Electrum has a relatively nice UI, but after this bug and the JSON-RPC one who will keep using this software?
- yongjik 8y agoWow the mod comment on the reddit thread is golden: https://old.reddit.com/r/CryptoCurrency/comments/a9yji3/electrum_wallet_hacked_200_btc_stolen_so_far/ https://old.reddit.com/r/CryptoCurrency/comments/a9yji3/elec... > Just to clarify the "hacked" part of the title: > Technically speaking, even though the term 'hacked' is broad, what happened was an attacker utilized the server response/messaging capability to phish users (it was more convincing because rich text was allowed to display in the electrum client). The message provided a link to "upgrade electrum", but was actually installing a malicious clone. > The attacker amplified their reach by spinning up more malicious servers which could loosely be considered a sybil attack. > People using the correct wallet software and not clicking any links are unaffected. Electrum was no more "hacked" than gmail is hacked every time one of their users is sent a phishing email
- thisacctforreal 8y agoPeople expect to be phished when opening emails in Gmail, they don't expect to have to distrust native app dialogs.
- mxscho 8y agoThis reminds me of the countless malicious TeamSpeak servers who send out fake "TeamSpeak needs an update: [evil-url]" messages with the server message or poke feature. (The second one displays an arbitrary text in a simple message box, e.g. sent by a bot when joining the server).
- lkdjjdjjjdskjd 8y agoSeems to me at least using Electrum for cold wallets as you should would not have been susceptible to the attack.