Hackers Siphon Bitcoin In Electrum Wallet Attack

Hackers Siphon Bitcoin In Electrum Wallet Attack
ôîòî ïîêàçàíî ñ : cryptobriefing.com

2018-12-28 18:24

If you’ve been buying the dip, you may want to brush up on good security. Crypto wallets are being targeted by cybercriminals, most recently with a phishing attack on the popular Electrum software wallet. Based on blockchain data, at least 200 BTC, worth nearly $730,000, have already been sent to the attacker’s bitcoin address.

While the wallet software itself appears to be secure, the hackers are using dummy nodes to imitate Electrum servers, which then send falsified error messages when users attempt a transaction.

Electrum is aware that it is being targeted, and the company has warned that “there is an ongoing phishing attack against Electrum users,” reminding them of the official website address and urging them not to download the wallet from any other source. It’s not the only attack currently unfolding, and desktop wallet Exodus is similarly warning its users of a“clone website just waiting to steal your crypto presents.”

The attack on Electrum has the social media community on high alert, sharing screenshots of the fake security update like the one below. And, according to an Electrum developer on Github, the attack is not over:

“The attacker has spawned lots of servers on different /16 IPv4s to increase his chances of being connected to. The error messages are trying to get the user to download and install malware (disguised as updated versions of electrum).”

Electrum Phishing Attack Had Warning Signs

Redditors detailed the painful unfoldings of the scam, which started by initiating a send transaction from an Electrum wallet. According to Reddit user, appropriately nicknamed /u/MyElectrumGotHacked, a pop-up rich-text error message appeared, warning: “In order to send please update to the latest version here,” followed by a fake GitHub address.

 

Via Twitter.

Needless to say, a legitimate app from the Appstore or Google Play does need to be updated through Github.

There were other red flags, including having to copy and paste the URL into a browser window. Victims were then prompted to download an application and  to complete two-factor authentication, which is not the norm for these transactions. In the end, the user logged into their account from a separate computer only to discover that their bitcoin balance had been wiped out.

The phishing scams thrust user security into the spotlight and ignited a debate about reasonable security measures that the average user can be expected to use. Exodus, a desktop wallet that is also under attack, recommends “storing large sums of funds on a hardware wallet like Ledger or Trezor.”

As crypto makes its way into the mainstream, there is clearly more work to be done in awareness, cybersecurity, or both.

 

The author is invested in digital assets, including bitcoin which is mentioned in this article.

 

Join the conversation on Telegram and Twitter!

 

The post Hackers Siphon Bitcoin In Electrum Wallet Attack appeared first on Crypto Briefing.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Emerald Crypto (EMD) íà Currencies.ru

$ 0.0095806 (+7.58%)
Îáúåì 24H $0
Èçìåíåèÿ 24h: 2.35 %, 7d: -7.78 %
Cåãîäíÿ L: $0.0086651 - H: $0.0095806
Êàïèòàëèçàöèÿ $183.154k Rank 1690
Öåíà â ÷àñ íîâîñòè $ 0.0048933 (95.79%)

attack wallet electrum bitcoin hackers crypto siphon

attack wallet → Ðåçóëüòàòîâ: 42


Ôîòî:

A Bug Making Ethereum Transactions on Exchanges Vulnerable Has Been Fixed

A bug centering around a new Ethereum token, GasToken, which was enabling abuse on cryptocurrency exchanges, appears to have been resolved. The details are provided in a report originally published on November 13, 2018, that discussed how the bug was exploited by attackers, and what digital platforms could do if they wished to protect their hot wallet funds.

2018-11-22 00:34


Ôîòî:

Gold-Backed AurumCoin Latest to Fall Victim to 51 Percent Attack

Gold-backed AurumCoin is the latest cryptocurrency project to fall victim to 51 percent attack, resulting in the loss of AUD$ 15752. 26, per a report by Finder on November 12, 2018. Hack Attack Results in Blame Game Shortly after the hack attack, AurumCoin’s twitter handle subtly sparked the blame game stating the coins were stolen from the wallet of cryptocurrency exchange.

2018-11-13 12:00


Bitcoin Wallet Samourai Warns Users of “Dusting Attack”

On October 25, 2018, the privacy-centric cryptocurrency wallet Samourai warned users via Twitter of a new type of tracking tactic called a “dusting attack. ” Biting the Dust According to tweets, the attack is an attempt to compromise the security and privacy of Samourai users by using “coin dust” to deanonymize users and linking their transactional inputs together.

2018-10-27 18:00


$7.8M In Cryptocurrency Disappears From Trade.io “Cold Storage”, Hackers Implicated

Switzerland-based Trade. io Suffers Devastating Hack, Cold Wallet Affected In hand-to-hand fist fights, it is not like gentlemen to kick their opponents while they are already down. However, in the emerging cryptocurrency market, which has been bashed by violent sell-offs in the past nine months, malicious actors still seem poised to attack, hack, and steal from […] The post $7.

2018-10-23 03:28


Ôîòî:

Security researchers attack the McCaffy-Backed Vault for “unopened” demands

Operating in such an environment, cautious users are always mindful of their security and learn to avoid outrageous claims that are sometimes nothing more than just that. A recently released wallet was said to be “unhackable” by its promoters, including John McAfee, and this has naturally triggered security researchers. Also Read: Football Team in Gibraltar

2018-8-1 09:29


Ôîòî:

Etherscan rushes to plug vulnerabilities following strange hacking attempts overnight

Etherscan, the most widely used Ethereum blockchain explorer, has quickly patched security vulnerabilities overnight as hackers exploited certain parts of its service. Hackers successfully manipulated the Disqus API – a third-party service used by Etherscan that allows for comments to be left on Ethereum wallet addresses.

2018-7-24 13:00