Slashdot Mirror


Users Report Losing Bitcoin in Clever Hack of Electrum Wallets (zdnet.com)

A hacker -- or potentially a group of hackers -- has made over 200 Bitcoin (circa $750,000 at today's exchange) using a clever attack on the infrastructure of the Electrum Bitcoin wallet over the last one week. From a report: The attack resulted in legitimate Electrum wallet apps showing a message on users' computers, urging them to download a malicious wallet update from an unauthorized GitHub repository. The attack began last week on Friday, December 21, and appears to have been temporarily stopped earlier today after GitHub admins took down the hacker's GitHub repository. Admins of the Electrum wallet expect a new attack to soon get underway, with either a new GitHub repo or a link to another download location altogether. This is because the vulnerability at the heart of this attack has remained unpatched, albeit Electrum wallet admins taking steps to mitigate its usability for the attacker.

5 of 72 comments (clear)

  1. Re:LOL ... love these stories ... by MikeDataLink · · Score: 2, Interesting

    The attack resulted in legitimate Electrum wallet apps showing a message on users' computers, urging them to download a malicious wallet update from an unauthorized GitHub repository.

    You know, after so much hype and bullshit around cryptocurrencies, this shit just makes me laugh.

    You wanted to play in an unregulated financial industry, this is what you get. It's the wild west of scams and idiots, and I have no sympathy for any of them.

    Boo fucking hoo, more cryptocurrency fools have lost their money.

    You know people said the same thing when physical currency was introduced. Same exact arguments, physical currency was just stolen by people with bigger muscles and weapons instead of hacking skills.

    --
    Mike @ The Geek Pub. Let's Make Stuff!
  2. Re:LOL ... love these stories ... by Anonymous Coward · · Score: 2, Insightful

    Then keep playing with it. Personally I'll stick with my bank, my stock broker, and my credit card company. Literally millions of dollars have flowed thru these institutions directly by me and not a single penny has been misplaced over decades. I'll stick with what works for me. And exactly what happened when law enforcement was notified of the hack? Anything? I know if someone robbed me of cash I'd call the police and they would at least try to look for the thief.

  3. Re: good by sacrilicious · · Score: 2, Funny
    Burn them! Burn all crypto-currency users!

    And I'm also afraid of the internet, let's burn that too.

    --
    - First they ignore you, then they laugh at you, then ???, then profit.
  4. Re:LOL ... love these stories ... by ArchieBunker · · Score: 2

    Half the time the police steal from you. Get pulled over and have a few thousand dollars on you? It's assumed to be drug money and confiscated under civil forfeiture. You'll get it back eventually after getting a lawyer involved.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
  5. Re:LOL ... love these stories ... by dissy · · Score: 2

    Fortunately, there is a physical limit to what the "bigger muscled" guys can steal from me because I don't carry all the money I own on me all the time. Typically I might have only about 0.01% of it, so that's all they could take - the rest is buried in a secret place in my garden (LoL). OTOH your entire wealth in digital form can be stolen all in one go.

    What's ironic is bitcoin was designed to be used the same way, but for some reason few seem to do so.

    Bitcoin wallets are free, and transferring small amounts into a new one to have with you or for specific purchases is trivial. Similar to only carrying a small amount of cash with you.

    What is far worse however is many people don't even keep *one* wallet let alone multiples.
    They entrust that task to online sites like exchanges to manage their wallet for them.

    It would be akin to not carrying any cash, but instead having Bob hold your cash and follow you around all day in case you need him to take money or hand some out on your behalf.
    The thing is, you don't really know Bob.
    For some people they wake up one day and Bob has disappeared.
    Or one day Bob says he got beaten up and your money was stolen.

    It's quite silly sounding to even have a Bob that does this, but that seems to be the norm.