Bitcoin Wallet Hacked

zdnet.com/article/users-report-losing-bitcoin-in-clever-hack-of-electrum-wallets/

EXIT ALL CRYPTO MARKETS

Attached: electrum-error-message.png (571x335, 27K)

Other urls found in this thread:

zdnet.com/article/users-report-losing-bitcoin-in-clever-hack-of-electrum-wallets/
twitter.com/NSFWRedditImage

good thing i use a usb cold wallet and not some fucking pajeet electum bullshit.

How the fuck is crypto supposed to reach mainstream audience when things like this can happen? The average normalfag doesnt know how to verify checksums.

It's just retards falling for a phishing scam and DOWNLOADING A COMPLETELY DIFFERENT WALLET

The average normalfag doest even know what a checksum is

the problem is that retards are the ones who need to be able to use it for it to ever matter outside of NEETs.

>zdnet.com/article/users-report-losing-bitcoin-in-clever-hack-of-electrum-wallets/
>The problem here is that Electrum servers are allowed to trigger popups with custom text inside users' wallets.
Wait...so you can make the popup say anything you want it to?
Holy shit someone please make this lulzy with race war now messages and shit

jonald fyookball is a fucking moron

What is a checksum?

and yeah, this is pretty bad for bitcoin

I got sum nuts you can check

The fact that bitcoin transactions can't be reverted is a huge problem within cryptocurrencies.

A checksum is a string of characters which guarantee no changes were done to a piece of software after downloading. If the checksum doesn't match, it means the software has been tampered with or damaged.

>it means the software has been tampered with or damaged
Or that it's just a different file...
The popup said they had to update and provided a fake github repo. How the fuck would checksums help in this situation? They're just provide a fake checksum hash in the fake repo

Each file produces a unique checksum. You can't have a different file with the same checksum.

>checksum has no collisions
Brainlet.

Alright, you're retarded. Let me argue your position for you

You(faggot): b-but user! If they go to the site the attacker could just post a check-sum that matches the one on the trojan file
Me: Well just write down the checksum the first time you download the legitimate file. Also jonald fyookball is an idiot for letting this happen

>he doesn't know what a collision is
Brainlet.

>retards being retards
thanks just bought 100k

>Each file produces a unique checksum.

He posted
>it means the software has been tampered with or damaged
So I reply"
>Or that it's just a different file

And he doesn't understand...

I can't even...

And then he ignores the fact that fake file signatures would be provided in the fake repo.

bizlets lmao

There's a better chance of winning the lottery a hundred times in a row than to get a collision in SHA 256. go be retarded some place else

SHAQ 420 HAKED
SELL ALL CREEPCURRENTCIS
BIT TORRENT CRACK AVAILABLE FOR DOWNLOW

This is why mass adoption needs regulated and safe (and backed) exchanges.. people are too stupid, they can handle user names and passwords, maybe two factor authentication but nothing else, not wallets with upgrades, seeds etc.

What a fucking retard, unbelievable.

>invent freedom fulfilling decentralized currency in which no world banks or reigning arbiter powers can manipulate the transactions against your will.
>complain about how that's a bad thing

It's like you enjoy being jewish.

>guy made 750k in 24 hours
>wasn't even a highly technical attack
>literally just a 0 day and phishing

yes because the chances of the malware having a collision are worth mentioning

MD5 would like a word with you.

>jonald fyookball is a fucking moron
that's a bug in the original electrum, not just the fork.

Ledger and Trezor are hacked too. There is a thread up right now

tfw Skywire automatically verifies checksums

Big if true

This shows me that software developers have their heads up their own ass. It doesn't say anything about cryptocurrency.

there's a direct relationship between developers and cryptocurrency, it actually says a lot.

amazing what raspberry pi can do these days

lol so electrums update mechanism has a hole in it and retards downloaded compromised wallets from an unsafe location, and so we should exit all crypto markets.... kek.

grandma bertha is gonna put her life saving into bitcorn, the only true fiat in the world exddd.

dud if you torrent a windows and it's got backdoors and other malware in it who do you blame? the inventor of operating systems bill gates or who? not your own stupidity surely.

>You can't have a different file with the same checksum.
of course you can, man that's how hashes work for every hash there is an infinite number of images that produces it.

i feel sorry for you user you point went over their head completely

Why would anyone use anything but the Ethereum foundation wallets?
their stuff seems the most solid out of all. They don't overcomplicate and shit just works.

Best to just use the command line interface to geth.

old news is old

first we kill bitcoin, because all this shit happens with bitcoin
then we get people to move to eth and use mycrypto / local myetherwallet / metamask

>because all this shit happens with bitcoin
two reasons first bitcoin is the only thing that matter, second bitcoin is the only one worth stealing really. you don't have to cash out immediately because it will be around for along time. unlike shitcoins.

People said the same thing about e-commerce back in the early 00s :
>"How is e-commerce ever work with so many scamstore and hackers stealing your debit card"
UX and security systems will just get better, things like Nimiq are already top notch, in 10 years all smartphones will have a hardware wallet too.

>using embedded computers in an industrial application is inferior to something

eXiT aLl CrYpTo MaRkEtS

it's a clever hack on a stupidly designed wallet. this is not the first critical bug found in electrum.

Thank God I use pruned full node.

It's old news at this point and not a hack, retard. You have to manually go to a 2 day old github and install the malware.

But typical zoomer knows two shits about even how to verify github repo age. That's the point. Full node is too heavy to be stored on SSD and light wallets brings shit 'social' features like auto-update, share to facebook, sign in and so on.

>soo we hacked ledger lul, just let me open it and put a 10m wide antenna inside, and then let me hack your computer and allow me to sleep in your basement while I wait for you to send bitcoin, so I can switch the address and force confirm the sending by sending radio beans.

nevermind I though it was about ledger hack

>local myetherwallet
Warming up to the idea of this being the best option - if used on a computer that doesn't have access to the internet

Normies use coinbase, not electrum. Not sure what brand of retard fell for this one, but it’s not normies

> tfw you have your own Bitcoin node and electrum server

That being said, Electrum should have auto update