Users report losing Bitcoin in clever hack of Electrum wallets
zdnet.com
zdnet.com
The Electrum Servers (anyone can run one) can check your balance and send bitcoin on your behalf. Thanks to the magic of cryptography, this is all perfectly safe. If you send bitcoin through them, they couldn't redirect it to themselves. The worst they could do is refuse to send it.
Turns out Electrum Servers are allowed to return custom error messages to the client, though. So this guy set up a bunch of these servers and had them always return a message saying "Please update your electrum here: http://github.com/my-hostile-electrum/steal-yo-coins.git". What's worse, because Electrum is using the QT QMessageBox, these errors are displayed with full HTML rendering, making them look even more convincing.
So, crap. Bitcoin is, as they say, a bug bounty on the entire world.
Absolutely unacceptable design not to account for something like that when programming software. There should be an explicit notice of where the message is coming from. I see people blaming users for trusting a new GitHub repository, but the fault rests solely on the contributors to the project responsible for this.
[0] https://user-images.githubusercontent.com/29142493/50359293-...
You'll have to be more specific about the type and quantity of poison.
Complicated security vulnerabilities, I get. It's tough. But just the basic thought to inform someone that a message is not from the Electrum "team" would be nice.
It's unreasonable to expect everyone to read every bit source code of all open (or closed) source software they use.
If I were to use Linux for free, and in this imaginary world all of the sudden I had my banking credentials stolen from a similar lack of care, I think I'd be justifiably upset.
Should the people who lost money be thankful they got to use Electrum in the first place?
Cryptocurrencies are speculative trading vehicles, not money. No one actually lost anything of real value. A fool and his coins are soon parted.
You can debate about the "real value" of Bitcoin or lack thereof, but I'm sure it had "real value" to the people who lost it. If people will pay $5 for Bitcoin, its worth at the time is $5, if $3,000, "real value" is $3,000. But that's besides the point.
Again, I've never really used Bitcoin and don't find it particularly promising, it's not my hill to die on. I do care about an issue like this, though.
It is a growing trend to annotate the readme of an open source repo with a kind of statement of confidence. "This is code I'm not vouching for but want to share because it may be useful to others" and "this is my open source project that I consider to be production ready and will tie my reputation to" are very different things.
This was very obviously the second, so ethical duties involving lying to people for your own benefit and concepts of due diligence clearly come in to play.
And even if this makes no sense in your ethical system, at least be aware that people think that way and will remember your name in these kinds of circumstances even if they have no legal recourse.
For production software I've found it's wise to have a paid vendor to hold accountable (single throat to choke). Paid support is available for most major FOSS packages.
Until then, set expectations explicitly so that people who make different assumptions from you don't get mad at you. It takes 5 minutes to be explicit in your readme.
Somehow everyone else in the world deals with similar issues without the special pleading so common in software. Software isn't that different, despite your wish to be unbound from normal expectations to not cause harm through misleading communication because you are behind a screen.
FAKE link: hxxxs://github.com/electrum-wallet
LEGIT link: https://github.com/spesmilo/electrum
to the second part, I would rephrase that to: it has vulnerabilities related to phishing.
If the code allows it then it isn’t a bug/hack it’s a feature...only in the world of blockchain(s) of course.
Now If I login to my bank app and upon logging in I revealed my login credentials to a third party and my account was subsequently zeroed out...yes I’d call that a hack.
That said, I wouldn't call such a scenario a hack.
Bad design and you still relies on somebody else's computer who can veto your transaction.
People use non-full-node SaaS Wallet because they don't understand the true value of cryptocurrency. If they got veto from the SaaS service they are using. They practically lost their property. A money never used is a lost money.
Also, That's why they manually download the fake update from URL that doesn't belong to the first-party. Because they are dumb enough to use SaaS wallet.
I remember him claiming his dealings with the team were frustrating as well (gist: they didn't understand the problem).
Source: https://blockexplorer.com/news/electrum-releases-update-goog...
This bug is absolutely atrocious: who decided that displaying error messages (with rendered HTML!) from untrusted third-party servers was a good idea?
It's a shame since SPV wallets are a great solution for most users, and Electrum has a relatively nice UI, but after this bug and the JSON-RPC one who will keep using this software?
There is still quite a valley between feasibility of crypto currencies in real world settings, and the current state of affairs.
I would hope that someone who owns 200 BTC would put a little thought into how to secure it and would not be affected by this hack.
This would be the social prudence equivalent of walking around 24/7 with all of your life savings in cash.
It's possible to implement chargebacks on a smart-contract platform, or even at layer 0 as EOS and XRP do. What's so bad about the possibility of marrying the benefits of cash with the convenience of electronic money ?
Why bother replying to comments in threads about cryptocurrency if they don't have any benefit ? Clearly now that cryptocurrency long speculators have pretty much all died, cryptocurrency should just disappear by itself if it doesn't have any use over fiat. Or do you not believe in your own opinion ?
Am I not allowed to post if I think cryptocurrencies are useless?
> Clearly now that cryptocurrency long speculators have pretty much all died, cryptocurrency should just disappear by itself if it doesn't have any use over fiat. Or do you not believe in your own opinion
Why don't you just articulate some of the benefits instead of invoking bloviated sarcasm? The argument that "bitcoin exists so it must be useful" is pretty obviously fallacious logic.
My apologies if you weren't being intentionally disingenuous though, in that case, here's a link with what seems like good answers to your question: https://www.quora.com/What-are-the-advantages-of-Cryptocurre...
Posting a page full of quora answers as your response is not a practical way to have a discussion. If you have a point to make I encourage you to lay it out here so that I can address it, I am not going to spend time constructing a response to a page of quora answers you took 30 seconds looking up on google.
1. Paying for a VPN, VPS, mail, domains or other digital goods.
2. Paying for physical goods. I usually buy via the Swedish sites webhallen and inet for example.
3. Dark net markets.
4. EatBCH charity which give food to Venezuelans.
5. Cam sites accepting Bitcoin. First search result: https://www.bestwebcamsites.com/bitcoin-cam-sites
... And also don't immediately convert it to dirty legacy fiat using a third party service?
* chmuranet.com (VPS focused on torrents but you get root)
* njal.la (domains with privacy focus)
* mullvad.net (VPN)
There are others if you search but I can't vouch for them.
It's just a lack of fake enthusiasm coming from stakeholders in the cryptocurrency community (mostly longs/business owners).
Many people who were wrong about the dot-com bubble still think they were right. Some external agent just screwed them.
People don't tend to change their views about stuff like cryptocurrencies. The best we can expect is a wealth transfer to saner minds.
It's all part of technological maturation.
Computers the size of tennis courts made a lot of sense when those were the fastest, cheapest way of calculating ballistics tables.
This line has been the standard party line in Bitcoin land since time began. Everything about bitcoin is "just around the corner".
All of your talk is a thin veil around the hidden message: "don't sell your Bitcoin or it will crater the value of my stash!" and of course layered under that message is "buy my Bitcoin!!!!".
Again, its been like 10+ years now of 'cryptocurrencies' and its failed to provide a use case apart from 'speculating' and getting yourself uninvited from family Christmas.
Bitcoin is more than 10 years old. That is almost as old as 1st generation iPhones. How much longer do we have to wait to fix these deeply fundamental flaws in the stack?
> It's all part of technological maturation.
An alternative interpretation might be that Bitcoin is fundamentally broken and isn't a useable technology.
A lot of developmental progress in the ecosystem with models/architectures, tools, and infrastructure hasn't happened until recently (past year, give or take).
>For you to center the conversation around those arguments shows you're not very informed on the topic.
The "it's too complicated for you to understand" tact is a tired, overly-used canned response from cryptocurrency evangelists, who seek (intentionally or not) to derail discussions about very real issues.
I've been following Bitcoin for almost its entire life and am probably vastly more informed than most of the shysters who show up on sites like HN to shill their coin.
> A lot of developmental progress in the ecosystem with models/architectures, tools, and infrastructure hasn't happened until recently (past year, give or take).
I've heard this line forever. Lightning network, for example, has been "just around around the corner" since forever. So far, it is still just as "just around the corner" as it was 5 or 6 years ago and ranks among the top all-time vaporware software projects out there.
The attempt to refocus on "The Blockchain" is only done to distract from the fact that Bitcoin, poster child of "The Blockchain" has no lawful use. It doesn't scale, it isn't free, it isn't trustless, it isn't censorship resistant, it isn't a good store of value, it isn't instant and it isn't anonymous. It isn't even deflationary (as if that is a good thing) because it has been forked and cloned thousands of times. Oh yeah, it also requires more energy than small nations to secure. (And don't feed me the line about it being "green energy" or "less than conventional banking"–we both know that is a laugably horseshit argument)
The whole space is a joke. Aside from self-driving cars, Bitcoin will be the biggest overhyped pile of complete nonsense this decade.
The paper was released April 2015. Progress is definitely slower than I'd like, but wanted to correct this claim.
[ Disclaimer: lightning developer and specification guide ]
Who exactly am I cutting out when I'm trading USD-backed currency via a smart contract owned by a company?
I never used any of this, but it really doesn't look to me like it is unreasonable to assume that error messages like this are created by the client, not an untrusted server. Untrusted servers should not be able to inject content like this.
If custom error messages are really needed, you could allow them as a special option while making it obvious through the client UI that this is sent from an untrusted source (field hidden by default, warning displayed when full error message is expanded).
The safest option now is just to consider Electrum as insecure by default. Same with Ethereum's Parity desktop and Metamask. They're convenient for day to day use but don't trust them with big amounts.
EDIT: Seems that's already been discussed in the issue: https://github.com/spesmilo/electrum/issues/4968#issuecommen...
QMessageBox displays text as HTML (formatting, links and all) by default, which I've always thought is a terrible choice.
https://old.reddit.com/r/CryptoCurrency/comments/a9yji3/elec...
> Just to clarify the "hacked" part of the title:
> Technically speaking, even though the term 'hacked' is broad, what happened was an attacker utilized the server response/messaging capability to phish users (it was more convincing because rich text was allowed to display in the electrum client). The message provided a link to "upgrade electrum", but was actually installing a malicious clone.
> The attacker amplified their reach by spinning up more malicious servers which could loosely be considered a sybil attack.
> People using the correct wallet software and not clicking any links are unaffected. Electrum was no more "hacked" than gmail is hacked every time one of their users is sent a phishing email
It is relatively super cheap compared to the value of 1 BTC.
On the other hand, if you're more worried about getting hacked or simply losing your private keys, having your house broken into and the wallet stolen, etc. you're probably better off putting it in Coinbase with a strong password and 2FA enabled. The same way you protect other things you care about like your bank account and 401k.
It's odd to me that this is so highly frowned upon in the cryptocurrency communities though. People with very little knowledge about computers or infosec are constantly pressured into storing their own coins, which is fundamentally pretty user-unfriendly just due to the irreversible nature of it where you can't make a single mistake.
This is not a good idea. There is a big difference between your bank account/401k and crypto. If Coinbase gets hacked, you aren't really getting your crypto back. If your 401k account gets hacked, there is at least some recourse.
Why would cryptocurrencies of all things hold value amidst a collapse of world civilization? In those environments, food, guns and ammunition rule.
While I think a number of Bitcoin maximalists have the former couple scenarios in mind, and agree that their beliefs are illogical, the latter two scenarios are actually much, much more common in recent history. Think of Zimbabwe or Venezuela in the present day, Greece in the financial crisis, Russia after the fall of the Soviet Union in the 1990s, East Germany after the fall of the Berlin Wall, Latin America seemingly every decade since the 1950s, or China during the Cultural Revolution. Bitcoin could've saved lives and fortunes for many of the people affected by these. Indeed, it's held up fairly well for people in Venezuela and Zimbabwe, the two countries to face major currency crises since Bitcoin's invention.
I'm sorry, but do you not see how absurd that sounds? It's a hedge against a particular kind of societal collapse? This is just totally impractical. The reality is that bitcoin traffic in Zimbabwe and Venezuela is extremely miniscule; that's because you can't actually buy much of anything with cryptocurrencies, especially useful goods like food, water, medicine and guns, and trying to convert cryptocurrency into real money is fraught with obstacles and risks (i.e. if you try to do an in-person conversion). Cryptocurrency is not a realistic hedge against any kind of societal disruption.
Apparently some can’t be fixed without new hardware. I can’t watch until later :(
https://fahrplan.events.ccc.de/congress/2018/Fahrplan/events...
Which ones? There have been reports of many getting compromised.
I thought the best way to secure your Bitcoin was to print it out on archival grade paper, encase it in twenty layers of plastic, dig a hole in your backyard and bury it.
Of course, if that got compromised, then it is still your fault because obviously you didn't dig the hole deep enough, or didn't cover it with grass, or you should have gone out into a remote forest and buried it there (I sure hope you left your cell phone off while walking to the location or you might have been tracked!)
Always remember: Bitcoin can never fail, it can only be failed.
decentralize for the sake of it is foolish.
For Not-Banks press number 2 or stay on the line.
The entire point of Bitcoin is decentralization, the rest is growing pains and price of doing business.
It's a tradeoff like anything else. For some people, the risk is worth the benefit. For others it's not. Still more find the risk worth the benefits for a subset of their money, and not for the rest.
All of these "financial systems" can happily coexist, and none of them are completely broken, they just prioritize different things and make different tradeoffs.
Also, bitcoin doesn't require being a lawless land where everyone can do anything all the time. It's like cash, but electronic.
If a thief breaks into your house and steals $10,000 in cash, will the police give you $10,000? If they find the guy and he still has it, sure! But what if he burned it? or spent it? now you are fucked.
It's the same with bitcoin. if they catch the person who did this, the courts can force him to return the money with threat of lots of jail time and more. If he doesn't have it, then the users that had it stolen are fucked.
and now they are caught holding bags
a future which has no real use cases.
I’m pretty sure GP isn’t trying to say that everyone should use Bitcoin. The thing that gets annoying is that there is a crowd that campaigns this, and then other people (particularly in this comment section) fight back saying nobody should use Bitcoin.
The obvious fact which I feel is somehow being overlooked here is that different people have different needs and there is no one-size-fits-all solution to banking today.
As a society, we tend to protect people from themselves because the other option is to let them die on the streets when they lose it all. Making people have insurance and using banks and payment systems that have built-in protection, is far cheaper than providing welfare for those that would otherwise be scammed out of every penny, irreversibly.
You can be a self-serving ubermensch the same day you opt out of all social help.
There absolutely is a choice - you can politically campaign for the right to opt out, or you can go and live in a country that doesn't have the protections you don't want. Most of them are pretty damn awful because they don't look after their citizens at all.
What you don't get to do is live in a society with such protections and social measures and then not play by its rules.
It is hard for me to fully internalize this point when I have a counterexample readily available, albeit one that will do nothing to convince you. I consider myself capable of making sound financial decisions for myself and would never raid my own pension account, unless faced with immediate existential danger (in which case "raiding" it would be a rational decision).
I disagree that the solution to that is to centralize funds in order to let a centralized body inefficiently misallocate (or sometimes outright steal) them and would appreciate the freedom to do this myself. I think the state has too much power and this is detrimental in the long run, as it is detrimental when any single entity has too much power.
> There absolutely is a choice - you can politically campaign for the right to opt out, or you can go and live in a country that doesn't have the protections you don't want.
> What you don't get to do is live in a society with such protections and social measures and then not play by its rules.
I can certainly campaign politically, but that also includes respectfully disagreeing with your conclusion above. This does not make your position right and mine automatically wrong (nor vice versa).
The rest of the quoted part of your post sounds like another non-choice (in that the it is highly impractical), followed by a moral judgement.
Many people do, many of these very same people are not actually competent when it comes down to it, just overconfident, or just have a run of bad luck.
> I disagree that the solution to that is to centralize funds...
Who said anything about centralising or the state? You can invest in pension funds all over the place, with many financial bodies, but you'll find access to these funds restricted in various ways.
> The rest of the quoted part of your post sounds like another non-choice (in that the it is highly impractical)
It's perfectly practical, you can move to all sorts of other nations, take your pick. It's a massive coincidence that the ones that are worth living in have restrictions and protections like these, no?
It's always better to have the option of do-overs.
multisig escrow is a solution that works and a lot of people use for years, requires the service provider have their own resources and capital to fulfill the delivery of goods.
not a solution for everyone, but a solution for many.
Wasn't the DAO rolled back?
The beauty of The DAO was that it wasn't even a hack or an attack. It was merely somebody cleverly exploiting a loophole in the contract everybody agreed to. After all in crypto-utopia "Code Is Law" and there is no interpretation of a contract outside of the code. The irony is the only actual theft that occurred was the ethereum devs rolling back the contract to save their own asses.
The DAO single handedly proved that the blockchain is fully mutable and is certainly not trustless or censorship resistant. Hanging your hat on any blockchain requires you to trust the developers and miners to do you well. And if they don't... good luck getting your voice heard.
With Ethereum it was the core developers / top of the pyramid who stole wealth from the the DAO "hacker" who cleverly found a loophole in the "Code Is Law" contract everybody agreed to and used it to their advantage. The Ethereum devs, coupled with mob rule, clawed back all the transactions and literally stole the funds back.
I'd rather have due process provided by a government than mob rule.
Getting hacked is one worry, I would worry even more about someone with a wrench in my apartment.
You should have shared this link instead of that Reddit thread.
https://www.reddit.com/r/CryptoCurrency/comments/a9yji3/elec...
Please don't break the site guidelines by calling names or being personally rude though: https://news.ycombinator.com/newsguidelines.html. It's enough to offer a better link.
If you use SPV wallets, you have to trust the nodes you connect to. Electrum lets you connect to your own node.