Complicated security vulnerabilities, I get. It's tough. But just the basic thought to inform someone that a message is not from the Electrum "team" would be nice.
It's unreasonable to expect everyone to read every bit source code of all open (or closed) source software they use.
If I were to use Linux for free, and in this imaginary world all of the sudden I had my banking credentials stolen from a similar lack of care, I think I'd be justifiably upset.
Should the people who lost money be thankful they got to use Electrum in the first place?
Cryptocurrencies are speculative trading vehicles, not money. No one actually lost anything of real value. A fool and his coins are soon parted.
You can debate about the "real value" of Bitcoin or lack thereof, but I'm sure it had "real value" to the people who lost it. If people will pay $5 for Bitcoin, its worth at the time is $5, if $3,000, "real value" is $3,000. But that's besides the point.
Again, I've never really used Bitcoin and don't find it particularly promising, it's not my hill to die on. I do care about an issue like this, though.
You'll have to be more specific about the type and quantity of poison.
It is a growing trend to annotate the readme of an open source repo with a kind of statement of confidence. "This is code I'm not vouching for but want to share because it may be useful to others" and "this is my open source project that I consider to be production ready and will tie my reputation to" are very different things.
This was very obviously the second, so ethical duties involving lying to people for your own benefit and concepts of due diligence clearly come in to play.
And even if this makes no sense in your ethical system, at least be aware that people think that way and will remember your name in these kinds of circumstances even if they have no legal recourse.
For production software I've found it's wise to have a paid vendor to hold accountable (single throat to choke). Paid support is available for most major FOSS packages.
Until then, set expectations explicitly so that people who make different assumptions from you don't get mad at you. It takes 5 minutes to be explicit in your readme.
Somehow everyone else in the world deals with similar issues without the special pleading so common in software. Software isn't that different, despite your wish to be unbound from normal expectations to not cause harm through misleading communication because you are behind a screen.