I Just Lost 1,400 BTC (2020)
github.com
github.com
This issue has been fixed in Electrum a long time ago already. However the problem is that no one can prevent people from running older versions.
This kind of problems are to be expected in crypto in the future as well, so always stay cautious.
Man 2: Right now we're proving we don't need corporations. We don't need money. This can become a commune where everyone just helps each other.
Man 1: Yeah, we'll have one guy who like, who like, makes bread. A-and one guy who like, l-looks out for other people's safety.
Stan: You mean like a baker and a cop?
Man 2: No no, can't you imagine a place where people live together and like, provide services for each other in exchange for their services?
Kyle: Yeah, it's called a town.
However, isn't it kind of pessimistic to think that there's nothing new to learn from rebuilding existing institutions from the ground up based on new knowledge?
I'm by no mean a crypto apologist. I think it's important to discuss why those new ideas fail and what we can learn from them in the future rather than mock them for trying to reinvent the wheel.
New things fix some old problems, but also introduce new ones that we hadn't before. The value of solving the old problems is greater than the total cost of the new problems, why we stay with new things even when they add problems to our lives.
(We're probably not lucky)
It's pretty crazy the number of people who bought Bitcoin/crypto at such an early stage (e.g spending >$1000 on something nearly worthless and very obscure) yet are very bad at the security of this. You would think the first step to recovering >$10M plus would involve a Google search or two.
i.e. perhaps a trend is people are so terrified of anyone finding out about it that they avoid Google etc and do everything in secret.
Reading some of these it is not that much different to someone winning in the lottery or getting some making million-level exit from IT business.
Though $1000 is a money typical let's say IT employee can easily spend and lose without having major issues. The issue with some early BTC adopters is that it was like buying a lottery ticket, most probably assumed that they would be likely losing the money, therefore they didn't invest in security and careful planning. Many people working for FAANG for example don't have to work that long to make $1000, so it is quite natural not to spend several hours of r&d on $1000 investment.
I think the main issue in this vulnerability was only fixed in early 2019 so it is super recent compared to the value & state of cryptocurrenty. Even I would expect any crypt wallet software from 2018 to be secure because crypto was no longer a niche interest at that point. Sure regular security & bug fixes are a norm for modern software but having such an egregious issue as recent as late 2018 is unacceptable.
> Warning: Electrum versions older than 3.3.4 are susceptible to phishing (links to [0])
3.3.4 was released 2019-02-13 [1]
[0] https://github.com/spesmilo/electrum/issues/4968
[1] https://github.com/spesmilo/electrum/releases?after=3.3.6
Looks like this guy installed an old and vulnerable version.
Electrum has a history of severe security bugs. If you want to store crypto safely, I recommend a Trezor hardware wallet. If you want crypto exposure in your portfolio without the technical/security headaches, I recommend Grayscale's investment products. GBTC, for example, is backed by Bitcoin and you can buy it through any investment account.
The problem is though that the BTC will still be traced to you...
Perhaps a start would be not to keep more than, say, a fifth of your cryptocurrency in a single place if you have many millions' worth?
It may have some utility as an asset class but the crypto fan boys seem to ignore that it is largely incompatible with our current financial and legal system.
I’ll happily agree with anyone that Bitcoin is an interesting and novel invention but I fail to see how it does anything useful for me other than as a speculative investment.
Now that crypto markets are a parody of wildcat banks in the 1800s I won’t even touch it with a 10 foot pole.
Edit: I found it amusing when the cafe closed a year later presumably because both owners retired after selling at the peak in early 2018.
If I have to pay for breakfast I’d rather use a credit card app on my phone that has a dispute process and gives me a % cash back.
In Canada those breakfasts would technically be taxable capital gains, which means calculating the adjusted cost basis based on mining input costs and then half of that taxable gain is added to your annual income.
There is just no real incentive to use crypto unless you’re buying something questionable on the internet.
That said, crypto loss is very preventable. Lots of people have put lots of effort to make holding bitcoin/crypto more secure.
“Well, you know, sometimes you die”… doesn’t seem like good investment or fiat currency plan.
Better analogy would be "it is not worth living because you might die"
Typically you can safely work with an independent financial advisor as your money is stored with a custodian like fidelity. Fidelity is on the hook to make basic tax reports, account statements, and provide security for your funds. Obviously a part of that security is controlling transfers and not dealing with dubious business partners.
I can’t point to any vault where my money is stored, but I can reasonably bet that fidelity has enough safeguards that it won’t vanish. I wish there were more such custodians for btc assets providing “cold wallets”. BTC makes audits and other activities to verify nothings gone odd with the custodian for your and everyone else’s accounts without requiring privileged access to the ledger.
Paying .05% for the price large of not having your btc vanish is a bargain.
Have to note that when there are millions or maybe hundred of millions of people with crypto wallets, there will be also some amount of "false positives" reporting lost BTC, for example people who have sent their BTC to wrong address drunk or high, and then afterwards think that its the platforms fault.
In this case don't use cryptocurrencies, or at least don't hold your own coins and delegate that to a third-party (keep them in an exchange, etc).
Keeping your coins in a self-hosted wallet is like handling millions in physical cash or precious metals. You can do it, but it requires responsibility and precautions, which is why in the real world it's typically delegated to financial institutions (as in you keep that cash in the bank) and they themselves use precautions such as moving physical cash in armored trucks.
With this kind of amount, you need to take the appropriate precautions and have (or build) a digital "armored truck" and definitely not keep them on an online machine. Use a hardware wallet at the very least, or "build your own" hardware wallet by using an air-gapped machine with no direct access to the internet.
Definitely not. I'm sure that for someone who has middle-level skills at basic IT and basic understanding of cryptocurrencies, safe storage and handling of cryptocurrencies is 10x safer than handling the same amount of physical cash or gold at home. Considering also that you want to use your assets.
If I were routinely transfering tens of thousands worth of cash from my home to somewhere to spend it would surely catch some attention, I would guess. With crypto I can just use it from safety of my own home at online shops and similar.
Your choice as to whether you entrust your assets to a scheme like that. I prefer something solid like real physical assets that I can hold or touch and that doesn't rely on a source of energy for its existence.
On top of all this around the same time I was trying to access some small amount of bitcoin in an older electrum wallet. It was no longer supported so I would have been forced to upgrade while there was this trojan variant going around.
Any way what the lesson should be is when writing security critical software do it right the first time, don't force users to upgrade frequently, don't allow messages from anybody to be broadcast to users, don't break existing secure installations forcing users to upgrade unnecessarily. Keep it simple and secure. KISS.
Safely done by downloading a new version from the official website (which wasn't compromised) + verifying its signature.
I agree that allowing nodes to pop up messages was a huge error.
What keeps hackers from taking over someones phone and sending their dollar/euro holdings somewhere?
If you try and move large amounts of money via your mobile banking app you won’t get very far before you have to show up in person at a branch.
My bank requires in-person to send a wire transfer, meaning in person identification at a bank branch with photo ID and PIN.
You can only transfer money on the app within your own accounts or to payees that are in the system (e.g your utility company, insurance company, etc.) or by using interac e-transfers with a limit of ~$1500.
Even if you’re trying to pay your taxes to the Canada Revenue Agency the bill payment system has a limit that I have hit. You can bet that a review process is triggered when that happens as well.
Any deposit of >$10000 from a wire transfer usually triggers a phone call as well where someone will politely ask you if you were expecting the transfer.
Two specific design decisions of crypto - irreversibility and pseudonymity - make this much harder for crypto.
- Banks limit the amount per single transaction
- Limit on total daily amount one can transfer
- If a limit has to be exceeded for a large purchase they have a 24/7 hotline to authenticate and authorise such a one off transaction
- Additional checks on source of funds when someone pays in a lot of money
- Need for multiple extra factors of authentication when making a transfer to a new payee
- Extra checks including money laundering checks when making transfers abroad
- … and much more
If your bank's app has a vulnerability that you lose money through, they bank will probably compensate you out of their own pocket even if they can't reverse the transaction.