How do you ensure that you properly export the administrator private key into the environment variable? Executing the echo $FORGE, moderator-SK, indicates that the configuration is correct if the result output is the same as the private key you generated.

Therefore, users should not export chain codes and private keys to untrustworthy environments. Of course, this risk can be avoided by strengthening the layered determination key reasoning algorithm. The process of the common sub-private key inference and strengthening the sub-private key inference is shown in the figure.

The main reason for the Trezor vulnerability is that it does not have built-in multi-signature functionality, so its multi-signature implementation is to support Electrum extension. This led to an attack on electrum, and Trezor was affected.

DeViable Security Labs hereby suggests that versions of Electrum below 3.3.4 are vulnerable to such phishing attacks, and users using Electrum Wallet are requested to update to the latest version of Electrum 3.3.8 via the official website (, which has not yet been officially released, and do not use the link in the prompt to avoid asset losses.

Therefore, the use of multi-signature wallets provides additional security. In the Bitcoin ecosystem, it is easy to put them in an Electrum wallet. Multi-signature wallets require confirmation of several private keys in order to sign a transaction.

Electrum is a world-renowned Bitcoin light wallet with a long history of multi-signature support and a very broad user base, many of which like to use Electrum as a cold wallet or multi-signature wallet for Bitcoin or even USDT (Omni). Based on this usage scenario, Electrum is used less frequently on the user's computer. The current version of Electrum is 3.3.8, and previous versions of 3.3.4 are known to have a message flaw that allows an attacker to send update prompts through a malicious ElectrumX server. This update prompt is very confusing for the user, and if you follow the prompt to download the so-called new version of Electrum, you may be tricked. According to user feedback, because of this attack, stolen bitcoins are in the four digits or more. This captured currency theft attack is not stealing the private key (electrum's private key is generally stored with two-factor encryption), but replaces the transfer destination address when the user initiates the transfer. Slow fog reminds users that when transferring money, special attention needs to be paid to whether the destination address is replaced, which is a very popular method of currency theft recently. It is also recommended that users use hardware wallets such as Ledger, and if you pair it with Electrum, although the private key does not have any security issues, you should also be alert to the replacement of the destination address.

how to find electrum seed on 2fa account, Enable 2FA on domain Admin account updates the EOSIOTools feature article on the WebAuthn sample application to show developers how to integrate WebAuthn in a project to facilitate two-factor authentication (2FA) using devices such as YubiKey when signing a transaction. The article describes why WebAuthn 2FA is used and how it works. It also says EOSIO's support for WebAuthn is a step forward for more secure/seamless authentication for blockchain applications. (MEET.ONE Report)

Like Bitcoin's core wallet, Electrum Wallet allows users to control their own funds and private keys. Electrum wallets' private keys can also be exported and used on other supported wallets to access funds. Electrum apps are available for Windows, Linux, OSX and Android, but do not support iOS and browser clients.