According to Bleeping Computer, the Bitcoin wallet app Electrom was on GitHub on May 9th, accusing a phishing product called Electrum Pro of stealing a user's seed key and registering a domain name called electrum without Electrum's permission. The Electrum team noted that there was a piece of code indicating that the counterfeit product might have taken the user's seed key and uploaded it to the electrum. Affected users should transfer funds from Bitcoin URLs managed by Eletrum Pro.

Next, I tested the "forgot password" feature on the login page, and after some analysis, I found that the "forgotten password" did not deploy a rate limit, so can we use this to make a violent enumeration of other people's account passwords?

Electrum is a well-known light wallet for Bitcoin that adds new features such as server authentication using SSL to prevent MITM attacks. So unlike other Bitcoin light wallets, Electrum cannot communicate directly with different versions of Bitcoin full nodes, and each startup connects to electrumserver to communicate, and electrum.

According to, we will continue to monitor and track further movement of funds after a recent user submitted a coin-losing incident claiming that the download used electrum wallets had been phishing attacks, losing more than 700 bitcoins, and that the stolen address had been added to the Devi AML system. It is reported that malicious website (electrumsecure) fake Electrum website phishing attacks, to guide users to download the wallet, in order to steal the user's private key and other sensitive data. De-dimensional Security Labs hereby reminds users not to install electrum wallets from unknown sources at will to avoid asset losses. Electrum Official Website: electrum.orgElectrum Phishing Website: electrumsecure.

In addition, small partners who have used Electrum wallets should be aware that with Thecret phrase generated by Electrum, we can recover bitcoin keys on any browser using the Bitcoin Wallet web tool. And Electrum is so secure that there is no evidence that the distributed attack prevention system designed by Dark Wallet will be due to Electrum.

How do I use this pair of keys to send information? Suppose the Star of Guardians of the Galaxy wants to send Grout a message saying, "Hello, Grout, but make sure that the super-big counter-bully can't read this message?" We can have Grut create a pair of keys, hand over the public key to the star, and keep the private key himself. The star can encrypt the information with the public key, the encrypted information looks like nonsense, only Grut decrypted with the private key to know exactly what the star said.

At the time of writing, at least 1,450 BTCs worth about $11.6 million had been stolen from phishing attacks that faked Electrum upgrade tips. DeViable Security Labs hereby suggests that versions of Electrum below 3.3.4 are vulnerable to such phishing attacks, and users using Electrum Wallet are requested to update to the latest version of Electrum 3.3.8 via the official website (, which has not yet been officially released, and do not use the link in the prompt to avoid asset losses.