On April 9th Electrum, the Bitcoin wallet service, was hacked, resulting in the loss of user funds. In response to the attack, Beosin Chengdu Chain Security made an analysis: This wallet Electrum was attacked, mainly because the use of the kivy framework is using a standard py compiler and wallet does not do anti-secondary packaging protection, the core file can be directly recompiled back to the py file. Attackers can imitate the code, directly join the code to steal the user's password, key after the secondary packaging, and then cooperate with other attacks, tempt users to install the wallet implanted with malicious code, thereby stealing the user's password, key and other sensitive information.

We'll open the envelope and log in with the information provided in the envelope. Then we will check the balance, scan the wallet, install ELECTRUM on LEDGER BLUE, encrypt the wallet with multiple signatures, scan the BLOCKCHAIN.INFO wallet with ELECTRUM, and then slowly transfer the money to the buyer... By displaying a sample of the account balance or proof of bank balance that the amount is equivalent to Bitcoin at the PRICECHAIN.INFO price... If a non-disclosure agreement is required and also signed by a delegate, the seller is only willing to sign contracts and transactions.

Nor will the proof-of-interest system be as simple as such a simple explanation. If 1000 bitcoins are in circulation, but only 100 bitcoins are stored, a cyber attacker would only need 101 bitcoins to carry out an attack. Now imagine if there were only two bitcoins stored - ah.

According to the dimensionality reduction security laboratory (, hackers launched a denial of service (DoS) attack on the well-known wallet Electrum server. The hackers used a botnet of more than 140,000 computers to attack Electrum nodes and deployed malicious nodes at the same time . When users connect to these malicious nodes and use the old version of Electrum to send transactions

Therefore, the first thing to do when entering MpBootDriverCallback is to perform integrity checks on Argument1 and Argument2. For Argument2, it checks whether it equals 0x28, and for Argument1, it checks whether the magic of the structure is 0xEB01. If both checks are correct, it continues to traverse the list of drivers created by WdBoot, and for each driver, it calls MpCopyDriverEntry, which copies the driver entry data into the MP_DRIVER_INFO structure and then links it to the MP_DRIVERS_INFO-LoadedDriversList.

The Healthy Security Lab is concerned that Nearly 250 bitcoins have been stolen in a recent hacking attack on an Electrum wallet. This attack, confirmed by Electrum, involves creating a fake version of the wallet to trick users into providing password information. Electrum responded on Twitter that "this is an ongoing phishing attack on Electrum users and advised users to download wallet apps from the official website" and that The Healthy Security Lab advised users not to install an unknown source of Electrum wallets to avoid being tricked.