Users of Bitcoin wallet Electrum are facing a phishing attack, according to the Devi Security Lab. Hackers broadcast messages to the Electrum client through a malicious server, prompting the user to update to v4.0.0, and if the user follows the prompt to install this "backdoor-carrying client", the private key is stolen and all digital assets are stolen. At the time of writing, at least 1,450 BTCs worth about $11.6 million had been stolen from phishing attacks that faked Electrum upgrade tips. DeViable Security Labs hereby suggests that versions of Electrum below 3.3.4 are vulnerable to such phishing attacks, and users using Electrum Wallet are requested to update to the latest version of Electrum 3.3.8 via the official website (, which has not yet been officially released, and do not use the link in the prompt to avoid asset losses.

To prevent this, it is more secure to sweep your private key into a new public address in your newly created wallet. This requires creating a transaction that emptys the balance of the old wallet and then sending the funds to the new private/public key pair that you know only. Most unmanaged wallets, including Ledger, Trezor, Exodus, Electrum, Samourai, and Metamask, let you clean your wallet, drain your wallet and summarize your balance into a new wallet.

If you protect seed words with a password when creating a seed, click "Use seed phrase (optional)" and enter your mnprint password here (unlike the password in your wallet)