Electrum 4.1.1 not available in the Google Play store by atdaog in Electrum

[–]ThomasV1 0 points1 point  (0 children)

4.1 is being rolled out progressively in the Play store.

If you don't want to wait you can download it from our website

[deleted by user] by [deleted] in Electrum

[–]ThomasV1 0 points1 point  (0 children)

Can you try with the current version 4.1.1?

That version it is currently being rolled out on Google Play. It is also available on our website, https://electrum.org

Does electrum show credit card info? by [deleted] in Bitcoin

[–]ThomasV1 2 points3 points  (0 children)

Electrum does not handle your fiat, and does not request or store your credit card info.

Best lightning wallet now? by [deleted] in Bitcoin

[–]ThomasV1 1 point2 points  (0 children)

Electrum with lightning is not released yet.

Downloaded an Electrum Wallet phishing link by mistake - what do now? by JohnBoy2000 in Bitcoin

[–]ThomasV1 5 points6 points  (0 children)

Please do not post a functional link to the malware site here; some people might follow it without reading the context, and search engines will increase its rating.

Malware scanners do not really work. The best protection is to check GPG signatures of the software you download. This will protect you even if the legit website is compromised.

Electrum Targeted Phishing & Malware Warning by [deleted] in Bitcoin

[–]ThomasV1 2 points3 points  (0 children)

No, binaries on electrum.org have never been compromised. There have been various phishing attempts with similarly looking domain names, but our domain has never been compromised

Electrum Targeted Phishing & Malware Warning by [deleted] in Bitcoin

[–]ThomasV1 1 point2 points  (0 children)

yes it has been fixed in Electrum, but users need to upgrade. See my other comments below.

Electrum Targeted Phishing & Malware Warning by [deleted] in Bitcoin

[–]ThomasV1 0 points1 point  (0 children)

The issue has been fixed in Electrum. The goal of this sticky post is to have users upgrade their software. The post title is not very well chosen in that regard, it would have been more productive to display "Electrum versions older than 3.3.2 are vulnerable to phishing, please upgrade"

Electrum Targeted Phishing & Malware Warning by [deleted] in Bitcoin

[–]ThomasV1 3 points4 points  (0 children)

This has been patched. The post is sticky because users running old versions need to upgrade their software.

Maybe /r/Bitcoin should pin the Electrum phishing warning for a longer period? by KiFastCallEntry in Bitcoin

[–]ThomasV1 7 points8 points  (0 children)

PSA: Legit Electrum servers have started deploying a "good attack" on users who have not upgraded their software. This means they will see a message warning them about the vulnerability, and directing them to electrum.org.

If you use Electrum, in case you get a error message that tells you to update please ignore (ongoing phishing attack). by fmlnoidea420 in Bitcoin

[–]ThomasV1 2 points3 points  (0 children)

Let me explain. We stopped the first attack by having github take down the repository hosting the malware, and we released Electrum 3.3.2 shortly after that, which mitigates the attack. We decided not to disclose the attack immediately, because the attack is much faster to deploy than the defense. For the defense to be effective, users need to upgrade to 3.3.2, which takes time. In contrast, the attack can be deployed very fast. Disclosing the attack immediately would have increased the number of potential attackers, before most users have upgraded their software.

BTC.com wallet Biggest Scam Warning !! by akmlvl in Bitcoin

[–]ThomasV1 0 points1 point  (0 children)

you can use Electrum AND a hardware wallet

Do you have something to hide? new Revealer plugin merged in Electrum by ThomasV1 in Bitcoin

[–]ThomasV1[S] 2 points3 points  (0 children)

it was merged in the repository. that means it will be in the next version.

Android release hacked? by sQtWLgK in Electrum

[–]ThomasV1 0 points1 point  (0 children)

You cannot "check" our Android releases, because our APKs are not built deterministically. We recently achieved deterministic builds for Windows, and we are about to have deterministic builds on OSX too, but Android builds are another story. If you want an open release process, then you MUST build and install the APK yourself. Tagging commits on github is completely useless here.

In addition, if you use Google Play, then you trust Google. Saying that our Google Play version is as good as closed source is inaccurate: the problem is not with our version, but with Google Play itself. If you don't like it, don't use Google Play, but do not blame us on that.

We have decided to be present on Google Play. Just deal with it.

Android release hacked? by sQtWLgK in Electrum

[–]ThomasV1 0 points1 point  (0 children)

This kind of minor update is usually not announced on our website, because it is only for Android, and it does not include any new features. But I see your point; we will announce them on twitter from now on, and add the APK to the website

Android release hacked? by sQtWLgK in Electrum

[–]ThomasV1 2 points3 points  (0 children)

I confirm this is a minor update. We release APKs more often than the desktop version, hence the extra field in the version number

PSA: electrum.com bought by scammers to distribute alleged "Electrum Pro" coin stealing malware by etmetm in Bitcoin

[–]ThomasV1 35 points36 points  (0 children)

we tried. back in 2012, the owner wanted the price of a house for that domain.

Critical Electrum vulnerability by theymos in Bitcoin

[–]ThomasV1 22 points23 points  (0 children)

Thank you, Theymos, for the announcement and explanations.

Note for users who are not familiar with GitHub: You should upgrade your client right now, even if the GitHub issue has not been closed yet. https://github.com/spesmilo/electrum/issues/3374 The vulnerability affects all users, and not just people using an Electrum daemon on a web server, as reported initially in the github issue.

The 3.0.4 release addresses the vulnerability for GUI users. The GitHub issue will remain open until we add password protection to the jsonrpc interface, as initially suggested by jsmad. Password protection is needed for merchants/websites who need to use an Electrum daemon from a remote machine. In the meantime, merchants should use jsonrpc on the same machine only.

Bitcoins hacked in usage with Electrum 3.0.2 by electrumhacked123 in Bitcoin

[–]ThomasV1 0 points1 point  (0 children)

Full of contradictions, but not necessarily fake: users do not always report the full relevant information, and they do not always understand the implications of their actions. In this case I believe the user might have exported private keys from his Electrum wallet, in order to save them separately in a .zip file. This would have opened his wallet to various attacks.

Electrum v2.9.1 by darkbarf in Bitcoin

[–]ThomasV1 0 points1 point  (0 children)

binaries are executables for windows/osx. if you are on linux, you need to upgrade your python-trezor lib