According to the slow fog zone, the Phishing attack by Electrum forged upgrade tips has stolen at least 200 BTCs, and this attack cannot be avoided by upgrading Electrum alone, requiring the entire ecological service to make corresponding changes (because Electrum is not a full node, and then on the transaction broadcast and the corresponding server has a message communication, the attacker can also deploy a malicious server)

At the time of writing, at least 1,450 BTCs worth about $11.6 million had been stolen from phishing attacks that faked Electrum upgrade tips. DeViable Security Labs hereby suggests that versions of Electrum below 3.3.4 are vulnerable to such phishing attacks, and users using Electrum Wallet are requested to update to the latest version of Electrum 3.3.8 via the official website (electrum.org), which has not yet been officially released, and do not use the link in the prompt to avoid asset losses.

(nonce, receiving_address, value, dataitem0, dataitem1... Dataitemn, v,r,s?nonce is the number of transactions that the address has sent, encoded in binary format (e.g., 0 -'', 7 'x07', 1000 -'x03'xd8'). (v,r,s) is a newly generated Electrum-style transaction signature without the private key corresponding to the sending address, and the range of v is 27 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . The public key and address can be extracted directly from an Electrum-style signature (65 bytes). The conditions under which the transaction is legal.

Public Electrum server

Thomas Voegtlin, founder of electrum, a cryptocurrencies wallet service, said he plans to increase support for Bitcoin Lightning online trading technology by the end of July. He said the transaction would be conducted by electrum servers interacting with the Bitcoin network, rather than integrating with other Lightning network clients. Lightning Network is a Layer 2 expansion technology under development with the goal of faster payments, lower fees, and higher transaction throughput than bitcoin networks, and several Lightning network projects are currently developing iterations.

Electrum hackers pre-empted a large number of "normal" electrum servers on the P2P network.

In recent days, hackers or hacker groups have stolen more than 200 bitcoins worth about $750,000 by attacking the infrastructure of electrum Bitcoin wallets. The attacker is targeting Electrum.

As mentioned earlier, because electrum light wallets are different from Bitcoin light wallets such as MultiBit or Breadwallet, they cannot communicate directly with bitcoin full nodes and can only communicate with electrum.

The Electrum team has also been developing other features. Electrum Wallet users can view the full release notes here.

In a forum post on Bitcointalk, website administrator Theymos explained: "If at any time in the past you've logged in to Electrum without a wallet password and opened a web page, your wallet might have been stolen." Particularly paranoid people may want to send all bitcoins (BTCs) from their old Electrum wallets to the newly generated Electrum wallet. "

Hot Wallet's transaction data "Load More" feature and "Page Load" feature are added.

Electrum personal server

Dash Electrum was released, renamed Dash-Electrum, adding the option to use Tor Proxy at startup, according to Dash Coin. DASH is now trading at $159, down 3.26 percent.

Bitcoin wallet Electrum now supports Lightning online payments, according to Coindesk on July 11. It has previously been reported that Bitcoin Wallet Electrum has released a beta version of Electrum 4.0, adding support for the Bitcoin Lightning Network.

It is reported that malicious websites (electrumsecure) fake Electrum website phishing attacks, to guide users to download and use the wallet, in order to steal the user's private key and other sensitive data. Users are reminded not to install electrum wallets from unknown sources at will to avoid asset losses.

The Electrum team has announced the attack in an official tweet, saying that "this is an ongoing phishing attack on Electrum users" and reminding them to check the authenticity of the client's source before logging in. The team published its official website, and the Electrum clients downloaded elsewhere may be problematic.

If the transaction is to create a smart contract, then the load is the EVM code that created the smart contract If the transaction is to call the function of the smart contract, then the load is the input data that executes the message if the transaction is simply transferred between two accounts, then the load is empty.

Each license node, Endorsing Peer, verifies the identity and authorization of the user from the proposed load. If the validation check passes, Endorsing Peer will simulate the transaction. Private read and write set Privat from the simulation results.

Golden Morning News . . . U.S. Department of Defense: Blockchain has "enormous" potential to improve disaster relief Electrum wallets were stolen from nearly 250 bitcoins.

