All About Lightning Electrum
Google researcher Tavis Ormandy discovered the Bitcoin wallet Electrum.
According to GitHub, Bitcoin Desktop Wallet client Electrum has released a 4.0 beta version, adding several important updates that support lightning networks. Electrum primarily adds features such as PSBT (partially signed Bitcoin transactions), Lightning Network, watchtowers (暸 watchtowers), and Submarine Swaps (subliminal switching).
From August to September, the Bitcoin wallet Electrum was phished twice by hackers. According to statistics from various parties, the phishing attacks forged Electrum upgrade notifications have stolen at least 1,450 BTC worth $11.6 million.
The main reason for the Trezor vulnerability is that it does not have built-in multi-signature functionality, so its multi-signature implementation is to support Electrum extensions. This leads to an attack on Electrum, and Trezor is affected.
According to news on Reddit on December 27th, Electrum's wallet was hacked and nearly 250 bitcoins ($937,000) were maliciously stolen, coinelegraph reported. Electrum later confirmed that the attack included creating a fake version of the wallet and tricking users into providing password information. Reddit user u/ normal_rc that hackers set up a large number of malicious servers. Electrum responded on Twitter today that "this is a persistent phishing attack against Electrum users" and implored users to check the effectiveness of the resources they log on to.
In the end, you've completed your first transaction with the Electrum Wallet.
DeViable Security Labs hereby suggests that versions of Electrum below 3.3.4 are vulnerable to such phishing attacks, and users using Electrum Wallet are requested to update to the latest version of Electrum 3.3.8 via the official website (electrum.org), which has not yet been officially released, and do not use the link in the prompt to avoid asset losses.