On December 27, Reddit user u/normal_rc reported that Electrum's wallet had been hacked and that nearly 250 bitcoins (243.6 BTCs, nearly $1 million) had been maliciously stolen, coinelegraph reported. Electrum then confirmed that the attack included creating a fake version of the wallet to trick users into providing password information. Electrum responded on Twitter that "this is a persistent phishing attack on Electrum users" and warned users not to download Electrum from any source other than the official website.

Attacking the Electrum client user (mobile side) requires the user to actively connect to a malicious lightning network node, and the attacker uses the correct scriptpubkey, which burns the coin in the funding output. Because Eclair's mobile client does not relay payments, an attacker cannot make a withdrawal without offband interactions (for example, selling something to a user and those using funds in a fake channel).

Electrum users are reminded of the Update Tip, which indicates that the new version of Electrum is likely to be fake, and if installed, transfer Bitcoin out in another security environment in a timely manner.