He later updated his post, adding: "If you don't set your wallet password, theft is trivial." If your wallet password is set well, the attacker seems to be able to get address transaction information only from your wallet and change your Electrum settings, which seem to have a high level of further utilization for me. So if you set your wallet password, you can reduce your panic, but you should still take this seriously. "

Users of Bitcoin wallet Electrum are facing a phishing attack, according to the Devi Security Lab. Hackers broadcast messages to the Electrum client through a malicious server, prompting the user to update to v4.0.0, and if the user follows the prompt to install this "backdoor-carrying client", the private key is stolen and all digital assets are stolen. At the time of writing, at least 1,450 BTCs worth about $11.6 million had been stolen from phishing attacks that faked Electrum upgrade tips. DeViable Security Labs hereby suggests that versions of Electrum below 3.3.4 are vulnerable to such phishing attacks, and users using Electrum Wallet are requested to update to the latest version of Electrum 3.3.8 via the official website (, which has not yet been officially released, and do not use the link in the prompt to avoid asset losses.

It turns out that the FTP account password used to upload local user information, with a normal Electrum Installer file, is used once the user installs it, and sensitive information entered under Electrum is sent to a remote malicious FTP server for reception.

Verus Desktop Wallet is the first GUI application to support the Verus ID protocol, as well as a full-node wallet for KMD ecosystem tokens, based on BTC's Electrum server and Ethereum/ERC20 tokens. The wallet also includes an intuitive mining/pledge interface that displays estimated revenue forecasts as well as private transactions/messages.