Electrum is a well-known light wallet for Bitcoin that adds new features such as server authentication using SSL to prevent MITM attacks. So unlike other Bitcoin light wallets, Electrum cannot communicate directly with different versions of Bitcoin full nodes, and each startup connects to electrumserver to communicate, and electrum.

If the URL entered by the user matches the URL in the webinject destination list, the SSL request is hijacked by the agent, who inserts itself into the communication using its own SSL certificate. After the proxy server receives the request, the SSL connection is established using the proxy server's SSL certificate, after which the request is sent to the destination site and an SSL connection is established between the proxy and the target site. Responses from the target web site are decrypted and then encrypted using the agent's certificate and sent to the victim, while traffic is decrypted by the agent's certificate. The state SSL context data structure used to maintain SSL traffic is similar to Figure 1.

Electrum is another popular Bitcoin wallet that has been around for nearly a decade. Electrum Bitcoin Wallet has been available for all devices since 2011 and was one of the most widely used wallet applications before other alternatives emerged. There are still a lot of people who are still swearing at the Electrum wallet.

Users of Bitcoin wallet Electrum are facing phishing attacks, according to Hackers broadcast messages to the Electrum client through a malicious server, prompting the user to update to v4.0.0, and if the user follows the prompt to install this "backdoor-carrying client", the private key is stolen and all digital assets are stolen. At the time of writing, at least 1,450 BTCs worth about $11.6 million had been stolen from phishing attacks that faked Electrum upgrade tips. DeViable Security Labs hereby suggests that versions of Electrum below 3.3.4 are vulnerable to such phishing attacks, and users using Electrum Wallet are requested to update to the latest version of Electrum 3.3.8 via the official website (, which has not yet been officially released, and do not use the link in the prompt to avoid asset losses.