Electrum developers disclosed and patched a critical vulnerability that allowed malicious websites to steal bitcoin from users of the popular wallet. Reports said the flaw affected older versions and could be triggered through website interaction, prompting urgent calls for users to upgrade to a fixed release.
The risk persisted well beyond the initial patch cycle. Later reporting linked an old Electrum weakness to the theft of 1,400 BTC from a user, while newer campaigns targeting Electrum wallets reportedly infected more than 150,000 hosts and stole over $4.6 million. The incidents show that outdated wallet software and continued malware activity remained a significant threat to Electrum users even after the original vulnerability was addressed.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
A user reportedly lost 1,400 BTC due to an old Electrum vulnerability, showing that exploitation of legacy Electrum weaknesses continued years after the original disclosure and patch. The loss was reported in August 2020.
A later report said attacks targeting Electrum wallets were still ongoing, with more than 150,000 hosts infected and over $4.6 million stolen. This marked a major escalation in the scale and persistence of Electrum-related theft activity.
Electrum developers announced that the critical vulnerability had been fixed, addressing the issue that allowed websites to steal funds from affected wallets. Multiple outlets reported the remediation on or around January 8, 2018.
Reports described a critical vulnerability in the Electrum Bitcoin wallet that could allow malicious websites to steal users' bitcoins. The issue was publicly covered in early January 2018 before or alongside the fix becoming widely known.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
itsec.ru
Open sourcebits.media
Open sourceforklog.com
Open sourcebits.media
Open source2bitcoins.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.