Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

* Transactions are signed locally: Your private keys are not shared with the server. You do not have to trust the server with your money.

* Freedom and Privacy: The server does not store user accounts. You are not tied to a particular server, and the server does not need to know you.

* No scripts: Electrum does not download any script. A compromised server cannot send you arbitrary code and steal your bitcoins.

* No single point of failure: The server code is open source, anyone can run a server.

https://en.bitcoin.it/wiki/Electrum



Elsewhere on that wiki:

https://en.bitcoin.it/wiki/Thin_Client_Security#Server-Trust...

“All thin clients listed below currently connect to a single server, and are vulnerable to an attack similar to a double-spend. The attack can be run by that single server - the server can just lie to them that they received a Bitcoin transaction, and they, assuming the server does not lie, perform some service, transfer funds or send goods without actually receiving any Bitcoin in exchange.”

Scenario: Bob hacks the server (or colludes with the people operating it). He buys 100 BTC of goods from you, you see the funds in your Electrum client and ship the goods. Surprise! the transaction was fake. You're out 100 BTC.

I'd have more faith in this system if the Electrum website disclosed, very clearly, that this kind of attack is possible and also spelled out exactly who is running the server and why I should trust them. Instead, they appear to be trying to sweep the whole issue under the rug. I therefore see little reason to trust Electrum.


This is a pretty unlikely scenario for a typical use case. The attacker would have to own the electrum server that the victim is connecting to, and orchestrate a fake transaction. Even then, if the person double checks the transaction via a third party like blockchain.info, they would see it's fake.

I think you are over-exaggerating the impact of this vulnerability given the safeguards available to mitigate the attack, such as running your own electrum server or cross checking transactions with a third party.


I guess it depends on the technical savvy of the user and whether “running your own electrum server or cross checking transactions with a third party” is really going to happen.

The project website doesn't advise taking these measures, nor disclose the possibility of this scenario. That's what bugs me the most here.

If their intended user is a knowledgeable Bitcoin hobbyist, who knows how the currency works inside and out, maybe it isn't a big deal, but just speaking personally as a Bitcoin newbie, the lack of disclosure/accountability suggested I stay away.


That's sounds like a very prudent decision to me. I fully agree that this issue should be clarified on the site. I will add it to my community service todo list to email the developer to try and help resolve the issue.

The project is still in its early stages of development, but is already very useful to bitcoin-tech savvy users. The ability to install it on my Android phone and other devices while running my own transaction server is a big plus for me currently.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: