/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Bitcoin wallet app Electrum had a critical flaw for two years that would let attackers remotely steal bitcoins; flaw went unpatched for weeks after discovery

Developers left the vulnerability unpatched for months after being alerted.  —  For almost two years, hackers could have easily stolen …

Motherboard Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

Electrum's problem wasn't just the bug itself but the response: a remote-theft vulnerability lived in the wallet for almost two years, and developers sat on the fix for weeks after being alerted. The related coverage shows this wasn't an isolated lapse — a year later Electrum was hit by a DoS campaign steering users toward backdoored downloads, meaning attackers kept working the wallet from new angles even after the code hole closed.

The wider arc matters too: Bitcoin Core, the network's most popular client, patched its own serious flaw that year only for researchers to surface a second bug that could have minted bitcoins past the 21M cap, and by 2020 researchers found double-spending flaws in major wallets like Ledger Live, Edge, and Breadwallet. Electrum is one data point in a recurring pattern of long-lived, critical defects in self-custody wallet software.

First-order effects

  • Every Electrum user running an unpatched version during those two years was exposed to remote theft of their holdings, with no action required on their part beyond using the app.
  • Because developers delayed the fix for weeks after disclosure, the public alert widened rather than shrank the attack window — anyone holding funds in Electrum at that moment faced elevated risk.

Second-order effects

  • With the direct exploit eventually patched, attacker effort shifted to social engineering — the later DoS-plus-backdoored-download campaign against Electrum shows adversaries pivoting from code exploits to tricking users into installing malicious versions.
  • Each high-profile wallet defect raises the bar for competitors: vendors like Ledger, Edge, and Breadwallet ended up under researcher scrutiny themselves, making audit depth and patch speed a differentiator in wallet selection.

Third-order effects

  • If the pattern holds — Electrum, Bitcoin Core, and multiple consumer wallets all carrying critical flaws for extended periods — self-custody wallet software will face structural pressure toward formal audits, faster disclosure-to-patch cycles, and possibly third-party verification of releases.
  • Repeated near-misses at the client layer strengthen the case among institutions and regulators that wallet software is critical financial infrastructure, not hobbyist tooling, raising the compliance cost of shipping it casually.

The trend: Self-custody crypto wallet software keeps shipping long-lived critical vulnerabilities, and the gap between disclosure and patch is becoming the defining risk in Bitcoin's client ecosystem.

Discussion

  • @taviso Tavis Ormandy on x
    The bitcoin wallet Electrum allows any website to steal your bitcoins. I was gonna report it...but there was already an open issue from last year. I pointed out this is kinda critical, and they made a new release within a few hours. Update to 3.0.4 if you use it.