electrum must verify itself. If do that from the first version we dont have these problems
Electrum has a signed update announcement mechanism since v3.3.3. It was introduced in this commit:
https://github.com/spesmilo/electrum/commit/0bfda7c8c74757d261bbc7e24eee44fa09965e85You should still verify downloaded binaries using GPG, of course. And only get your binaries from electrum.org. Type it yourself, do not copy-paste, do not click links.