Post
Topic
Board Electrum
Merits 1 from 1 user
Re: about GPG signature
by
NotATether
on 11/01/2024, 06:41:01 UTC
⭐ Merited by hugeblack (1)
hi surry for the dump question but i wont to know if its possible for a hacker if he did hack electrum.org website and put his fake electrum version
but he kept the original signature file in this case even if you verified the signature file you will lose your btc since the hacker kept the original file
and only changed the electrum.exe file to his fake version

The PGP fingerprint will definitely be different, and the hacker cannot impersonate that, only create a new fingerprint.

Also, if you have you used your own PGP key to trust the original Electrum signing key, then when you try to verify a binary signed by a malicious PGP key then the program will display a warning during verification: "Warning: this key is not trusted" or words to that effect.