📁 A file:// Flaw in Electrum's Payment Protocol
On 7 June 2022, a GitHub advisory disclosed that Electrum 2.1–4.2.1's BIP70 `?r=` parameter accepted `file://` URIs — a malicious QR code could make the client open an arbitrary file as protobuf. On Linux/macOS this enabled DoS via endless sources like `/dev/zero`; on Windows it could trigger an SMB connection leaking credential hashes for offline brute-forcing. Fixed in 4.2.2.
