Bitpay’s Copay Wallet Has Been Compromised

- Advertisement -

November 28, 2018 12:15 AM

The vulnerability only affects certain versions of the Copay wallet.

BitPay’s Copay wallet has been comprised, according to a November 26 announcement from the company, by malware that can potentially access private keys and be used to steal digital currency.

The malicious code appears to have first been identified last week on GitHub, although BitPay seems to have only become aware of the vulnerability after a separate GitHub issue was published yesterday, November 26.

- Advertisement -

According to the press release, JavaScript code used by both Copay and BitPay applications was modified to load the malware. The malicious code was installed on the 5.0.2 through 5.1.0 versions of BitPay’s Copay wallet. The BitPay smartphone app is not affected, and BitPay is still investigating to find out if any individual user accounts were compromised.

In the meantime, BitPay is urging its customers using the infected versions of the Copay wallet to not open the app and to assume their private keys have been compromised.

BitPay says it has released a security update, Copay wallet version 5.2.0, which will be accessible to all Copay and BitPay customers. The company is cautioning users to first update their wallet to the more secure 5.2.0 version before inputting their 12-word backup phrases because these phrases correspond to private keys that may have been compromised. Once their wallets have been updated, users should move their funds from affected wallets to the updated version.

Nathan Graham is a full-time staff writer for ETHNews. He lives in Sparks, Nevada, with his wife, Beth, and dog, Kyia. Nathan has a passion for new technology, grant writing, and short stories. He spends his time rafting the American River, playing video games, and writing.

Like what you read? Follow us on X @Bitnewsbot to receive the latest BitPay, Copay or other Ethereum wallets and exchanges news.



Previous Articles:

- Advertisement -

Latest News

Bitcoin Demand Surges As Price Nears One-Year Low

Global Google searches for "buy Bitcoin" have hit a five-year peak, a historic signal...

AI models escalate to nukes in 95% of war games

AI models from OpenAI, Anthropic, and Google deployed nuclear weapons in 95% of war-game...

Nvidia Projects $78 Billion Revenue, Topping Estimates

NVIDIA's Q4 revenue surged 73% year-on-year to $68.1 billion, significantly surpassing analyst expectations.The company's...

Kraken Launches Flexline Crypto-Backed Loans

Kraken has launched Flexline, a crypto-backed loan service for its Pro users, offering fixed-rate...

Critical Flaws Found in Anthropic’s Claude Code AI

Researchers at Check Point disclosed critical vulnerabilities in Anthropic's Claude Code AI assistant.The flaws,...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!