Bitpay’s Copay Wallet Has Been Compromised

- Advertisement -

November 28, 2018 12:15 AM

The vulnerability only affects certain versions of the Copay wallet.

BitPay’s Copay wallet has been comprised, according to a November 26 announcement from the company, by malware that can potentially access private keys and be used to steal digital currency.

The malicious code appears to have first been identified last week on GitHub, although BitPay seems to have only become aware of the vulnerability after a separate GitHub issue was published yesterday, November 26.

According to the press release, JavaScript code used by both Copay and BitPay applications was modified to load the malware. The malicious code was installed on the 5.0.2 through 5.1.0 versions of BitPay’s Copay wallet. The BitPay smartphone app is not affected, and BitPay is still investigating to find out if any individual user accounts were compromised.

In the meantime, BitPay is urging its customers using the infected versions of the Copay wallet to not open the app and to assume their private keys have been compromised.

- Advertisement -

BitPay says it has released a security update, Copay wallet version 5.2.0, which will be accessible to all Copay and BitPay customers. The company is cautioning users to first update their wallet to the more secure 5.2.0 version before inputting their 12-word backup phrases because these phrases correspond to private keys that may have been compromised. Once their wallets have been updated, users should move their funds from affected wallets to the updated version.

Nathan Graham is a full-time staff writer for ETHNews. He lives in Sparks, Nevada, with his wife, Beth, and dog, Kyia. Nathan has a passion for new technology, grant writing, and short stories. He spends his time rafting the American River, playing video games, and writing.

Like what you read? Follow us on X @Bitnewsbot to receive the latest BitPay, Copay or other Ethereum wallets and exchanges news.

- Advertisement -



Previous Articles:

- Advertisement -

Latest News

Real-Time Proof of Reserves Urged to Prevent Hidden Financial Risks

Traditional audits can miss risks that emerge between scheduled checks. Proof of reserves offers continuous,...

Gemini Launches Tokenized U.S. Stocks Trading in EU Market

Gemini has launched tokenized stock trading for users in the European Union. The service begins...

Harare Woman in Court Over $600k Cryptocurrency Fraud Allegation

Melissa Messe Samantha Chiyangwa appeared in a Harare court accused of stealing close to...

Bitcoin Institutional Surge Fails to Ignite Major 2025 Price Rally

Institutional adoption of Bitcoin (BTC) reached record levels in 2025 but price gains remained...

Trump Refuses to Divest Crypto Ventures, Cites Industry Growth

President Donald Trump would not commit to divesting from his personal crypto ventures if...

Must Read

How to Choose a Cryptocurrency Exchange: Major Risks and Expert Advice

During the bitcoin frenzy, in late 2017, Coinbase, one of the key players in the global cryptocurrency market, stopped trading operations. At a point...