Bitpay’s Copay Wallet Has Been Compromised

- Advertisement -

November 28, 2018 12:15 AM

The vulnerability only affects certain versions of the Copay wallet.

BitPay’s Copay wallet has been comprised, according to a November 26 announcement from the company, by malware that can potentially access private keys and be used to steal digital currency.

The malicious code appears to have first been identified last week on GitHub, although BitPay seems to have only become aware of the vulnerability after a separate GitHub issue was published yesterday, November 26.

- Advertisement -

According to the press release, JavaScript code used by both Copay and BitPay applications was modified to load the malware. The malicious code was installed on the 5.0.2 through 5.1.0 versions of BitPay’s Copay wallet. The BitPay smartphone app is not affected, and BitPay is still investigating to find out if any individual user accounts were compromised.

In the meantime, BitPay is urging its customers using the infected versions of the Copay wallet to not open the app and to assume their private keys have been compromised.

BitPay says it has released a security update, Copay wallet version 5.2.0, which will be accessible to all Copay and BitPay customers. The company is cautioning users to first update their wallet to the more secure 5.2.0 version before inputting their 12-word backup phrases because these phrases correspond to private keys that may have been compromised. Once their wallets have been updated, users should move their funds from affected wallets to the updated version.

Nathan Graham is a full-time staff writer for ETHNews. He lives in Sparks, Nevada, with his wife, Beth, and dog, Kyia. Nathan has a passion for new technology, grant writing, and short stories. He spends his time rafting the American River, playing video games, and writing.

Like what you read? Follow us on X @Bitnewsbot to receive the latest BitPay, Copay or other Ethereum wallets and exchanges news.



Previous Articles:

- Advertisement -

Latest News

New Critical n8n Flaw Allows Remote Code Execution

A critical flaw (CVE-2026-25049) in the automation platform n8n enables authenticated users to execute...

Alphabet Stock Rallies as AI Drives Record Q4 Profit Growth

Alphabet's Q4 earnings beat Wall Street expectations, with EPS of $2.82 and revenue of...

UNICEF urges criminalizing AI deepfakes of child abuse

UNICEF research estimates 1.2 million children had their images manipulated into sexual deepfakes last...

CFTC Drops Proposed Ban on Prediction Markets

The US Commodity Futures Trading Commission has withdrawn a proposal that sought to ban...

Kyle Samani Steps Down as Multicoin Capital Managing Director

Kyle Samani, managing director at Multicoin Capital, announced his departure via a post on...
- Advertisement -

Must Read

Are Cryptocurrency Securities?

TL;DR - Cryptocurrencies are not typically considered securities, as they are decentralized digital assets that operate independently of any central authority or government. However,...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!