Latest news about Bitcoin and all cryptocurrencies. Your daily crypto news habit.
A developer has injected a piece of malicious code into the software used by the popular Copay and Bitpay wallets. The safety of the Bitcoin.com wallet was not compromised and the Bitpay app was not vulnerable to the attack, but Copay users need to take precautionary actions.
Also Read: Chinese Startup Gets Crypto Custodial Services License in Hong Kong
Someone Might Have Been Able to Steal Private Keys
The Bitpay team has announced that a third-party NodeJS (the open-source Java Script environment) package used by the Copay and BitPay apps had been modified to load malicious code. This could have been used to capture and steal usersâ private wallet keys. The company learned about the vulnerability from a GitHub issue report about an âevent-streamâ dependency attack.
Bitpay has only confirmed so far that the malicious code was deployed on its Copay and Bitpay apps from version 5.0.2 to 5.1.0. However, the company has tried to reassure users by saying that the Bitpay app was not vulnerable to the malicious code. A security update (version 5.2.0) has been developed and will be made available for users in the app stores. And the team is still investigating to figure out if the malicious code was ever actually used against people.
What Copay Wallet Users Need to Do Now to Keep Safe
The Bitpay team warns that anyone using a Copay app from version 5.0.2 to 5.1.0 should not open it again. Users should first update their affected wallets and then send all funds from affected wallets to new version 5.2.0 wallets. Users should not attempt to move funds to new wallets by importing affected backup phrases, as they should assume that the corresponding private keys may have been compromised.
If you use the Bitcoin.com wallet you have not been affected by this issue at all, so you donât need to do anything. âOur wallet doesnât use the compromised âpackage,â so weâre completely out of trouble for this one,â explains the Bitcoin.com wallet development team. âWeâre operating as normal, we have never used that package and will never use it.â
Do you use an affected Copay wallet? Share your thoughts in the comments section below.
Images courtesy of Shutterstock.
Verify and track bitcoin cash transactions on our BCH Block Explorer, the best of its kind anywhere in the world. Also, keep up with your holdings, BCH and other coins, on our market charts at Satoshiâs Pulse, another original and free service from Bitcoin.com.
Disclaimer
The views and opinions expressed in this article are solely those of the authors and do not reflect the views of Bitcoin Insider. Every investment and trading move involves risk - this is especially true for cryptocurrencies given their volatility. We strongly advise our readers to conduct their own research when making a decision.