BitPay Warns Users to Move Funds to New Wallets Amid Malicious Code Outbreak

2018-11-28 06:30

Global Bitcoin payment service BitPay has warned customers of a vulnerability on a third-party NodeJS package used by the Copay and BitPay apps which could be used to capture users’ private keys. The company said the malicious code was deployed on versions 5.0.2 through 5.1.0 of its Copay and BitPay apps. BitPay recommended users to move funds to new wallets immediately as private keys are potentially compromised.

BitPay Investigates Whether Code Vulnerability Exploited Copay Users

BitPay is currently investigating the matter as to whether Copay users suffered from any attack purported the malicious code, the company said in a statement.

“Currently, we have only confirmed that the malicious code was deployed on versions 5.0.2 through 5.1.0 of our Copay and BitPay apps. However, the BitPay app was not vulnerable to the malicious code. We are still investigating whether this code vulnerability was ever exploited against Copay users.”

The Bitcoin payment service warned customers not to use any infected Copay versions before running a security update provided by BitPay in the app stores.

“Our team is continuing to investigate this issue and the extent of the vulnerability. In the meantime, if you are using any Copay version from 5.0.2 to 5.1.0, you should not run or open the app. A security update version (5.2.0) has been released and will be available for all Copay and BitPay wallet users in the app stores momentarily.”

Additionally, BitPay recommended users to move funds to new wallets (v5.2.0) immediately as private keys could be compromised. The Atlanta-based firm warned users not to import affected wallets’ backup phrases as they too may be compromised.

“Users should not attempt to move funds to new wallets by importing affected wallets’ twelve word backup phrases (which correspond to potentially compromised private keys). Users should first update their affected wallets (5.0.2-5.1.0) and then send all funds from affected wallets to a brand new wallet on version 5.2.0, using the Send Max feature to initiate transactions of all funds.”

BitPay found out about the malicious payload via a Copay GitHub issue report. According to comments on GitHub, the malware “was really sneaky, and only triggering the upload of the private keys for wallets that had genuinely over 100 BTC in there”. BitPay and its users were lucky this time but should be prepared for future attacks, according to GitHub user atomantic.

“Narrowly escaped a mass theft/liquidation event. Network egress monitoring would be good to add to automated tests if not already part of the build validation process.”

In April 2018, BitPay issued a warning of a trojan horse called Coinbitclip which has affected some purchases using Bitcoin processed by the payment service. The trojan did not infect any specific Bitcoin wallet or payment system, but individual Windows users only, similarly to most types of ransomware.

 

Image from Shutterstock

The post BitPay Warns Users to Move Funds to New Wallets Amid Malicious Code Outbreak appeared first on NewsBTC.

Similar to Notcoin - Blum - Airdrops In 2024

origin »

World Trade Funds (XWT) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 0 XWT

bitpay users malicious code funds move copay

bitpay users → Результатов: 14


BitPay не поддержит возможный форк Bitcoin Cash

Криптовалютный процессинговый сервис BitPay заявил о том, что поддержит «традиционную» имплементацию ПО Bitcoin Cash под названием Bitcoin ABC. How does the November 15th #BitcoinCash hard fork affect BitPay users? For BitPay merchants: https://t.

2018-11-10 21:17


Фото:

BitPay-Pal? BitPay Introduces Settlement in USD-Pegged Stablecoins

BitPay, purportedly the largest blockchain payments provider, will allow merchants to accept settlements in USD-pegged stablecoins. Gemini Dollar and USD Coin Get the Green Light The leading blockchain payments provider BitPay announced that it will allow merchants to receive settlement in USD-backed stablecoins, namely the Gemini Dollar (GUSD) and Circle’s USD Coin (USDC).

2018-10-16 08:00


Фото:

It ‘Doesn’t Work’: Cryptocurrency Community Tells airBaltic To Ditch BitPay

BHB Network CEO Giacomo Zucco publicly urged Latvian airline airBaltic to replace BitPay as its Bitcoin payment processor September 5, claiming the company’s product “doesn’t work. ” Zucco to airBaltic: Go Open Source In a tweet, Zucco — who has become known for his support of open source alternatives to overly-centralized services both within cryptocurrency and beyond — called on airBaltic to look at switching from BitPay to open-source BTCPay and Globee.

2018-9-6 21:00


What Is BTCPay?

Bitcoin payment processors come in many different shapes and sizes. In every single case, users rely on centralized parties to take care of most of the legwork. BTCPay Server is an interesting solution in this regard, as it provides self-hosted payment processing through the BitPay API. The Concept of BTCPay Competition in the world of […]

2018-7-20 18:00