Fake Developer Sneaks Malicious Code into BitPay's Copay Wallet
The Copay wallet from crypto payments processor BitPay has been compromised by a hacker, the firm warns. An updated version has been released.

The Copay wallet from U.S.-based bitcoin payments processor BitPay has been compromised by a hacker, the firm says.
Bitpay announced Monday that it learned about the issue from a Copay GitHub reporthttps://github.com/bitpay/copay/issues/9346 indicating that a third-party JavaScript library used by the apps had been modified to load malicious code.
The malware was deployed on versions 5.0.2 through 5.1.0 of its Copay and BitPay wallet apps, and could potentially be used to capture private keys to steal bitcoin and bitcoin cash.
BitPay said:
“However, the BitPay app was not vulnerable to the malicious code. We are still investigating whether this code vulnerability was ever exploited against Copay users,”
The firm is asking users to not run or open the Copay wallet if they are using versions from 5.0.2 to 5.1.0. It has now released an updated version (5.2.0) without the malicious code for all Copay and BitPay wallet users that will be available in app stores "momentarily."
BitPay stressed: “Users should assume that private keys on affected wallets may have been compromised, so they should move funds to new wallets (v5.2.0) immediately.”
Bitpay has also advised users to not move any funds to new wallets by importing their 12-word backup phrases, since they correspond to "potentially compromised private keys.”
“Users should first update their affected wallets (5.0.2-5.1.0) and then send all funds from affected wallets to a brand new wallet on version 5.2.0, using the Send Max feature to initiate transactions of all funds,” it explained.
The attack appears to have been carried out by a supposed developer called Right9ctrl who took over maintenance of the NodeJS library from its author who no longer had time for the work, ZDNet reports. The social engineering attack occurred about three months ago when Right9ctrl was granted access to the repository, at which point they injected the malware.
Jackson Palmer, the creator of the dogecoin cryptocurrency, tweeted in response to the news: "This is one of the major issues with JavaScript-based cryptocurrency wallets with heavy up-stream dependencies coming from NPM. BitPay essentially trusted all the up-stream developers to never inject malicious code into their wallet. "
Code image via Shutterstock
More For You
Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.
需要了解的:
Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.
The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.
More For You
Bitcoin climbs above $89,000 as U.S. dollar tumbles on President Trump's remarks

The president said he isn't concerned about the dollar's recent declines, sending the greenback plunging even lower.
需要了解的:
- Bitcoin rallied above $89,000 as remarks by President Trump sent the dollar to its lowest level in nearly four years.
- Gold rose to a new record above $5,200 per ounce following the president's comments.
- One analyst is seeing a bullish technical divergence which could send bitcoin back to $95,000 in short order.










