ThreatPaper
Unverified

Malicious code in Copay stole users' bitcoin private keys

Assessment

The capability is established beyond dispute. Copay versions 5.0.2 through 5.1.0 shipped code that decrypted only inside Copay's build, injected itself into the running application, and transmitted private keys by HTTP POST to copayapi[.]host for wallets holding more than 100 BTC or 1,000 BCH. BitPay confirmed the affected versions directly. What was never established is that any keys were actually taken. BitPay's statement of 26 November 2018 says the company was "still investigating whether this code vulnerability was ever exploited against Copay users," and no subsequent public confirmation, victim count or loss figure was ever published — not by BitPay, not by any exchange, and not by law enforcement. Academic analysis of the incident states the attack "succeeded, directly affecting several users" without disclosing counts or amounts, and cites no public source for a total. Headlines written in the present tense — code that "steals private keys" — assert an outcome the record does not contain. The rating is Unverified rather than False because theft is entirely plausible and may well have occurred; the point is that eight years later nobody has published evidence that it did, and the incident is routinely described as a completed theft anyway.

Where this claim appeared

CoinGeek · 2018-11-27

https://coingeek.com/malicious-code-injected-bitpays-copay-wallet-steals-private-keys/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

event-stream: The npm Maintainer Handover That Backdoored a Bitcoin Wallet

Think this assessment is wrong? Report an error.