Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Kalshi’s crypto perpetuals spark debate over whether they’re futures or swaps

June 14, 2026

CFTC Staff No-Action Letter Opens Path For True Digital Comm

June 14, 2026

ETC Announces Fiscal 2026 Full Year and Fourth Quarter Results

June 14, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Hacker Steals Crypto from Copay Wallets Apps
Hacker Steals Crypto from Copay Wallets Apps
Security and Privacy

Hacker Steals Crypto from Copay Wallets Apps

August 15, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Security researcher Jacob Burroughs (@maths22), discovered that Copay-related libraries were targeted by a hacker who gained legitimate access to a widely used JavaScript library, according to GitHub.

The attacker was reportedly publishing rights to EventStream, the library loading the malicious code, which has over two million weekly downloads on the npmjs.com repository, according to ZDNet. After the attacker breached the Node.js module, they injected malicious code that stole Bitcoin and Ethereum from inside BitPay’s Copay wallet apps.

“The attacker began by submitting to the project, building trust, and eventually gaining owner-level access, which enabled the attacker to push a compromised version, snarfing Bitcoin and Ethereum hot-wallet credentials so they could be stolen and used for malicious activity,” said Casey Ellis, CTO at Bugcrowd.

“The main takeaway with this attack is that in the world of modern software, it’s turtles all the way down….Just because the code you write is secure doesn’t mean that the code other developers write for you is. The only way to get ahead of this is to practice deep and continuous abuse-case (i.e., security) testing.”

Based on research from Juniper Threat Labs, there have been very few (single-digit) attempts to connect to the threat actor’s command-and-control server hosting copayapi[.]host, which could be a good sign that not many people have been affected, if any at all, said Mounir Hahad, head of Juniper Threat Labs.

While many people favor open source frameworks with the belief that multiple eyes keep the code safe, this attack is an example of the inherent risks in what is believed to be the safer alternative to proprietary software, according to Hahad.

See also  Robinhood Settles With California for $3,900,000 After Probe Finds Users Were Blocked From Withdrawing Crypto

“While this is mostly true, as this example demonstrates, supply chain attacks including those at the very source of the chain can still take place. The attack took place in September and was only discovered in November, which gave the threat actor plenty of time and resulted in millions of users downloading the infected code. The last code change from the threat actor on this library was indeed on September 20, 2018, when he removed the infected code from the most recent version of the package,” Hahad said.

“To protect against similar attacks, users of open source libraries need to stay aware of communication on security boards and the sites where they download software from and act swiftly to apply patches when an issue is discovered.”

Source link

Apps Copay Crypto Hacker Steals wallets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Kalshi’s crypto perpetuals spark debate over whether they’re futures or swaps

June 14, 2026

Crypto exchanges are morphing into stock brokerages to stop capital from fleeing to Wall Street

June 14, 2026

Michael Selig Is Reshaping U.S. Crypto Policy as Sole CFTC Commissioner

June 14, 2026

South Korea Police Crypto Custody Bid Draws Fire for Favoring Large Exchanges

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Japan FSA Finalizes New Rules for Stablecoins, Crypto Intermediaries, and Funds Transfers

May 25, 2026

SEC’s Hester Peirce reflects on investor interest in spot Bitcoin ETFs

October 23, 2023

Nimble Network Integrates with Data Storage Mechanism of BNB Chain

April 15, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Kalshi’s crypto perpetuals spark debate over whether they’re futures or swaps

June 14, 2026

CFTC Staff No-Action Letter Opens Path For True Digital Comm

June 14, 2026

ETC Announces Fiscal 2026 Full Year and Fourth Quarter Results

June 14, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$64,085.00-0.25%
  • ethereumEthereum(ETH)$1,662.43-1.04%
  • tetherTether(USDT)$1.000.01%
  • binancecoinBNB(BNB)$606.68-0.55%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.13-1.76%
  • solanaSolana(SOL)$67.36-1.48%
  • tronTRON(TRX)$0.3176400.11%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.02-1.29%
  • HyperliquidHyperliquid(HYPE)$60.410.35%