Proprietary · · 78 days
Copay wallet targeted private keys
Copay builds included the malicious event-stream dependency chain. The payload was tuned to steal wallet private keys from affected 5.0.2 through 5.1.0 releases.
Copay was the target hidden inside the event-stream compromise. The attacker did not need to publish a fake wallet. They took over an upstream npm maintainer path, added flatmap-stream to event-stream, and waited for Copay's build chain to carry the payload into wallet releases.
The malicious code was selective. It stayed buried in an obfuscated npm dependency and decrypted only in the Copay context. BitPay later said versions 5.0.2 through 5.1.0 of the Copay and BitPay apps contained the malicious dependency chain, but the BitPay wallet was not vulnerable to execution.
The payload tried to capture private keys and send them to attacker-controlled infrastructure. That made the downstream impact different from the broad npm ecosystem impact: most event-stream consumers carried malicious code, but Copay users carried the value the attacker wanted.
BitPay fixed Copay in 5.2.0, told users not to open affected apps, and advised moving funds to a new wallet created with the clean version rather than reusing twelve-word backup phrases from potentially compromised wallets. Later 5.3.1 work locked dependency updates and restricted wallet network connections.
Appendix · Affected releases
- The upstream compromised artifacts are modeled in the OSS event-stream record; this record captures the downstream Copay wallet releases and user impact. BitPay said Copay 5.0.2 through 5.1.0 were vulnerable and fixed it in 5.2.0.
- BitPay's exposed customer count is not known; users is left as 0 for unknown rather than treating app downloads as confirmed victims. A previously listed SHA-256 named no Copay file and was removed as ambiguous.
- The compromised builds are not recoverable, checked 2026-09-03. bitpay/copay now has zero tags and zero releases, so the assets are gone; npm holds flatmap-stream only as a 0.0.1-security placeholder and npmmirror has no more.
- The payload itself is held under [[event-stream]], which has the event-stream release as probable_exact and flatmap-stream as disputed. What is missing here is only the Copay build that bundled them, not the injected code.
References
Source record: proprietary/copay/meta.yaml