May 24, 2026

Capitalizations Index – B ∞/21M

Breaking: Numerous Bitcoin Wallets May Have Been Compromised by Rogue Developer

Breaking: numerous bitcoin wallets may have been compromised by rogue developer

Breaking: Numerous Bitcoin Wallets May Have Been Compromised by Rogue Developer


Bitcoin wallet hack copay breach
Advertisement


CCN is expanding. Are you our next full-time journalist from the West Coast USA? Send us your CV and examples here.

A Node.js module called event-stream is used in millions of web applications, including BitPay’s open-source bitcoin wallet — Copay — and this module was reportedly compromised thanks to what can objectively referred to as social engineering, laziness, and incompetence.

A user with very little coding activity on GitHub requested publishing rights to the event-stream library from its previous maintainer, Dominic Tarr, who said that he had not maintained the repository in years and gave control to the new user, called right9ctrl.

The library event-stream is used in many Node.js applications. According to a complainant on GitHub, the new maintainer right9ctrl either pulled a sneaky move to inject malware or unknowingly had the same effect as if he had, that effect being that it would leak private keys from applications that relied on both the event-stream and copay-dash modules.

Ayrton Sparling wrote:

“He added flatmap-stream which is entirely (1 commit to the repo but has 3 versions, the latest one removes the injection, unmaintained, created 3 months ago) an injection targeting ps-tree. After he adds it at almost the exact same time the injection is added to flatmap-stream, he bumps the version and publishes. Literally the second commit (3 days later) after that he removes the injection and bumps a major version so he can clear the repo of having flatmap-stream but still have everyone (millions of weekly installs) using 3.x affected.”

Basically, the developer updated the module with malware and then patched the problem to avoid detection, but the numerous people who had already installed it remain affected. Copay — whose open-source code is itself used by many crypto applications — would be just one of many that use the library, but it happens to be built and maintained by a multi-million dollar bitcoin payment processing company — BitPay — which raises questions on its own.

Why Does BitPay Use Upstream Libraries?

Those outside of open source development may have the misconception that it is all done for free due to ideals or hobbyism, but this is far from the case. The majority of major and important open source development, such as work on bitcoin Core or work on the Linux Kernel, for instance, is done by developers who are employed by companies with a stake in the development of such software.

Companies like Red Hat contribute code to the Linux Kernel and companies like Blockstream employ bitcoin Core developers. The reason is obvious: while they could simply wait on releases and rely on the work of others, these companies understandably have aims to achieve in development and also, most importantly, have a lot of money at stake in kernel development.

This model works for major software development, and this author believes that there is no reason it shouldn’t be applicable here. Rightfully, BitPay should arguably not be using software on a trust basis. Millions upon millions of dollars in client wallets are being entrusted to them, not upstream developers. If BitPay is not interested in actively developing libraries like event-stream, then they should use forked versions, verifying that each update is safe. Instead, as many industry stakeholders have alleged, they’ve demonstrated incompetence.

CCN has reached out to BitPay for comment and will update this article upon receiving a reply.

Featured Image from Shutterstock

Get Exclusive Crypto Analysis by Professional Traders and Investors on Hacked.com. Sign up now and get the first month for free. Click here.

Advertisement


Published at Mon, 26 Nov 2018 20:37:26 +0000

Previous Article

Daily: Bitcoin Shoots up 10% !! But Why??

Next Article

Blockchain Training in Calgary, Alberta for Beginners-Bitcoin training-introduction to cryptocurrency-ico-ethereum-hyperledger-smart contracts training

You might be interested in …

全球支付处理商万事达:电子货币的风险远超出益处

全球支付处理商万事达:电子货币的风险远超出益处

全球支付处理商万事达:电子货币的风险远超出益处 6月9日消息 CoinDesk报道 万事达表示,电子货币所呈现的风险远超出其带来的益处。 去年11月,英国财政部要求提交关于电子货币的信息,全球支付处理商万事达在其上交的文件中,作出了以上评论。 CoinDesk通过自由信息要求获得了该文件,该文件共有4页,万事达在提交文件中表示,其认为电子货币并没有很多显著的优势。 万事达批判了电子货币的低交易成本、较低的交易处理时间以及系统的安全性。该文件写到,“我们认为,相比于万事达支付网络,电子货币所谓的快速、安全并不能站住脚,至少从其完成一个区块需要10分钟才能验证完成来看,电子货币会明显地更容易受到黑客攻击。” 万事达还继续写到,尽管目前电子货币交易的成本或许低于传统支付方式,但是这是由于电子货币服务提供者无需承担消费者保护和反洗钱法律的成本。 万事达称,一旦监管引入,电子货币交易成本会很快提高。 消费者保护 万事达提交的文件建议英国政府制定新监管条例,以解决目前电子货币领域缺乏的消费者保护问题。 万事达指出的其中一个风险是,如果现在消费者使用电子货币购买商品,而商家并没有发货,那么消费者没有任何法定储备金的保护。 为了更进一步对比突出现行金融系统的安全性,该文件引用了英国的《金融服务补偿规定(Financial Services Compensation Scheme)》,该规定要求,如果公司倒闭,那么该注册公司的每位客户可获得高达8.5万美元的补偿。 万事达还提及了许多关于众所周知的比特币交易平台MtGox倒闭的事情,强调电子货币领域缺乏保护而导致消费者遭受的损失。 此外,万事达还认为,比特币用户处于危险之中,随着该电子货币使用的增加,比特币挖矿成本势必增加,直到这种成本无法承受。文件中还继续写到,“为了获得规模经济,电子货币的高边际成本将对导致矿工数量的减少,直到成就一些垄断的矿工,这就违背了电子货币设计的初衷,同时比特币使用者面临广泛性的系统性欺诈。” 综合建议 万事达建议政府应当制定监管条例,解决加密货币相关的风险问题,同时保障了合法的电子货币公司“蓬勃发展”。 万事达写到,“现在的区块过程”并没有提供足够的透明性,监管应当要求所有的交易经由监管性的、透明的管理者的检查,也就是这些交易应当受到国家、欧洲或者全球相关机构的监管。 电子货币公司应当如同非银行货币公司一样,要获取执照和受到监管。他们应当要求“履行KYC条例,进行反洗钱(AML)过程,提交可疑的活动报告,并且解决加密货币安全问题。” 最后,万事达认为,政府应当制定消费者保护措施,强制电子货币公司制定正规的消费者投诉流程,并且可以撤销未授权的投诉。 其它机构提交的文件 为响应电子货币信息要求,其它公司提交了相关文件,其中包括埃森哲和花旗银行。 埃森哲在它的回应中建议英国政府应当监管比特币钱包,应用银行账户一样的身份认证要求。 另一方面,花旗银行财务交易服务技术及创新团队则建议财政部应当考虑建立自身的电子货币。 原文:http://www.coindesk.com/mastercard-digital-currencys-risks-outweigh-the-benefits/网址:http://www.btc798.com/article-7754-1.html (Why?) Published at Wed, 05 Apr 2017 00:06:24 +0000 [wpr5_ebay kw=”bitcoin” num=”1″ ebcat=”” cid=”5338043562″ lang=”en-US” country=”0″ sort=”bestmatch”]Scientific InstrumentRendered in Mental Ray with area lights and final gather. Final […]

Germany: Six Arrested in Illegal Crypto Mining Operation

Germany: Six Arrested in Illegal Crypto Mining Operation German police have arrested six members of a mining ring who were making use of stolen electricity to mine currency since 2017, as reported by Freie Presse, […]