Bitcoin Forum
May 05, 2024, 03:16:30 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [2018-11-27] Breaking: Numerous Bitcoin Wallets May Have Been Compromised by Rog  (Read 185 times)
Lmaooo (OP)
Full Member
***
Offline Offline

Activity: 694
Merit: 108


santacoin.io


View Profile
November 27, 2018, 01:41:33 AM
 #1

Breaking: Numerous Bitcoin Wallets May Have Been Compromised by Rogue Developer

A Node.js module called event-stream is used in millions of web applications, including BitPay’s open-source bitcoin wallet — Copay — and this module was reportedly compromised thanks to what can objectively referred to as social engineering, laziness, and incompetence.

A user with very little coding activity on GitHub requested publishing rights to the event-stream library from its previous maintainer, Dominic Tarr, who said that he had not maintained the repository in years and gave control to the new user, called right9ctrl.

The library event-stream is used in many Node.js applications. According to a complainant on GitHub, the new maintainer right9ctrl either pulled a sneaky move to inject malware or unknowingly had the same effect as if he had, that effect being that it would leak private keys from applications that relied on both the event-stream and copay-dash modules.

CCN | https://www.ccn.com/breaking-numerous-bitcoin-wallets-may-have-been-compromised-by-rogue-developer/

1714922190
Hero Member
*
Offline Offline

Posts: 1714922190

View Profile Personal Message (Offline)

Ignore
1714922190
Reply with quote  #2

1714922190
Report to moderator
1714922190
Hero Member
*
Offline Offline

Posts: 1714922190

View Profile Personal Message (Offline)

Ignore
1714922190
Reply with quote  #2

1714922190
Report to moderator
1714922190
Hero Member
*
Offline Offline

Posts: 1714922190

View Profile Personal Message (Offline)

Ignore
1714922190
Reply with quote  #2

1714922190
Report to moderator
Unlike traditional banking where clients have only a few account numbers, with Bitcoin people can create an unlimited number of accounts (addresses). This can be used to easily track payments, and it improves anonymity.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714922190
Hero Member
*
Offline Offline

Posts: 1714922190

View Profile Personal Message (Offline)

Ignore
1714922190
Reply with quote  #2

1714922190
Report to moderator
1714922190
Hero Member
*
Offline Offline

Posts: 1714922190

View Profile Personal Message (Offline)

Ignore
1714922190
Reply with quote  #2

1714922190
Report to moderator
bbc.reporter
Legendary
*
Offline Offline

Activity: 2926
Merit: 1442



View Profile
November 27, 2018, 03:12:18 AM
 #2

Why would Dominic Tarr give publishing rights to someone he does not know? I reckon there might be more to this story. Did anyone question the possibility that right9ctrl is really Dominic?

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3071



View Profile
November 27, 2018, 11:05:43 AM
 #3

Bitpay: another nail in the coffin of their incompetence

Vires in numeris
hatshepsut93
Legendary
*
Offline Offline

Activity: 2968
Merit: 2145



View Profile
November 27, 2018, 04:00:09 PM
 #4

Javascript's ecosystem has really poor security, people are using modules without even thinking to audit them or checking the devs behinds them. Popular packages depend on dozens or even hundreds of other packages, so attack surface can be huge. Developers need to take this issue very seriously, and users should avoid using middlemen like BitPay and online wallets because of these risks.

.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
milewilda
Legendary
*
Offline Offline

Activity: 3108
Merit: 1127



View Profile
November 27, 2018, 04:11:58 PM
 #5

Why would Dominic Tarr give publishing rights to someone he does not know? I reckon there might be more to this story. Did anyone question the possibility that right9ctrl is really Dominic?
Also a question on my mind too which rights do easily being passed out to someone.I'll search up between the relation or the full story of this one because its impossible on such
arrangement without any connections among the two.Talking about right9ctrl is Dominic then its possible.

leea-1334
Hero Member
*****
Offline Offline

Activity: 2240
Merit: 953


Temporary forum vacation


View Profile
November 27, 2018, 04:26:14 PM
 #6

I hope this is a stupid question but this has nothing to do with Electrum wallet or Bitcoin Core right? I do not think I recognize any of those names but you know, just in case. I remember seeing the forum warning when there was the Electrum vulnerability a few months ago so just want to make sure my client is safe.

Any merchants using Bitpay affected?

.
..........
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
█████████████░░██████████████████████████░░███████████████████
███████████████░░██████████████████████████░░█████████████████
█████████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░███████████████
█████████████████░░░░░░░░░░██░░██░░░░░░░░░░██░░███████████████
███████████████████░░░░░░██░░██████░░░░░░██░░█████████████████
█████████████████████░░░░░░██████████░░░░░░███████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
.....I AM BLACKJACK.FUN.....
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
█████████████░░██████████████████████████░░███████████████████
███████████████░░██████████████████████████░░█████████████████
█████████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░███████████████
█████████████████░░░░░░░░░░██░░██░░░░░░░░░░██░░███████████████
███████████████████░░░░░░██░░██████░░░░░░██░░█████████████████
█████████████████████░░░░░░██████████░░░░░░███████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████
██████████████████████████████████████████████████████████████

▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
..........
Theb
Hero Member
*****
Offline Offline

Activity: 1680
Merit: 655


View Profile
November 27, 2018, 05:57:19 PM
 #7

Good thing that BitPay already confirmed the issues as well as provided the necessary steps on transferring funds of the users who are affected. This was their latest blog post regarding the issue.

Users should assume that private keys on affected wallets may have been compromised, so they should move funds to new wallets (v5.2.0) immediately. Users should not attempt to move funds to new wallets by importing affected wallets' twelve word backup phrases (which correspond to potentially compromised private keys). Users should first update their affected wallets (5.0.2-5.1.0) and then send all funds from affected wallets to a brand new wallet on version 5.2.0, using the Send Max feature to initiate transactions of all funds.

So to any members here who have Copay wallets you should follow BitPay's instructions in order to avoid any chances of losing your funds. So far I haven't seen any reports of stolen cryptocurrencies but I think Copay users should act immediately before this thing goes south.

..bustadice..         ▄▄████████████▄▄
     ▄▄████████▀▀▀▀████████▄▄
   ▄███████████    ███████████▄
  █████    ████▄▄▄▄████    █████
 ██████    ████████▀▀██    ██████
██████████████████   █████████████
█████████████████▌  ▐█████████████
███    ██████████   ███████    ███
███    ████████▀   ▐███████    ███
██████████████      ██████████████
██████████████      ██████████████
 ██████████████▄▄▄▄██████████████
  ▀████████████████████████████▀
                     ▄▄███████▄▄
                  ▄███████████████▄
   ███████████  ▄████▀▀       ▀▀████▄
               ████▀      ██     ▀████
 ███████████  ████        ██       ████
             ████         ██        ████
███████████  ████     ▄▄▄▄██        ████
             ████     ▀▀▀▀▀▀        ████
 ███████████  ████                 ████
               ████▄             ▄████
   ███████████  ▀████▄▄       ▄▄████▀
                  ▀███████████████▀
                     ▀▀███████▀▀
           ▄██▄
           ████
            ██
            ▀▀
 ▄██████████████████████▄
██████▀▀██████████▀▀██████
█████    ████████    █████
█████▄  ▄████████▄  ▄█████
██████████████████████████
██████████████████████████
    ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
    ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
       ████████████
......Play......
cr1776
Legendary
*
Offline Offline

Activity: 4032
Merit: 1299


View Profile
November 27, 2018, 07:33:24 PM
 #8

I hope this is a stupid question but this has nothing to do with Electrum wallet or Bitcoin Core right? I do not think I recognize any of those names but you know, just in case. I remember seeing the forum warning when there was the Electrum vulnerability a few months ago so just want to make sure my client is safe.

Any merchants using Bitpay affected?

Bitcoin Core doesn't use node.js since it is not written in Javascript.

Electrum is written using primarily Python, (https://github.com/spesmilo/electrum ), so shouldn't be impacted either.

As far as merchants using Bitpay, who knows.
bbc.reporter
Legendary
*
Offline Offline

Activity: 2926
Merit: 1442



View Profile
November 28, 2018, 12:11:27 AM
 #9

Bitpay: another nail in the coffin of their incompetence

Isn't only Copay affected and not the Bitpay processor?

In any case, this news should be bigger than it is, I reckon. Also, the users should be informed that there are other bitcoin processors available for them to be safe, like Globee and Btcpay.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
..........UNLEASH..........
THE ULTIMATE
GAMING EXPERIENCE
DUELBITS
FANTASY
SPORTS
████▄▄█████▄▄
░▄████
███████████▄
▐███
███████████████▄
███
████████████████
███
████████████████▌
███
██████████████████
████████████████▀▀▀
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
.
▬▬
VS
▬▬
████▄▄▄█████▄▄▄
░▄████████████████▄
▐██████████████████▄
████████████████████
████████████████████▌
█████████████████████
███████████████████
███████████████▌
███████████████▌
████████████████
████████████████
████████████████
████▀▀███████▀▀
/// PLAY FOR  FREE  ///
WIN FOR REAL
..PLAY NOW..
figmentofmyass
Legendary
*
Offline Offline

Activity: 1652
Merit: 1483



View Profile
November 28, 2018, 12:55:38 AM
 #10

Bitpay: another nail in the coffin of their incompetence

Isn't only Copay affected and not the Bitpay processor?

the copay wallet was created by bitpay, and they maintain it. so this compromise certainly reflects poorly on them.

i imagine you're right, they're not running their business on top of copay. i haven't seen any news suggesting bitpay was hacked or anything.

jeromix
Copper Member
Jr. Member
*
Offline Offline

Activity: 266
Merit: 2

Ako Bayot!


View Profile
November 28, 2018, 03:01:10 PM
 #11

It was proven already year after year that the bitcoin could not be easily cracked down. But, for the bitcoin wallets as stated by OP could be. However, wallets that will be vulnerable for this are those online wallets or the exchange wallets. There is no way that they could breach the hardware wallet that is being stored in the PC or smartphone for it is an offline wallet.

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!