LiveActive security incident?Get immediate response
CVE Record

CVE-2018-1000851: Copay Bitcoin Wallet version 5.01 to 5.1.0 included.

Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appear to be exploitable via Affected version run the malicious code at startup . This vulnerability appears to have been fixed in 5.2.0 and later .

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Certain Copay Bitcoin Wallet releases shipped with malicious code that could expose users' wallet private keys when the affected app started. For executives, the business risk is direct cryptocurrency loss and trust impact, not generic server compromise. The CVE record says Copay 5.01 through 5.1.0 were affected and 5.2.0 or later fixed it.

Executive priority

Prioritize this where the organization used Copay for business or customer cryptocurrency operations. The impact can be direct asset theft, so confirm exposure quickly. If no affected Copay use exists, this is primarily historical supply-chain awareness.

Technical view

CVE-2018-1000851 concerns Copay Bitcoin Wallet private-key storage exposure caused by malicious code executed at startup. Public references connect the incident to the event-stream npm package compromise. The source bundle provides no CVSS score or CWE, but states affected versions 5.01 to 5.1.0 and a fix in 5.2.0 and later.

Likely exposure

Exposure is most likely where Copay Bitcoin Wallet 5.01 through 5.1.0 was installed or distributed. Systems without Copay, or with Copay 5.2.0 or later, are not identified as affected by the provided sources.

Exploitation context

The CVE states malicious code could run at startup and compromise users' private keys. KEV is false in the bundle, so do not treat this as CISA-confirmed known exploited. Public reporting describes this as a real supply-chain backdoor incident targeting Bitcoin theft.

Researcher notes

Evidence is strong for affected Copay versions and fixed version, but the bundle lacks CVSS, CWE, and detailed vendor remediation beyond upgrade guidance. Avoid expanding scope to other wallets or packages unless separate evidence is reviewed.

Mitigation direction

  • Upgrade Copay to version 5.2.0 or later.
  • Follow BitPay guidance for affected wallets and funds.
  • Identify any users who ran Copay 5.01 through 5.1.0.
  • Treat exposed wallet private keys as potentially compromised.
  • Review vendor and project advisories before taking recovery actions.

Validation and detection

  • Inventory installed Copay versions across managed endpoints.
  • Check whether users ran affected versions before upgrade.
  • Review wallet exposure against BitPay's published advisory.
  • Confirm current deployments are Copay 5.2.0 or later.
  • Document any affected wallets for incident response handling.
Prepared
Confidence
medium
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-1000851 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
5Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.