you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 10 min ago 255 onions tracked
home / news / security
04 November 2025 security 4 min read

Clipboard hijackers: the silent malware that swaps your crypto address

You copy a wallet address, paste it into your wallet app, and hit send. The transaction confirms on-chain, but the money never arrives where you intended. The odds are good that a clipboard hijacker swapped the destination in the milliseconds between copy and paste.

How the swap actually works

Clipboard malware, known in the trade as clippers, runs quietly in memory and polls the clipboard at high frequency. Microsoft researchers documented one strain checking every 500 milliseconds, matching copied text against regex patterns for Bitcoin, Ethereum, Tron, and Monero formats before overwriting them (Microsoft Defender Security Blog). The economics are absurdly favorable to the attacker. As Kaspersky analysts put it when examining CryptoShuffler, there is no access to mining pools, no network interaction, and no suspicious processor load; the malware simply waits for a string that looks like an address and replaces it (Kaspersky). The whole substitution takes milliseconds. Detection is trivially easy for the malware because most cryptocurrency addresses have recognizable prefixes and fixed lengths. A regular expression does the rest. No privilege escalation, no exploits, no user interaction beyond the copy-paste habit almost everyone has.

Documented campaigns, real losses

CryptoShuffler is the classic case. Kaspersky reported in late 2017 that its operators had already collected more than 23 BTC, then worth around $150,000, by targeting Bitcoin, Ethereum, Zcash, Dash, Monero, and even Dogecoin (BleepingComputer). The technique never went away; it industrialized. In early 2025, CyberArk uncovered MassJacker, a clipper backed by an encrypted list of roughly 778,531 attacker wallets, with a single Solana cash-out wallet amassing over $300,000 in transactions (BleepingComputer). Distribution channels have widened too. ESET found trojanized WhatsApp and Telegram apps that replace wallet addresses directly inside chat conversations, some even using OCR to read seed phrases from screenshots (ESET). Kaspersky's GitVenom campaign seeded hundreds of fake GitHub repositories that netted attackers about 5 BTC, roughly $485,000, from a single hijacked wallet.

Why checking the ends is not enough

The common advice, glance at the first and last few characters, was sound advice circa 2017. It is not sound today. Modern clippers generate or fetch lookalike addresses that deliberately preserve those exact edges. The Laplas Clipper, first observed in November 2022 and later sold as malware-as-a-service from $49 per week, sends each copied address to a bot server that returns a visually similar substitute (Cisco Talos). BleepingComputer testers reproduced the trick, generating a matching-prefix Bitcoin address in about five seconds. Academic work formalized the problem as the EthClipper attack, which mines vanity addresses whose prefixes and suffixes match the victim's, defeating hardware-wallet confirmation screens precisely because users verify only the visible ends of the string (arXiv research paper). Ledger's own support documentation now warns that scammers craft addresses with identical first and last characters for exactly this reason. Address poisoning compounds the risk. Scammers dust wallets with decoy transactions whose addresses match the short form displayed by most interfaces, six characters at the front and four at the back, hoping victims copy a lookalike from their own transaction history later.

Practical defenses that actually hold up

No single measure is bulletproof, but layered habits make clipboard attacks dramatically less likely to succeed:
  • Verify the middle. Compare several characters from the center of the address, not just the edges, since lookalikes concentrate their differences there.
  • Use checksum tools. Paste the full address into our bitcoin validator or monero validator to confirm it parses as a valid address before sending.
  • Confirm on the hardware screen. Scroll through the entire recipient address on your device display; that screen cannot be rewritten by PC malware.
  • Ditch the clipboard for repeat payments. Store verified recipients in your wallet's address book and select by name instead of re-copying.
  • Send a test transaction for large amounts, confirming the small payment landed before moving the rest.
Keep the host clean, too. Clippers arrive through cracked software, fake installers, malicious GitHub projects, and phishing attachments, so a reputable antivirus with real-time protection remains the first line of defense. Some products, including Kaspersky's Safe Money, explicitly guard clipboard contents during transactions.

The bottom line

Clipboard hijacking endures because it converts ordinary behavior, copying and pasting, into an irreversible transfer, and blockchain finality means there are no chargebacks. Attackers now possess vanity-address tooling that defeats casual inspection outright. Treat any pasted address as untrusted until it has been fully validated character by character or on a trusted screen. A few seconds of verification against the entire string is the only reliable habit left. Our security notes cover additional hardening steps for high-value wallets.

more notes

all news ›