Clipboard hijackers: the silent malware that swaps your crypto address
You copy a wallet address, paste it into your wallet app, and hit send. The transaction confirms on-chain, but the money never arrives where you intended. The odds are good that a clipboard hijacker swapped the destination in the milliseconds between copy and paste.
How the swap actually works
Clipboard malware, known in the trade as clippers, runs quietly in memory and polls the clipboard at high frequency. Microsoft researchers documented one strain checking every 500 milliseconds, matching copied text against regex patterns for Bitcoin, Ethereum, Tron, and Monero formats before overwriting them (Microsoft Defender Security Blog). The economics are absurdly favorable to the attacker. As Kaspersky analysts put it when examining CryptoShuffler, there is no access to mining pools, no network interaction, and no suspicious processor load; the malware simply waits for a string that looks like an address and replaces it (Kaspersky). The whole substitution takes milliseconds. Detection is trivially easy for the malware because most cryptocurrency addresses have recognizable prefixes and fixed lengths. A regular expression does the rest. No privilege escalation, no exploits, no user interaction beyond the copy-paste habit almost everyone has.Documented campaigns, real losses
CryptoShuffler is the classic case. Kaspersky reported in late 2017 that its operators had already collected more than 23 BTC, then worth around $150,000, by targeting Bitcoin, Ethereum, Zcash, Dash, Monero, and even Dogecoin (BleepingComputer). The technique never went away; it industrialized. In early 2025, CyberArk uncovered MassJacker, a clipper backed by an encrypted list of roughly 778,531 attacker wallets, with a single Solana cash-out wallet amassing over $300,000 in transactions (BleepingComputer). Distribution channels have widened too. ESET found trojanized WhatsApp and Telegram apps that replace wallet addresses directly inside chat conversations, some even using OCR to read seed phrases from screenshots (ESET). Kaspersky's GitVenom campaign seeded hundreds of fake GitHub repositories that netted attackers about 5 BTC, roughly $485,000, from a single hijacked wallet.Why checking the ends is not enough
The common advice, glance at the first and last few characters, was sound advice circa 2017. It is not sound today. Modern clippers generate or fetch lookalike addresses that deliberately preserve those exact edges. The Laplas Clipper, first observed in November 2022 and later sold as malware-as-a-service from $49 per week, sends each copied address to a bot server that returns a visually similar substitute (Cisco Talos). BleepingComputer testers reproduced the trick, generating a matching-prefix Bitcoin address in about five seconds. Academic work formalized the problem as the EthClipper attack, which mines vanity addresses whose prefixes and suffixes match the victim's, defeating hardware-wallet confirmation screens precisely because users verify only the visible ends of the string (arXiv research paper). Ledger's own support documentation now warns that scammers craft addresses with identical first and last characters for exactly this reason. Address poisoning compounds the risk. Scammers dust wallets with decoy transactions whose addresses match the short form displayed by most interfaces, six characters at the front and four at the back, hoping victims copy a lookalike from their own transaction history later.Practical defenses that actually hold up
No single measure is bulletproof, but layered habits make clipboard attacks dramatically less likely to succeed:- Verify the middle. Compare several characters from the center of the address, not just the edges, since lookalikes concentrate their differences there.
- Use checksum tools. Paste the full address into our bitcoin validator or monero validator to confirm it parses as a valid address before sending.
- Confirm on the hardware screen. Scroll through the entire recipient address on your device display; that screen cannot be rewritten by PC malware.
- Ditch the clipboard for repeat payments. Store verified recipients in your wallet's address book and select by name instead of re-copying.
- Send a test transaction for large amounts, confirming the small payment landed before moving the rest.