Clipboard Hijackers: The Malware That Swaps Your Address

You copy a wallet address, paste it, and send. Somewhere in between, malware on your machine swapped it for a different one – and nothing on screen suggested anything had happened.

Not the same trick as address poisoning

Address poisoning

Pollutes your history

Your device stays clean. The danger is copying a bad address that arrived there legitimately.

Clipboard hijacker

Infects your device

Your history stays clean. Malware swaps the address in the half-second between copy and paste.

The defense for one does nothing against the other – see how address poisoning works.

How it works, mechanically

Infection
Listening
Substitution

The clipper arrives inside something you installed, registers a clipboard handler that tests every copy against address formats for Bitcoin, Ethereum, Tron and others, then swaps the contents for an attacker's address the moment a match fires.

The attacker behaved like a marketer, not a hacker

Check Point Research documented a Rust-based clipper in June 2026 hidden inside Solana and Pump.fun sniper bots, an "Aviator Predictor," and crash-game forecasters – tools built for people hunting an edge. The malware itself was old news. What stood out was the campaign built around it:

  • A WordPress hub feeding downloads through GitHub, SourceForge and YouTube
  • Repositories padded with fake stars and forks
  • A download counter showing tens of thousands of installs – from a platform with no build for it
  • Tutorial videos with AI narrators and coordinated positive comments

Every check a careful person runs before downloading – star count, reviews, community sentiment – had been bought in advance.

The ratio of addresses to funds recovered is the design, not a failure – it's what makes the operation hard to block.

778,531

unique attacker addresses found in the MassJacker campaign alone (CyberArk)

$336,700

moved through those addresses in total – no two victims ever pay the same one

15,500+

addresses packed into a single Check Point-analyzed clipper binary, rotated as used

The advice that doesn't transfer

Three habits that genuinely help against other crypto scams, and why none of them catch this one.

A saved address book

Works against address poisoning, not this. You can select a perfectly correct address from your own contacts – the substitution happens after the copy and before the paste, on your own machine.

Checking the first and last characters

Catches a random swap, so clipper authors adapted. The Laplas family generates a lookalike of the address you copied – researchers produced a convincing one in about five seconds.

A hardware wallet

Protects your keys and seed phrase – neither is under attack here. It can't know the destination you approved isn't the one you intended. You'll confirm the swapped address yourself.

What actually works

  • Verify the address after pasting it, not before. Read what's actually sitting in the recipient field against a trusted source, comparing the middle of the string – not just the ends.
  • If you use a hardware wallet, check the address on its screen. That display is beyond the reach of clipboard malware on your computer.
  • Send a small test first for large transfers, then re-verify the field contents before the real send rather than reusing anything.
  • If something tells you to bypass a security warning – disable Gatekeeper, ignore a signature prompt – stop. That instruction is the payload's install step.
  • Treat cracked software, sniper bots and game cheats as a wallet risk, not just a legal one. Most major clipper campaigns are distributed exactly this way.
  • Keep a separate, clean device for anything involving real money – one machine for downloads and experiments, another for significant holdings.

Two paste operations, both exposed on an infected machine

A standard SimpleSwap exchange involves pasting an address twice, and a clipper can substitute either one:

You paste in

The receiving address for your swap.

You copy out

Our deposit address, into your own wallet.

Nothing on our side can detect a substitution – the swapped address is indistinguishable from one typed deliberately, and a confirmed transfer can't be reversed. The service can be operating perfectly and funds can still end up somewhere else. Read what's actually in the field after pasting – ours included. Our only official domain is simpleswap.io.

Want the full breakdown?

Read the full guide for the Check Point and Microsoft research in detail, how the Laplas lookalike generator works, and the complete prevention checklist.

Key takeaways

  • Clipboard malware swaps the address after you copy it – even a correct source can end up at the wrong destination.
  • Star ratings, reviews, and community sentiment can all be bought in advance – they don't prove safety.
  • Read the destination address from your screen right before sending, every time.

Clipboard Hijackers FAQ

Address poisoning pollutes your transaction history while your device stays clean – the danger is copying a bad address that arrived there legitimately. A clipper is the reverse: your history is fine, but malware on your machine swaps the address between copy and paste. The defense for one does nothing against the other.

No. A hardware wallet protects your keys and seed phrase, not the destination address. If a clipper has already swapped what's in the field, you'll approve and confirm that swapped address yourself on the device screen.

Verify the address after you paste it, not before you copy it. Read what actually landed in the recipient field against a trusted source, and compare the middle of the string, not just the first and last characters.

No exchange can be, and that's worth saying plainly. A standard exchange involves two paste operations – the receiving address you enter and the deposit address you copy from us – and a clipper can substitute either one. Nothing on our side can tell a swapped address from one you typed deliberately, and a confirmed transfer can't be reversed.