Library · Crypto, word by word · Scams and security
What is clipboard malware?
Clipboard malware is malicious software that watches what you copy and, when it sees a crypto address, silently swaps in an address the attacker controls. You paste what looks like the right address and send your funds to the thief.
What it means for you
A crypto payment cannot be reversed, so the check has to happen before you send: compare the pasted address with the original in full, every character, not just the first and last few. On a hardware wallet, compare the address on the device screen with the address the recipient gave you through a separate channel.
A common mistake: “My hardware wallet shows the address, so clipboard malware cannot affect me.”
In fact: The device shows the address it was given. If malware swapped it before you pasted, the screen displays the attacker's address faithfully; it protects you only if you compare that screen with the real address.
How it works
The malware runs in the background and monitors the clipboard for text matching an address format, then replaces it. Research on one such attack showed the substitute can be picked from a store of pre-generated addresses to match the original's prefix and suffix, defeating people who check only a few characters; matching about a quarter of the characters gave roughly even odds of a convincing fake. bitcoin.org notes such malware also spreads through compromised open-source packages and trojanized apps. Address poisoning differs: it plants a lookalike in your transaction history, while clipboard malware alters the address on your own device.
Sources: bitcoin.org: Avoid scams (malware), Ivanov and Yan, EthClipper: A Clipboard Meddling Attack on Hardware Wallets (arXiv) · checked 4 October 2026
Often confused with
On Cryptominium
Related words
Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.