What Is Clipboard Malware? The Virus That Swaps Your Crypto Address

Clipboard malware β often called a clipper β is a small program that watches everything you copy. It does nothing at all until it spots something shaped like a crypto address, and then it quietly swaps that address for one belonging to the attacker. You paste, the transaction looks normal, you confirm it, and the money arrives in a stranger's wallet. Nothing can be reversed and nobody can help you.
Think of writing an address on an envelope and handing it over, while someone behind you replaces it with an identical-looking envelope addressed elsewhere.
Why is the swap so hard to notice?
Because nobody reads a crypto address. It is a long string of random characters, and wallets like MetaMask show it shortened in the middle, so you glance at the first four and last four and move on. Attackers know this: they generate thousands of addresses until they find one whose beginning and end match the address you copied. The middle is different, and the middle is the part you never check. The site you copied from was perfectly genuine β the theft happens in the two seconds between copy and paste.
How does it get onto a machine?
Almost always through something you installed. Cracked software and game cheats are the classic route. So are fake wallet or trading apps downloaded from a search advert sitting above the real site, browser extensions asking for more permission than they need, and files sent in a Discord or Telegram message by someone helpful. Phone versions exist too, usually in apps installed from outside the official stores.
What actually stops it?
- Check the middle of the address after pasting, not just the ends. This one habit defeats the whole attack.
- Send a small test amount first and wait for it to arrive before sending the rest.
- Confirm on a hardware wallet screen. A Ledger or Trezor shows the real destination on its own display, which malware on your computer cannot edit.
- Install only from official sites, typed in yourself or opened from your own bookmark.
If a pasted address ever comes out different from the one you copied, stop immediately and treat that computer as compromised: move your funds using a clean device, and assume anything else stored on the infected machine was read too. Our guides to test transactions and hardware wallets cover both defences in full.