Clipboard hijacker: How malware changes the address in the clipboard
The user copies the correct address, but malware swaps it before pasting.
This scheme doesn't necessarily require a "hack" in the usual sense. The user copies the correct address, but malware swaps it before pasting. The attack relies on this very ordinary action.
The main thing to know right away: The key is not to panic and not to try to "fix" the situation with random transfers. First, stop the repeat risk, save the original data, and only then figure out what happened.
How the scheme works
A clipboard hijacker monitors the clipboard and replaces a string that looks like a crypto address with the attacker's address. The user copies the correct details, but after pasting sees a different address.
In this situation, it's important to separate two things: the attack mechanism itself and what has already happened to the assets. The user copies the correct address, but malware swaps it before pasting. After an incident, a technical review begins not with guesses, but with a specific transaction and its continuation on the blockchain.
What to do if this has already happened
Before confirming, compare the address after pasting with the original source. If you suspect swapping, use a clean device and check the system for malware before the next transfer.
- Stop repeating the action that led to the incident: don't sign new requests and don't send additional payments.
- Save the tx hash, full addresses, network, asset, amount, and time of the transaction.
- Record the correspondence, domain, profile, app, or signing screen — everything that explains the context of the transaction.
- If there is a risk of wallet compromise, move the remaining assets to a new secure wallet without using the exposed seed phrase.
- If the amount is significant, it makes sense to trace the further route of the funds and identify service points along the way.
What to save for the review
For this specific topic, it's especially useful to save: the original address, the address after pasting, a screenshot of the send form, and device information.
For an initial review, prepare the data in a single message or file — this reduces the risk of losing an important detail:
- tx hash / txid
- full sender and recipient addresses
- network, asset, amount, and time
- screenshots and correspondence
- domain, profile, or app, if they are related to the incident
What you should avoid doing
- Don't share your seed phrase or private keys with "helpers" or a "recovery service."
- Don't pay an unknown intermediary a "tax," "insurance," or "unlock fee."
- Don't delete correspondence or transaction history before everything is saved.
Important: a transaction and an address are verifiable on-chain facts. The owner's identity, motive, and legal status should not be automatically inferred from a single graph.
When it makes sense to bring in a specialist
If the amount is significant, the route has already branched, or exchanges, swap services, bridges, and other services have appeared along it, a manual review helps separate available actions from useless ones. To start, public data is usually enough — private keys are not needed.
Frequently asked questions
Does a test transfer protect against a clipboard hijacker?
Only if the test address and the main amount address are each verified against a trusted source every time. If the address is copied from an infected environment the second time, the swap may happen again.
Can a confirmed transaction be canceled?
As a rule, no. Further actions depend on the route of the funds and whether services have appeared along it that can restrict the movement of assets.
Can you immediately identify a scammer by an address?
No. The blockchain shows addresses and transactions. Identity requires additional data: a service's KYC, public sources, case materials, or other confirmations.
In short
The user copies the correct address, but malware swaps it before pasting. If this has already happened, first stop the repeat risk and save the original data. Then you can review the route and the real points for further action.
Need to understand what happened and where the funds went?
Send the tx hash, network, and a short description of the situation. A seed phrase and private keys are not needed for an initial assessment.
Submit data for assessment