Clipper malware rewrites the wallet address between your copy and paste
Clipboard hijackers sit dormant for months, then replace a copied crypto address with the attacker's own. One booby-trapped GitHub campaign siphoned five Bitcoin, per Kaspersky.
You copy a long string of characters you could never memorize, switch windows, and paste. Clipper malware — also called a clipboard hijacker — lives in that half-second gap. It watches your clipboard for anything shaped like a crypto address and quietly substitutes one the attacker controls. You approve the payment you meant to send, and the coins go somewhere else. Because you never mistyped anything, nothing feels wrong until the funds fail to arrive.
How a clipper works
The swap is hard to catch because the replacement is itself a valid-looking address. Kaspersky's Vitaly Kamluk warned that clipboard injectors can 'remain silent for years,' showing no network traffic, until the moment they overwrite a wallet address. Many strains change only part of the string, so the beginning and end still resemble what you expected.
Where it hides
In February 2025 Kaspersky detailed GitVenom, a campaign of hundreds of booby-trapped GitHub repositories — fake Telegram bots, game cracks and automation tools dressed up with AI-generated descriptions — whose payload bundled a clipboard hijacker. It stole five Bitcoin, worth about $485,000 at the time and received in November 2024, per Kaspersky, with most infections in Brazil, Turkey and Russia. An earlier clipper spread through a trojanized Tor Browser and stole roughly $400,000 across more than 15,000 attacks in 52 countries in 2023, Kaspersky found, hitting Bitcoin, Ethereum, Litecoin, Dogecoin and Monero.
The delivery channels keep shifting — pirated software, cracked games, fake privacy tools, poisoned open-source projects — but the endgame is identical: get the swap code onto your machine and wait for a large transfer.
What makes clippers dangerous is their patience and reach. The GitVenom repositories passed as ordinary developer projects, and the fake Tor Browser masqueraded on the system with the icon of a common app such as uTorrent and set itself to launch at startup, Kaspersky said. Neither showed obvious symptoms; the theft only surfaces when a payment lands in a stranger's wallet.
Protect yourself
- Verify the full pasted address against the source, character by character, before you sign anything.
- Send a small test transaction first when moving significant funds.
- Download wallets, browsers and tools only from official sources — trojanized installers on third-party sites are the main delivery route, per Kaspersky.
- Use a hardware wallet, which displays the true destination address on its own screen for confirmation.
- Keep endpoint security and OS patches current, and be wary of 'cracked' software and unvetted code repositories.
A clipper never needs your seed phrase or your password. It needs only your assumption that the address you pasted is the address you copied — which, for a few hundred milliseconds, is the one thing you cannot see happening.
— Sources: [Kaspersky](https://www.kaspersky.com/about/press-releases/kaspersky-exposes-hidden-malware-on-github-stealing-personal-data-and-485000-in-bitcoin) · [Kaspersky](https://www.kaspersky.com/about/press-releases/new-clipper-malware-steals-us400000-in-cryptocurrencies-via-fake-tor-browser)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING