SubscribeBTCSCAMWallet Test
Front page / Field guide: receiving crypto
elevatedField guide: receiving crypto

Verify every receive address on the device screen, not on the computer

Clipboard-swapping malware quietly replaces the address you copied with the thief's lookalike. Only the address shown on the hardware wallet's own screen can be trusted.

MO
Mara Okafor
Chief Investigations Editor · NOV 3, 2023 · 3 min read
Painting: Renaissance archive · Source: BleepingComputer

A crypto address is a long string of random characters, and almost nobody reads one all the way through. Most people glance at the first few characters, maybe the last few, and paste. That habit is the entire opening for a class of malware built to swap addresses in transit, and it works precisely because the address is too tedious to check by eye.

The swap you never see

In November 2022, per BleepingComputer, researchers detailed a clipboard hijacker called Laplas Clipper. It sits quietly on a Windows machine, watches the clipboard, and the instant you copy a wallet address it substitutes a lookalike the attacker controls, one crafted to resemble the original down to its first and last characters. Per the report it could target 19 assets and platforms, from Bitcoin and Ethereum to Solana and Cardano, and it spread through loaders such as Smoke Loader and Raccoon Stealer 2.0.

You copy the correct address; you paste what looks like the correct address; the funds settle with a stranger. Because the paste and the confirmation both happen on the same infected computer, the screen you would normally check against is the very screen doing the lying. No amount of care on that machine helps, because the machine itself is the adversary.

Why the device screen wins

This is exactly the gap a hardware wallet's own display is built to close. Per Ledger, its secure screen is driven directly by the device's Secure Element, so malware on the connected computer cannot alter what the device shows; the wider design goal is summed up as "what you see is what you sign." Ledger's rule is to double-check that the receiving address on the device screen matches the one on your internet-connected device before signing; if they differ, the computer is likely infected.

  • For any address you paste, confirm it on the hardware wallet's own screen, not just the computer or phone display.
  • Compare the full string, or at least a stretch of the middle, not only the first and last characters a clipper is built to match.
  • When receiving, use the wallet's on-device "show address" or "verify address" function rather than trusting a copied value.
  • For a large transfer, send a small test amount first and confirm it arrives at the intended address.
  • If the device screen and the computer disagree, stop; treat the machine as compromised.

The principle behind every hardware wallet is that the screen you trust is the one the attacker cannot touch. Verifying the address there, every time, costs a few seconds and defeats an attack that is otherwise invisible until the money is already gone.

— Sources: [BleepingComputer](https://www.bleepingcomputer.com/news/security/new-clipboard-hijacker-replaces-crypto-wallet-addresses-with-lookalikes/) · [Ledger](https://www.ledger.com/academy/topics/ledgersolutions/ledger-wallets-secure-screen-security-model)

The Rug Report
Every scam that mattered this week, each Sunday.

NOT FINANCIAL ADVICE · VERIFY EVERYTHING