Clipboard hijacking is a quiet but devastating attack that exploits how everyone sends crypto: by copying and pasting an address.
The attack requires malware to already be on your device. That malware watches your clipboard in the background. The instant it detects that you have copied something shaped like a crypto address, it silently replaces it with an address the attacker controls. You paste, see a long string that looks right, and hit send, never noticing the switch. Your funds go straight to the thief.
Because the swap happens invisibly and instantly, the only reliable defence is to verify the address after you paste it, not just before you copy it. Check the full string, or at least several characters from the middle as well as the ends, every single time.
Keeping your device clean of malware is the root protection: only install software from trusted sources, and be cautious with unknown downloads and email attachments.
Frequently Asked Questions
How would this malware get on my device?
Usually through a malicious download, a fake app, or an email attachment. Clipboard hijackers rely on already being installed, so keeping your device clean is the first line of defence.
How do I catch the address swap?
Always verify the pasted address before sending, checking characters in the middle as well as the start and end. Sending a small test amount first adds another layer of safety.