clipboard malware changed crypto address

Clipboard Malware Changed Your Crypto Address? Prove Which Address Was Actually Signed

If a crypto address changes after you copy and paste it, stop using that device for wallet activity immediately. Do not simply paste the correct address again and continue. First preserve the intended address, the pasted address and any transaction record. If nothing was signed, the immediate loss may still be avoidable. If a transaction was broadcast, check whether it is pending or confirmed. Then treat the device as potentially compromised until malware, extensions and other persistence are investigated—because modern clipper malware can do more than replace one address.

Most faucet rewards are tiny. FaucetPay can help you collect small payouts from supported faucets, PTC sites and reward platforms in one microwallet before withdrawing later.

Set up FaucetPay to collect small rewards →

If the pasted address changed, stop before testing again

A changed crypto address is not a normal clipboard quirk. MetaMask's current security guidance describes clipboard hacking as malware or spyware that watches copied values, detects crypto addresses and replaces them with an attacker-controlled address. Once you observe a mismatch, stop wallet sends on that device until the cause is investigated.

Do not keep copying addresses to see whether the malware does it again

Repeated tests using real wallet addresses create more opportunities to paste a substituted address into the wrong place or reveal additional clipboard data to malicious software. Preserve one clean example if you already have it, then move investigation away from active wallet use.

Use the Three-Address Divergence Proof

Record three values without exposing private keys or seed phrases.

  • A — Trusted Source Address: the address shown by the intended receiving wallet, authenticated exchange deposit page, verified address book or hardware-wallet display.
  • B — Pasted Address: the value that actually appeared after paste in a neutral text field or transaction form.
  • C — Signed / On-chain Destination: the recipient shown on the final signing device or, if broadcast, the recipient recorded in the blockchain transaction.

A equals B equals C — clipboard substitution is not proven

If all three addresses match, the loss or anomaly has another cause. Check the network, memo or tag, token contract, recipient ownership and transaction status. Do not label the device infected merely because a transfer went wrong.

A differs from B — this is the strongest clipboard-substitution pattern

If the trusted address is correct but the pasted value changes before you sign, something between copy and paste modified the destination. Clipboard malware is a strong explanation, but a malicious browser extension, webpage script or unusual clipboard manager can produce a similar symptom. Treat the host as compromised until investigated.

A equals B but C differs — inspect the transaction interface or signing path

If the pasted field was correct but the signed transaction uses another destination, simple clipboard replacement no longer explains the whole event. A malicious page, browser extension, wallet interface or compromised host may have altered the transaction after paste. Hardware-wallet users should compare C with the destination displayed on the hardware device.

A was copied from transaction history — check for address poisoning instead

Address poisoning is different from clipboard malware. In poisoning, an attacker plants a lookalike address in transaction history and hopes you copy the wrong value yourself. The clipboard may behave normally. Return to the original recipient's Receive or Deposit screen rather than using recent history as the address source.

A simple text-editor test can prove clipboard divergence

MetaMask currently suggests copying a wallet address and pasting it into the operating system's plain text editor to compare the result. If the copied and pasted addresses do not match, its guidance says to scan the device for malware, spyware or viruses. Perform this only after you have stopped real transfers and do not paste private credentials.

A clipboard mismatch proves device risk, not automatically seed theft

Do not jump from one replaced public address to the claim that the wallet seed was stolen. The evidence proves that software on the device can interfere with clipboard data. Whether private keys, passwords or recovery phrases were also exposed depends on the malware and what secrets were present on that device.

But modern clippers can be broader stealers

Microsoft's Defender Security Research Team described a Crypto Clipper campaign in June 2026 that monitored the clipboard for wallet addresses, seed phrases and private keys, replaced cryptocurrency destinations, captured screenshots and could execute attacker-supplied code. This does not mean every clipper has those capabilities; it means confirmed address replacement is serious enough to investigate as a wider host compromise.

Branch 1 — nothing was signed or submitted

If you caught the changed address on the confirmation screen and rejected the transaction, the blockchain loss may have been prevented. Confirm that no transaction hash or withdrawal request was created. Then leave the wallet inactive on that device and move to containment.

Do not 'fix' the address manually and sign from the same compromised screen

Typing or pasting the intended address again does not prove the malicious process is gone. Malware can replace the value again later, and a malicious interface can alter transaction details after the visible form. Use a trusted device or verified hardware display after containment.

Branch 2 — an exchange withdrawal request exists but no TXID exists

If the request is still inside a centralized exchange and no blockchain transaction has been broadcast, open the authenticated withdrawal history and use the exchange's official cancel control if available. The existing transaction-cancellation guide owns the platform-specific cancellation decision. Do not contact the wrong address owner because nothing may be on-chain yet.

Branch 3 — a self-custody transaction is pending

If a transaction hash exists and the transaction remains pending, some networks and wallets support replacement or cancellation while the sender still controls the nonce or inputs. That is a race, not a guaranteed undo. Move immediately to the cancellation guide and verify the final explorer state.

Do not increase the fee on the malicious transfer by mistake

A wallet's Speed Up function normally helps the existing transaction confirm faster. If the existing transaction already points to the attacker's address, speeding it up makes the bad outcome more likely. Use a documented cancellation or replacement path, not Speed Up, when your goal is to prevent that recipient from being paid.

Branch 4 — the wrong-address transaction is confirmed

Once the blockchain treats the transfer as confirmed or final, changing the clipboard cannot reverse it. A self-custody wallet provider normally cannot rewrite the destination. Preserve the transaction hash and recipient address and do not pay anyone who promises guaranteed blockchain reversal.

A confirmed wrong-address payment and a compromised wallet are separate questions

The transfer may be unrecoverable even when the private keys remain safe. Conversely, the wallet can be compromised even if you caught the address substitution before sending. Handle money recovery and wallet-authority recovery as two parallel tracks.

Start containment from another trusted device when possible

If the affected computer or phone may be running malware, use another trusted device for critical account changes and for creating any replacement wallet. Do not type a seed phrase or private key into the suspected host merely to check whether the wallet still opens.

Disconnecting the internet is containment, not proof of cleanup

Taking the device offline can interrupt command-and-control or further account access, but it does not remove malware, scheduled tasks, malicious extensions or stolen credentials. Preserve necessary evidence, then follow the operating-system vendor's malware-removal process.

On Windows, use the built-in malware scan options before trusting the host again

Microsoft's current Windows Security documentation provides Quick, Full, Custom and Microsoft Defender Offline scans. Defender Offline restarts into the Windows Recovery Environment so persistent malware has a harder time hiding or defending itself. Update security intelligence first where possible and review Protection History after scans.

A clean antivirus result is useful evidence, not a cryptographic guarantee

MetaMask warns that clipboard-hijacking scripts can be sophisticated and may activate only in particular wallet or dapp contexts. One scan that finds nothing does not prove the device was never compromised. Combine malware scanning with removal of suspicious software and extensions, operating-system updates and fresh verification before returning to financial activity.

Review recently installed software and browser extensions

A clipboard hijacker can arrive through malicious software, fake wallet applications, downloads or browser extensions. Review what was installed or enabled before the first observed mismatch. Remove software you cannot verify through its legitimate publisher and avoid installing random 'clipboard cleaner' tools from search ads.

Treat removable media as part of the incident when relevant

Microsoft's June 2026 Crypto Clipper analysis documented propagation through malicious shortcut files on USB storage. If the affected device recently used unknown or shared USB media, do not reconnect that media to other crypto devices until it has been investigated and scanned.

Check whether passwords or account sessions may also be exposed

Device malware can include spyware, screen capture, keylogging or browser-token theft beyond the clipboard. From a trusted device, review important email, exchange and wallet-related accounts for unexpected sessions, password changes or recovery events. Change compromised or reused passwords through official sites.

Determine whether the seed phrase or private key ever touched the infected device

Ask a concrete question: was the seed phrase, private key or an unencrypted backup ever typed, pasted, photographed, stored or displayed on this device while it may have been compromised? If no, do not claim the key is stolen without evidence. If yes, assume the secret may be exposed.

If a wallet secret may be exposed, a password change is not enough

A seed phrase or private key is the underlying signing authority. Changing the wallet application's local password does not change that key. MetaMask and Trezor both advise migrating funds to a wallet created from a fresh recovery secret when the old recovery authority is believed compromised.

Create the replacement wallet on a clean environment

If migration is required, create a new wallet with a new recovery phrase on a trusted device or properly initialized hardware wallet. Do not generate the new seed on the infected computer and do not import the old compromised phrase into the new wallet as a long-term solution.

A hardware wallet can protect keys without making the host trustworthy

A hardware wallet keeps signing keys isolated, but the computer can still lie about the destination. Trezor's Trusted Display guidance says malware can change what the computer or phone shows, while the hardware device displays the actual address or transaction it is about to use. Verify the complete destination on the device before approving.

If the hardware display showed the attacker address and you approved it, the device did what you authorized

That outcome is different from key extraction. The host may have substituted the destination, but the hardware wallet then displayed and signed that destination after user approval. The funds can still be lost even though the private key never left the hardware device.

If the hardware display showed the correct address but the blockchain shows another one, escalate the diagnosis

That would contradict the normal trusted-display model and should not be explained away as ordinary clipboard substitution. Preserve the device, firmware version, transaction hash and signing evidence and contact the hardware-wallet vendor through its official support channel before making further assumptions.

Keep an Incident Evidence Card

Record enough information to reconstruct the event without recording secrets.

  • Date and approximate time of the first mismatch
  • Trusted source of Address A
  • Pasted Address B
  • Signed or on-chain Address C
  • Asset and network
  • Transaction hash or withdrawal ID if one exists
  • Wallet or exchange used
  • Hardware-wallet model if relevant
  • Recently installed software, extensions or USB devices
  • Malware scan result and detection name if one is reported
  • Whether any seed phrase or private key was present on the device

Do not publish the evidence card with private data

Public wallet addresses and transaction hashes are normally sufficient for technical comparison. Do not include seed phrases, private keys, authenticator codes, passwords, recovery files or screenshots that display them. Support does not need full signing authority to inspect a transaction.

Do not pay a 'crypto recovery' technician who wants remote wallet access

A confirmed blockchain transfer cannot be magically reversed by remote desktop software. A stranger asking for seed words, private keys, remote-control access or an advance crypto payment can turn a clipboard incident into full wallet theft. Use official wallet, exchange, operating-system or law-enforcement channels appropriate to the case.

Return to crypto only after the trust boundary is rebuilt

Do not define success as 'the clipboard looks normal now'. Resume financial activity only when the environment you will use has been cleaned or replaced, wallet authority has been reassessed, important credentials have been secured and a trusted destination can be verified independently.

Use five final incident verdicts

End the incident with one state.

  • STOPPED BEFORE SIGN — the address changed but no request or blockchain transaction was created; contain and clean the device.
  • CANCEL WINDOW OPEN — a custodial or pending self-custody request may still be cancellable or replaceable; act through the documented transaction-control path.
  • CONFIRMED REDIRECT — the blockchain sent funds to the substituted address; preserve evidence and do not expect wallet software to reverse final settlement.
  • DEVICE COMPROMISE, KEYS NOT PROVEN EXPOSED — clean or replace the host, secure accounts and verify wallet authority before reuse.
  • SECRET MAY BE EXPOSED — create a new wallet from a fresh secret on a trusted environment and migrate remaining assets under the wallet's documented compromise procedure.

The practical response order

Use this sequence when you actually observe an address substitution.

  • 1. Stop signing and sending on the affected device.
  • 2. Preserve Address A, Address B and Address C if a transaction exists.
  • 3. Check whether the transaction is unsigned, internal to an exchange, pending on-chain or confirmed.
  • 4. Use the cancellation/replacement path only while a real control window remains.
  • 5. Move critical recovery work to another trusted device.
  • 6. Scan and investigate the affected host, extensions and recent software.
  • 7. Determine whether seed phrases, private keys or reused passwords were exposed.
  • 8. Migrate to fresh wallet keys only when the old signing authority may be compromised.
  • 9. Verify future destinations on a trusted source and, when available, a hardware-wallet display.

Why this page is separate from address poisoning

Address poisoning manipulates what address you choose by planting lookalike transaction-history entries. Clipboard hijacking changes the data after you copy it. The prevention overlaps—verify the full destination—but the incident evidence is different. A mismatch between trusted Address A and pasted Address B points toward clipboard or interface manipulation rather than a poisoned history choice.

Why this page is separate from the suspicious-site incident guide

The suspicious-site guide classifies connection, signatures, approvals, transactions and seed exposure after interacting with a questionable dapp. This page starts from host-level address substitution and asks whether the device itself can still be trusted, even when no suspicious dapp was connected.

Why this page is separate from the pre-paste checklist

The pre-paste guide is preventive and stops after proving one destination is safe to use. This article begins after the prevention check fails: an address has actually changed, so the user needs containment, transaction-state triage and malware/secret exposure assessment.

What can change after August 8, 2026

Wallet interfaces, malware families, browser-extension controls and operating-system scan options can change. The durable evidence is the divergence between the intended source address, pasted value and signed/on-chain recipient. Recheck wallet and OS vendor instructions before using interface-specific cleanup or transaction-control steps.

Sources checked on August 8, 2026

Current wallet, hardware-wallet, operating-system and security-vendor documentation was prioritized.

  • MetaMask — Clipboard hacking — https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/clipboard-hacking/
  • MetaMask — Address poisoning scams — https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/address-poisoning-scams/
  • MetaMask — I've been hacked or scammed — https://support.metamask.io/stay-safe/protect-yourself/ive-been-hacked-scammed-unauthorized-transactions-on-my-account/
  • MetaMask — How to migrate your assets to a new wallet — https://support.metamask.io/manage-crypto/move-crypto/transfer/account-migration-guide/
  • Microsoft Security — Crypto Clipper uses Tor and worm-like propagation for persistence and control — https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/
  • Microsoft Support — Virus & threat protection in the Windows Security app — https://support.microsoft.com/en-US/Windows/Security/threat-malware-protection/virus-and-threat-protection-in-the-windows-security-app
  • Trezor — Trusted Display: verify every address on your device — https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device
  • Trezor — Move crypto to a wallet with a new wallet backup — https://trezor.io/guides/backups-recovery/general-standards/move-crypto-to-a-wallet-with-a-new-wallet-backup
  • FTC Consumer Advice — Malware: How To Protect Against, Detect, and Remove It — https://consumer.ftc.gov/articles/malware-how-protect-against-detect-and-remove-it
Scam-aware reminder

Be careful with websites that promise unrealistic rewards, ask for deposits before withdrawal, or require suspicious wallet connections. Small reward sites should never need your seed phrase.

FAQ

What is clipboard malware in crypto?

Clipboard or clipper malware monitors copied data, detects cryptocurrency addresses and substitutes an attacker-controlled address before you paste. Some modern variants also steal other information, so a confirmed substitution should be treated as a device-security incident.

How can I prove that a crypto address was changed by the clipboard?

Compare the trusted recipient address with the value pasted into a neutral text field and, if a transaction exists, with the signed or on-chain destination. A source address that changes only after copy and paste is strong evidence of clipboard or interface manipulation.

What should I do if I notice the wrong address before confirming?

Reject the transaction, confirm that no TXID or withdrawal request was created, stop wallet activity on that device and investigate malware, extensions and recent software. Do not simply correct the address and continue signing from the same environment.

Can I cancel a crypto transfer sent to an address inserted by malware?

Only while a genuine control window remains. An exchange request may be cancellable before broadcast, and some pending self-custody transactions may support replacement. A confirmed blockchain transfer normally cannot be reversed by wallet software.

Does clipboard malware mean my seed phrase is compromised?

Not automatically. It proves the device can alter clipboard data. But current malware families can also capture seed phrases, private keys, screenshots or credentials, so check whether any signing secret was stored, typed, pasted or displayed on the affected device.

Should I move all crypto to a new wallet after a clipboard hijack?

Move to a wallet created from a fresh recovery secret when the old seed phrase or private key may have been exposed. If the keys remained isolated in a hardware wallet and only the host destination was altered, first clean or replace the host and verify the wallet authority rather than assuming key compromise without evidence.

Can a hardware wallet stop clipboard malware?

It cannot prevent the computer clipboard from being altered, but its trusted display can show the actual destination the device is about to sign. The user must compare that address with the intended recipient and reject the transaction if it differs.

Is clipboard hijacking the same as address poisoning?

No. Clipboard hijacking changes the address after copy. Address poisoning places a lookalike address in transaction history so the user chooses the wrong address before copying. Both require full destination verification, but their evidence and incident response differ.