
Clipboard hijackers: the malware that swaps the address you pasted
Nobody types a crypto address by hand. You copy it from an exchange, an invoice or a message, paste it into your wallet, and press send. That habit is exactly what a whole family of malware is built around.
A clipboard hijacker — often called a "clipper" — sits quietly on an infected computer or phone, watches what you copy, and the moment it sees something that looks like a crypto address, replaces it with one belonging to the attacker. You paste, you send, and the funds go somewhere you never intended.
How a clipper works
Clipboard access is a normal feature. Plenty of legitimate apps read the clipboard, so a program doing it doesn't stand out.
A clipper adds one step. It checks every copied piece of text against patterns: a string starting with bc1 or 1 or 3 might be Bitcoin, 0x followed by 40 hex characters is an EVM address, and so on. When there's a match, it swaps in an attacker address of the same type. More careful versions pick a replacement that shares the first and last few characters with yours, so a quick glance at both ends looks right.
The swap happens in the gap between copy and paste. Your wallet receives a perfectly valid address — just the wrong one — and has no way to know it was ever different.
How you end up infected
Clippers are rarely the main event. They usually arrive bundled with something you chose to install:
- Cracked software and game cheats. Pirated tools are one of the most common delivery routes.
- Fake wallet apps and "trading bots". Software promising an edge is a perfect lure for exactly the people who move crypto.
- Malicious browser extensions. An extension with permission to read pages and the clipboard can do the same job from inside your browser.
- Booby-trapped downloads. Fake installers for popular apps, delivered through search ads or lookalike sites.
Keeping your system updated, installing only from official sources and running fewer extensions all reduce the odds. But the honest assumption is that any general-purpose computer could be compromised one day — which is why the defences that matter most don't depend on the computer being clean.
Checking an address properly
The habit that beats a clipper is checking the pasted address against the source — and checking more than the ends.
- Compare a middle section too. Lookalike addresses are generated to match the beginning and the end. A run of characters from the middle is far harder to fake.
- Check after pasting, not before. The swap happens on paste. Looking at what you copied proves nothing.
- Use the original source. Compare against the address shown on the exchange or invoice page, not against a copy of a copy.
- Send a small test first for large or first-time payments, and confirm it arrived before sending the rest.
- Save trusted addresses. An address book entry you verified once can't be swapped on its way through the clipboard.
This is the same discipline that protects against address poisoning, where attackers seed your history with lookalike addresses instead of rewriting your clipboard. In both cases, the attacker is betting you'll check only the first and last few characters.
Why a second device matters
A clipper on your computer controls what your computer shows you. If the same machine both builds the transaction and asks you to confirm it, the malware can make the two agree.
That's where SSP's design helps. When you send from SSP Wallet, the transaction isn't complete until SSP Key approves it on your phone. SSP Key decodes the transaction on the phone itself and shows you the recipient and amount from that decode — not from anything your computer claims. A clipper on your computer can change what you paste, but it can't change what your phone reads out of the transaction.
So the check that counts is on SSP Key: compare the recipient address there against the original source before you approve. It's the moment the two-device model is built for, and the approval on the second device is what actually stops a transaction when something upstream has gone wrong.
The limit is worth stating plainly. SSP Key shows you the address the transaction really pays — it can't know which address you meant to pay. If you approve without comparing, a swapped address goes through just as validly as the right one.
If it happens
A confirmed transaction can't be reversed. If you discover funds went to a swapped address:
- Stop using the infected device for anything sensitive, and assume anything typed or copied on it is exposed.
- Check whether the device held keys. If it did, move remaining funds to new keys created on a clean device.
- Report it to the exchange or service you were paying, and keep the transaction ID — occasionally stolen funds reach a platform that can freeze them.
- Clean or reinstall the device before trusting it again.
The honest summary
Clippers don't break cryptography; they exploit copy and paste. They win when the address you check is the one on the same screen the malware controls, and when you only glance at the ends.
Compare the full address against the original source, check a middle section, test large payments, and make the final comparison on a separate device. With SSP, that's SSP Key — use it as the second look it's designed to be. And when the address format itself is unfamiliar, it's worth knowing how address formats differ before you send.


