Clipper Malware Steals Cryptocurrency by Swapping Wallet Addresses
A type of malware called a clipper has been targeting cryptocurrency holders by swapping their wallet addresses with ones controlled by attackers.
The attack, which has been around for some time but evolved over the summer of 2026 in three key ways, relies on the fact that crypto addresses are vulnerable when they leave the secure area of a wallet and travel through the operating system as plain text.
According to Microsoft, one of the variants of this malware reads the clipboard every 500 milliseconds, looking not only for addresses but also harvesting seed phrases and private keys. This means that even if you copy your recovery words to the clipboard, they can be exposed on an infected machine.
The clipper does not decrypt or open any wallet files, nor does it guess passwords. It simply recognizes a pattern in the clipboard and swaps the address with one controlled by the attacker. The checksum of the crypto address is no help here, as it detects corrupted addresses but not swapped ones.