Clipboard Hijacking
Share post
In Brief
Clipboard hijacking is malware that watches your device's clipboard for copied crypto addresses and silently swaps them for an attacker's address, so your funds go to a thief when you paste and send.

What Is Clipboard Hijacking?
Clipboard hijacking (clipper malware) is a form of malware that monitors your device's clipboard. The moment you copy a crypto wallet address, it replaces the copied text with an attacker's address of the same format. When you paste and send — often without re-checking — your funds go to the thief.
It works because crypto addresses are long strings nobody memorizes; most people glance at the first few characters at best. Clippers often arrive bundled with pirated software, fake app installers, or malicious browser extensions.
How a Clipper Attack Works
Malware infects your computer or phone and quietly watches the clipboard.
You copy a legitimate address — from a message, exchange page, or wallet.
The malware substitutes a look-alike attacker address in the clipboard.
You paste, see a plausible address, confirm — and the transaction is irreversible.
How to Protect Yourself
Verify the pasted address — check the first and last several characters, plus a section in the middle, every time.
Send a test amount first for large transfers.
Use QR codes or an in-app address book instead of copy-paste where possible.
Avoid pirated software and unofficial app stores — the classic clipper delivery route.
Clipboard Hijacking and Trust Wallet
Trust Wallet's address book lets you save verified recipients so routine sends never rely on the clipboard, and the send screen shows the full destination address for a final check before anything is signed. Paste, pause, verify — then send.