What is Clipboard Hijacker?
Malware that detects a copied crypto address on your device and silently replaces it with an attacker's address.
A clipboard hijacker is a type of malware that watches your clipboard for anything resembling a crypto address. When it spots one you have copied, it quietly swaps it for an address the attacker controls. If you paste and send without checking, your funds go straight to the thief.
This matters because it defeats the common habit of copy-pasting addresses. The attack is invisible until the money is already gone, and because transactions are irreversible, there is no recovery.
Example: you copy a friend’s address to repay them, but hidden malware replaces it during the paste; the transaction looks normal, yet the funds land in the attacker’s wallet.
Safety note: always verify the pasted address matches the intended one, checking the full string, not just the ends. Send a small test transaction first for large amounts, keep your devices free of pirated software and suspicious downloads, and use a hardware wallet so you can confirm the true recipient on the device screen. This threat overlaps with address poisoning as a reason never to trust a pasted address blindly. Related terms include wallet address, address poisoning, malware, and hardware wallet.
Related terms
Keep learning: read the guides · scam alerts · free tools · full glossary.