[{"data":1,"prerenderedAt":494},["ShallowReactive",2],{"page-\u002Fguides\u002Fclipboard-hijacking-crypto-wallet-address\u002F":3},{"id":4,"title":5,"body":6,"description":471,"extension":472,"meta":473,"navigation":489,"path":490,"seo":491,"stem":492,"__hash__":493},"content\u002Fguides\u002Fclipboard-hijacking-crypto-wallet-address.md","Clipboard Hijacking in Crypto: How Malware Replaces Wallet Addresses",{"type":7,"value":8,"toc":450},"minimark",[9,13,16,23,28,31,91,95,98,101,117,120,124,127,189,203,207,210,231,234,238,241,244,247,261,264,282,286,289,294,297,301,304,308,311,315,318,322,325,329,332,336,339,393,396,399,403,406,423,440,444,447],[10,11,12],"p",{},"Clipboard hijacking is one of the nastiest crypto mistakes because the wallet address can look normal at a glance.",[10,14,15],{},"You copy an exchange deposit address, a self-custody receive address, or a payment request. Malware on the computer or phone swaps it for the attacker's address before you paste it. If you only check the first and last few characters, the transfer can still look right until the funds are gone.",[10,17,18,19],{},"This is not the same as a fake wallet app, an approval scam, or address poisoning. The specific problem is simple: ",[20,21,22],"strong",{},"the address in your clipboard is no longer the one you intended to use.",[24,25,27],"h2",{"id":26},"short-answer","Short answer",[10,29,30],{},"If you move meaningful amounts of crypto, assume the computer or phone screen can be wrong and verify the address on a trusted screen before you send.",[32,33,34,47],"table",{},[35,36,37],"thead",{},[38,39,40,44],"tr",{},[41,42,43],"th",{},"Situation",[41,45,46],{},"Safest move",[48,49,50,59,67,75,83],"tbody",{},[38,51,52,56],{},[53,54,55],"td",{},"You pasted a wallet address and it looks slightly different",[53,57,58],{},"Cancel the transfer immediately and compare the full address from the source again.",[38,60,61,64],{},[53,62,63],{},"Your wallet app warns about an address mismatch",[53,65,66],{},"Stop. Scan the device for malware and do not keep sending from that system.",[38,68,69,72],{},[53,70,71],{},"You are sending to your own Ledger or Trezor",[53,73,74],{},"Verify the receive address on the device screen, not only in the app.",[38,76,77,80],{},[53,78,79],{},"You are withdrawing from an exchange",[53,81,82],{},"Open the destination wallet's receive flow again, compare the full address, and send a small test first.",[38,84,85,88],{},[53,86,87],{},"You suspect the computer is infected",[53,89,90],{},"Use a clean device, move funds only after re-verifying the destination, and stop trusting old copied addresses.",[24,92,94],{"id":93},"what-clipboard-hijacking-actually-is","What clipboard hijacking actually is",[10,96,97],{},"Ledger describes clipboard hijacking as malware that silently replaces a copied crypto address with a malicious one. The point is not to steal your seed phrase directly. The point is to make you authorize a normal-looking transfer to the wrong destination.",[10,99,100],{},"The trick works because many people do one or more of these:",[102,103,104,108,111,114],"ul",{},[105,106,107],"li",{},"trust copy-paste too much;",[105,109,110],{},"compare only the first and last few characters;",[105,112,113],{},"rush a transfer because it is an exchange withdrawal, a payment deadline, or a market move;",[105,115,116],{},"assume the desktop or phone display is the source of truth.",[10,118,119],{},"Ledger's support guidance is blunt here: assume the computer can be compromised and treat the hardware-wallet screen as the source of truth. Coinbase's malware guidance makes the same practical point from the device-security angle: malware can monitor clipboard contents, so users should double-check addresses before sending funds.",[24,121,123],{"id":122},"how-it-is-different-from-address-poisoning","How it is different from address poisoning",[10,125,126],{},"Clipboard hijacking and address poisoning both lead to the wrong address, but the attack path is different.",[32,128,129,145],{},[35,130,131],{},[38,132,133,136,139,142],{},[41,134,135],{},"Threat",[41,137,138],{},"What the attacker changes",[41,140,141],{},"When it happens",[41,143,144],{},"Best defense",[48,146,147,161,175],{},[38,148,149,152,155,158],{},[53,150,151],{},"Clipboard hijacking",[53,153,154],{},"The address you copied and pasted",[53,156,157],{},"Right before or during a transfer on an infected device",[53,159,160],{},"Compare the destination on a trusted wallet screen",[38,162,163,166,169,172],{},[53,164,165],{},"Address poisoning",[53,167,168],{},"Your transaction history with a lookalike address",[53,170,171],{},"Earlier, by planting fake transactions",[53,173,174],{},"Never copy addresses from old history",[38,176,177,180,183,186],{},[53,178,179],{},"QR-code swap or fake app",[53,181,182],{},"The source you scan or trust",[53,184,185],{},"Before you even copy the address",[53,187,188],{},"Use official apps and verify destination details before sending",[10,190,191,192,197,198,202],{},"If you want the transaction-history version of this problem, read ",[193,194,196],"a",{"href":195},"\u002Fguides\u002Faddress-poisoning-scams-crypto-wallet","address poisoning scams",". If you are mainly worried about wallet-draining signatures, read ",[193,199,201],{"href":200},"\u002Fguides\u002Fwallet-approval-scams-and-dangerous-permissions","wallet approval scams and dangerous permissions",".",[24,204,206],{"id":205},"what-the-attack-looks-like-in-real-life","What the attack looks like in real life",[10,208,209],{},"A common pattern is boring:",[211,212,213,216,219,222,225,228],"ol",{},[105,214,215],{},"You copy an exchange deposit address or wallet receive address.",[105,217,218],{},"Malware replaces it with a different address in the clipboard.",[105,220,221],{},"The attacker uses a lookalike address that matches the first and last characters.",[105,223,224],{},"You paste it into the sending wallet or exchange.",[105,226,227],{},"You verify too casually, or not at all.",[105,229,230],{},"The transfer confirms on-chain and cannot be reversed.",[10,232,233],{},"Ledger specifically notes that its app may show an address-mismatch warning when suspicious clipboard behavior is detected. That warning is not something to click through. It is a signal to stop the transaction and check the device for malware.",[24,235,237],{"id":236},"why-hardware-wallet-verification-matters","Why hardware-wallet verification matters",[10,239,240],{},"A hardware wallet does not magically stop you from pasting the wrong address. It helps only if you use the trusted screen correctly.",[10,242,243],{},"Ledger's transaction-verification guidance says to verify the address, amount, and fees on the device because computer and phone displays can be manipulated. Trezor's receive-flow guidance makes the same point: verifying the address on the Trezor device confirms that the address is really yours and not just what the computer is showing.",[10,245,246],{},"That creates a practical split:",[102,248,249,255],{},[105,250,251,254],{},[20,252,253],{},"Ledger and Trezor"," are strongest when you actually compare the address on-device before confirming.",[105,256,257,260],{},[20,258,259],{},"Tangem"," is simpler and mobile-first, but the transfer workflow still depends more on phone hygiene because there is no traditional device screen showing the full address in the same way.",[10,262,263],{},"That does not make Tangem unsafe. It means the buyer tradeoff is different. If clipboard-malware anxiety is one of your main fears, screen-based address verification deserves extra weight in your wallet decision.",[10,265,266,267,271,272,276,277,281],{},"Start with ",[193,268,270],{"href":269},"\u002Fguides\u002Fbest-hardware-wallet-for-beginners","best hardware wallet for beginners",", then compare ",[193,273,275],{"href":274},"\u002Fcomparisons\u002Fledger-vs-trezor","Ledger vs Trezor"," or ",[193,278,280],{"href":279},"\u002Fcomparisons\u002Ftangem-vs-ledger","Tangem vs Ledger"," depending on the setup you are considering.",[24,283,285],{"id":284},"a-safe-transfer-workflow","A safe transfer workflow",[10,287,288],{},"Use this every time you move meaningful crypto:",[290,291,293],"h3",{"id":292},"_1-start-from-the-receiving-side","1. Start from the receiving side",[10,295,296],{},"Open the destination wallet or exchange deposit page fresh. Do not reuse an address copied from a notes app, old email, or previous transfer history.",[290,298,300],{"id":299},"_2-copy-once-then-compare-the-full-address","2. Copy once, then compare the full address",[10,302,303],{},"Do not rely on the first and last characters only. Attackers know people check lazily.",[290,305,307],{"id":306},"_3-verify-on-the-trusted-screen-when-the-wallet-supports-it","3. Verify on the trusted screen when the wallet supports it",[10,309,310],{},"For Ledger or Trezor, show the receive address on the hardware device and compare it there before sending. If the app and the device do not match, stop.",[290,312,314],{"id":313},"_4-send-a-small-test-first","4. Send a small test first",[10,316,317],{},"Ledger recommends this for good reason. A test transaction is cheaper than losing the full transfer to one bad paste.",[290,319,321],{"id":320},"_5-save-verified-addresses-carefully","5. Save verified addresses carefully",[10,323,324],{},"If you use exchange allowlisting or an address book, add the address only after a full verification step. Do not save whatever happened to be in the clipboard during a rushed moment.",[290,326,328],{"id":327},"_6-treat-warnings-as-real-incidents","6. Treat warnings as real incidents",[10,330,331],{},"If the wallet app reports an address mismatch, or if a pasted address changes unexpectedly, assume the device may be compromised until you prove otherwise.",[24,333,335],{"id":334},"what-to-do-if-you-suspect-clipboard-malware","What to do if you suspect clipboard malware",[10,337,338],{},"Do not keep repeating the same transfer attempt from the same device.",[32,340,341,351],{},[35,342,343],{},[38,344,345,348],{},[41,346,347],{},"Step",[41,349,350],{},"Action",[48,352,353,361,369,377,385],{},[38,354,355,358],{},[53,356,357],{},"1",[53,359,360],{},"Cancel the transaction immediately if it has not been broadcast.",[38,362,363,366],{},[53,364,365],{},"2",[53,367,368],{},"Run a full malware scan and update the operating system and security tools.",[38,370,371,374],{},[53,372,373],{},"3",[53,375,376],{},"Stop downloading random files, browser extensions, cracks, or trading tools on that device.",[38,378,379,382],{},[53,380,381],{},"4",[53,383,384],{},"For meaningful balances, prepare a clean device before your next transfer.",[38,386,387,390],{},[53,388,389],{},"5",[53,391,392],{},"If funds may still be at risk, move them only after generating and verifying the destination address again from a trusted wallet flow.",[10,394,395],{},"Coinbase's malware guidance recommends the basic hygiene that still matters most here: keep the system updated, use reputable security software, avoid unverified downloads, and double-check addresses before sending.",[10,397,398],{},"If you think the device itself is no longer trustworthy, the safer move is often to transfer from a clean setup to a fresh wallet whose recovery method you already control. That is especially true if the same machine also stores passwords, exchange sessions, or hot-wallet extensions.",[24,400,402],{"id":401},"who-should-care-most-about-this","Who should care most about this",[10,404,405],{},"This risk matters most if you:",[102,407,408,411,414,417,420],{},[105,409,410],{},"move funds between exchanges and self-custody regularly;",[105,412,413],{},"copy long wallet addresses on a laptop you also use for general browsing or downloads;",[105,415,416],{},"manage larger balances where a single transfer mistake would hurt;",[105,418,419],{},"use hot wallets, browser extensions, or desktop wallets on the same machine;",[105,421,422],{},"rely on fast copy-paste habits instead of slower verification habits.",[10,424,425,426,430,431,435,436,202],{},"If that describes you, also read ",[193,427,429],{"href":428},"\u002Fguides\u002Fmove-crypto-exchange-to-hardware-wallet","how to move crypto from an exchange to a hardware wallet safely",", ",[193,432,434],{"href":433},"\u002Fguides\u002Fcommon-crypto-scams-and-how-to-avoid-them","common crypto scams and how to avoid them",", and ",[193,437,439],{"href":438},"\u002Fguides\u002Ffake-crypto-wallet-apps-and-how-to-avoid-them","fake crypto wallet apps and how to avoid them",[24,441,443],{"id":442},"bottom-line","Bottom line",[10,445,446],{},"Clipboard hijacking is not about breaking crypto. It is about breaking your transfer routine.",[10,448,449],{},"The fix is simple but non-negotiable: open the real destination fresh, compare the full address, verify it on a trusted device screen when possible, and send a small test before you move serious funds. If your system gives you one hint that the pasted address changed unexpectedly, stop treating it like a harmless glitch.",{"title":451,"searchDepth":452,"depth":452,"links":453},"",2,[454,455,456,457,458,459,468,469,470],{"id":26,"depth":452,"text":27},{"id":93,"depth":452,"text":94},{"id":122,"depth":452,"text":123},{"id":205,"depth":452,"text":206},{"id":236,"depth":452,"text":237},{"id":284,"depth":452,"text":285,"children":460},[461,463,464,465,466,467],{"id":292,"depth":462,"text":293},3,{"id":299,"depth":462,"text":300},{"id":306,"depth":462,"text":307},{"id":313,"depth":462,"text":314},{"id":320,"depth":462,"text":321},{"id":327,"depth":462,"text":328},{"id":334,"depth":452,"text":335},{"id":401,"depth":452,"text":402},{"id":442,"depth":452,"text":443},"Learn how clipboard hijacker malware swaps copied wallet addresses, how it differs from address poisoning, and why device-screen verification matters before every crypto transfer.","md",{"publishedAt":474,"updatedAt":474,"sourceNotes":475,"faqs":479},"June 24, 2026",[476,477,478],"We reviewed Ledger support guidance on clipboard hijacking, transaction verification, and trusted-address checks before publishing.","We reviewed Trezor guidance on verifying receive addresses on-device and its address-safety guidance about clipboard hijacking risk.","We reviewed Coinbase consumer-protection guidance on malware that monitors clipboard contents and the recommendation to double-check addresses before sending funds.",[480,483,486],{"question":481,"answer":482},"Does clipboard hijacking mean my hardware wallet was hacked?","No. The usual problem is that malware changed the address on your computer or phone before you confirmed the transfer. A hardware wallet helps only if you compare the address on the trusted device screen before signing.",{"question":484,"answer":485},"Is clipboard hijacking the same as address poisoning?","No. Clipboard hijacking changes the address you paste in real time on an infected device. Address poisoning plants a lookalike address in your transaction history and waits for you to copy the wrong one later.",{"question":487,"answer":488},"Should I move funds if I suspect clipboard malware?","Yes, but only from a clean device and only after verifying the new destination address on a trusted wallet screen. Scanning the device for malware matters too, but do not keep using a system you no longer trust for large transfers.",true,"\u002Fguides\u002Fclipboard-hijacking-crypto-wallet-address",{"title":5,"description":471},"guides\u002Fclipboard-hijacking-crypto-wallet-address","9LvDVfmbGTbS4OBq7pPKTCP-uEQw_S479EiHNLaHTUs",1782273930994]