Terenval Answers · P1 safety · Русская версия

What Is Clipboard Hijacking in Crypto and How Do You Prevent It?

Clipboard hijacking is malware-assisted address substitution. You copy the correct destination, but the device replaces it with an attacker-controlled address before you paste or send.

Last reviewed: 2026-10-05.

Editorial & technical review
Published by Terenval
Technical review: Terenval Wallet team
Editorial policy
Direct answer: Clipboard hijacking happens when malicious software monitors copied data, detects a crypto address and replaces it with an attacker-controlled address. The transaction you sign can be technically valid while paying the wrong recipient. Reduce the risk by using a clean device, installing wallets from verified sources and comparing the pasted destination with the trusted original before signing. For a large transfer, send a small test amount and verify the destination again before the final payment.

Key takeaways

How clipboard malware works

Malware can watch the system clipboard for strings that resemble Bitcoin or EVM addresses. When it detects one, it substitutes an attacker address, sometimes chosen to resemble the original at the beginning or end.

The user then pastes the substituted value into a wallet or exchange and signs it. From the blockchain's perspective, the signed transaction correctly authorizes the attacker-controlled destination.

A safer copy-and-paste workflow

  1. Obtain the destination from a trusted source.
  2. Copy it once.
  3. Paste it into the wallet.
  4. Compare the pasted value with the original source, including distinctive middle characters for high-value transfers.
  5. Confirm the blockchain network separately.
  6. For a new or high-value route, send a test amount.
  7. Re-check the destination again before the main transfer.

If the address changes after copying, stop. Do not keep retrying with meaningful funds until the device has been checked.

QR codes and address books

A QR code can reduce typing and copy errors, but a QR code from an attacker can still encode a malicious destination. A trusted address book can reduce repeated clipboard exposure, but the address must be verified carefully when it is first saved.

Hardware wallets can provide a separate trusted display for some transactions, but the user still needs to read and verify what the device displays.

Clipboard hijacking vs address poisoning

Clipboard hijacking compromises the copy/paste path on your device. Address poisoning tries to place a lookalike address into transaction history so you voluntarily copy the wrong one. Both attacks exploit address complexity and both are mitigated by independent recipient verification.

If you suspect infection

Stop signing transactions on the affected device. Review installed software and browser extensions, update the operating system and run reputable security checks. If the seed phrase or private key may also have been exposed, treat the wallet as compromised and migrate assets to fresh recovery material on a clean device rather than only cleaning the clipboard malware.

How this works in Terenval Wallet

Terenval Wallet's transaction review is the final place to compare the selected network, amount and recipient before approval. The wallet can show the destination it is about to sign, but it cannot know whether a substituted address is the human recipient you intended.

Use the official Terenval Wallet origin, keep the device clean and independently verify pasted addresses before approving significant transfers.

Official pages: Supported networks · Security

Open Terenval Wallet

Frequently asked questions

Is checking the first and last four characters enough?

It is better than no check, but targeted lookalike addresses can match visible edges. For large transfers, compare more of the address or use another trusted verification channel.

Can antivirus completely prevent clipboard hijacking?

No security tool is perfect. Device protection lowers risk, while transaction-time address verification remains essential.

What if the pasted address keeps changing?

Stop crypto activity on that device and investigate it as potentially compromised before signing anything else.

Related Terenval Answers

Primary and authoritative sources

Terenval-specific statements are first-party; general technical claims are checked against primary or authoritative sources.