---
content_id: 22
content_type: evergreen-answer
priority: P1
intent: safety
cluster: security-scams
language: en
title: "What Is Clipboard Hijacking in Crypto and How Do You Prevent It?"
slug: clipboard-hijacking-crypto-prevention
canonical: https://wallet.terenval.com/answers/clipboard-hijacking-crypto-prevention/
primary_query: "crypto clipboard hijacking how to prevent"
last_reviewed: 2026-10-05
publisher: Terenval
---

# What Is Clipboard Hijacking in Crypto and How Do You Prevent It?

## Direct answer

Clipboard hijacking happens when malicious software monitors copied data, detects a crypto address and replaces it with an attacker-controlled address. The transaction you sign can be technically valid while paying the wrong recipient. Reduce the risk by using a clean device, installing wallets from verified sources and comparing the pasted destination with the trusted original before signing. For a large transfer, send a small test amount and verify the destination again before the final payment.

## Key takeaways

- Copy/paste convenience does not prove the pasted address is unchanged.
- The wallet cannot reverse a valid confirmed payment to an attacker address.
- Check the destination after pasting, not only before copying.
- Device security reduces risk but does not replace transaction-time verification.
- If copied addresses unexpectedly change, stop using that device for crypto until it is investigated.

## How clipboard malware works

Malware can watch the system clipboard for strings that resemble Bitcoin or EVM addresses. When it detects one, it substitutes an attacker address, sometimes chosen to resemble the original at the beginning or end.

The user then pastes the substituted value into a wallet or exchange and signs it. From the blockchain's perspective, the signed transaction correctly authorizes the attacker-controlled destination.

## A safer copy-and-paste workflow

1. Obtain the destination from a trusted source.
2. Copy it once.
3. Paste it into the wallet.
4. Compare the pasted value with the original source, including distinctive middle characters for high-value transfers.
5. Confirm the blockchain network separately.
6. For a new or high-value route, send a test amount.
7. Re-check the destination again before the main transfer.

If the address changes after copying, stop. Do not keep retrying with meaningful funds until the device has been checked.

## QR codes and address books

A QR code can reduce typing and copy errors, but a QR code from an attacker can still encode a malicious destination. A trusted address book can reduce repeated clipboard exposure, but the address must be verified carefully when it is first saved.

Hardware wallets can provide a separate trusted display for some transactions, but the user still needs to read and verify what the device displays.

## Clipboard hijacking vs address poisoning

Clipboard hijacking compromises the copy/paste path on your device. Address poisoning tries to place a lookalike address into transaction history so you voluntarily copy the wrong one. Both attacks exploit address complexity and both are mitigated by independent recipient verification.

## If you suspect infection

Stop signing transactions on the affected device. Review installed software and browser extensions, update the operating system and run reputable security checks. If the seed phrase or private key may also have been exposed, treat the wallet as compromised and migrate assets to fresh recovery material on a clean device rather than only cleaning the clipboard malware.

## How this works in Terenval Wallet

Terenval Wallet's transaction review is the final place to compare the selected network, amount and recipient before approval. The wallet can show the destination it is about to sign, but it cannot know whether a substituted address is the human recipient you intended.

Use the official Terenval Wallet origin, keep the device clean and independently verify pasted addresses before approving significant transfers.

## Frequently asked questions

### Is checking the first and last four characters enough?

It is better than no check, but targeted lookalike addresses can match visible edges. For large transfers, compare more of the address or use another trusted verification channel.

### Can antivirus completely prevent clipboard hijacking?

No security tool is perfect. Device protection lowers risk, while transaction-time address verification remains essential.

### What if the pasted address keeps changing?

Stop crypto activity on that device and investigate it as potentially compromised before signing anything else.

## Sources

- https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/clipboard-hacking/
- https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/address-poisoning-scams/
- https://support.metamask.io/configure/accounts/how-to-view-your-account-details-and-public-address/

## Editorial review

Published by Terenval. Technical review: Terenval Wallet team. Last reviewed: 2026-10-05.

## Related Terenval Answers

- [How Can You Tell a Fake Crypto Wallet App from a Real One?](https://wallet.terenval.com/answers/how-to-tell-fake-crypto-wallet-app-from-real/)
- [What Is Address Poisoning and How Can It Trick Crypto Wallet Users?](https://wallet.terenval.com/answers/address-poisoning-crypto-wallet-users/)
- [How Do Token Approval Scams Drain Crypto Wallets?](https://wallet.terenval.com/answers/token-approval-scams-drain-wallets/)
- [How Do Fake Crypto Wallet Support Scams Work?](https://wallet.terenval.com/answers/fake-crypto-wallet-support-scams/)

Editorial policy: https://wallet.terenval.com/editorial-policy/

Official article: https://wallet.terenval.com/answers/clipboard-hijacking-crypto-prevention/
