Skip to main content

How to Protect Yourself from Clipboard Hijacking

Clipboard hijacking silently replaces copied crypto addresses. Learn how to spot it and protect your account.

Clipboard hijacking is a type of malware that silently replaces a crypto address you've copied with the attacker's address. Because the substitution happens instantly and the replaced address can look similar to the original, most users don't notice until funds are already sent — and crypto transactions are irreversible.

How to spot it

After pasting a withdrawal address, compare it character by character against the original. Don't rely only on the first and last few characters — some advanced clipboard hijackers generate replacement addresses that deliberately match the beginning and end of the original, targeting users who only do a partial check. If the pasted address differs from what you copied in any way, do not proceed. Close the browser or app immediately.

How to protect yourself

1. Always verify the full address after pasting
Never assume the pasted address is correct. Compare the entire address against the source every time, especially before large transactions.

2. Enable the Withdrawal Whitelist
The Withdrawal Whitelist restricts your account to only send funds to pre-approved addresses. Even if malware replaces your clipboard, the transaction will be blocked if the substituted address isn't on your whitelist.

3. Clean your device
If you suspect your device is infected:

  • Uninstall any recently installed apps or browser extensions you don't recognise

  • Run a full scan with a reputable antivirus tool

  • Avoid using browser-based wallets or exchange sites until the device is confirmed clean

  • Consider completing sensitive transactions on a separate, trusted device

Did this answer your question?