mad-pepe.vip

How does clipboard malware steal crypto during a mobile swap

Clipboard malware steals crypto during a mobile swap by replacing the wallet address you copied with an attacker's address, so you send funds to the wrong destination. This happens because mobile operating systems allow any app to read the clipboard in the background, and malicious apps exploit that permission to swap addresses instantly.

Swap crypto

Live rates · no account
0

You send from your own wallet straight to the exchanger — nothing to connect, no account, and you stay on this page throughout. Rates are indicative until a swap is opened.

The swap is carried out by an independent exchanger and the deposit address above is theirs. mad-pepe.vip never holds, receives or controls your funds, has no key to that address, and earns a referral commission. Opening a swap sends your receiving address, IP, browser and timezone to the exchanger for their compliance checks; we store none of it. Check their terms, fees and country restrictions before sending anything.

How the attack works step by step

  1. You copy a wallet address. On a phone, you typically long-press an address in your wallet app or an exchange interface, then tap "Copy." That address now sits in the system clipboard - a temporary storage area shared by all apps on the device.

  2. A malicious app reads the clipboard. If any app on your phone has background activity permissions or clipboard access (both common on Android, and possible on iOS under certain conditions), it can monitor the clipboard contents. The malware checks whether the copied text looks like a cryptocurrency address - usually a long alphanumeric string starting with a known prefix like "0x" (Ethereum), "1" or "3" (Bitcoin), or "T" (Tron).

  3. The malware replaces the address. The moment the malware detects a valid address, it overwrites the clipboard with an address controlled by the attacker. This happens in milliseconds, before you paste the address into the send field.

  4. You paste and confirm. Because your wallet app shows the address you just pasted (which now belongs to the attacker), you see a string that looks legitimate. Most users glance at the first few and last few characters, not the entire 40-character hash. The attacker's address often starts with the same characters as the intended address, making the swap harder to spot.

  5. The transaction goes to the wrong wallet. You confirm the send, and the funds arrive in the attacker's wallet. The transaction is irreversible on the blockchain.

Why mobile swaps are especially vulnerable

Phones have two traits that make clipboard attacks more effective than on desktops:

How clipboard malware gets onto your phone

The malware typically arrives through:

What does not stop clipboard malware

What does help

The hub page this belongs to, "Mobile wallet swap safety mistakes to avoid," covers broader errors like using public Wi-Fi, failing to verify transaction details, and relying on unverified dApp browsers. Clipboard malware is one specific mistake in that set - but it is the most common cause of stolen funds during mobile swaps.

Not financial advice. mad-pepe.vip publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.

Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.

Back to trezor