How does clipboard malware steal crypto during a mobile swap
Clipboard malware steals crypto during a mobile swap by replacing the wallet address you copied with an attacker's address, so you send funds to the wrong destination. This happens because mobile operating systems allow any app to read the clipboard in the background, and malicious apps exploit that permission to swap addresses instantly.
Swap crypto
Live rates · no accountSend exactly to:
This asset needs a memo / tag. Send it with or the exchanger cannot credit your deposit.
You receive about at . Exchange reference .
Status: waiting for your deposit
You send from your own wallet straight to the exchanger — nothing to connect, no account, and you stay on this page throughout. Rates are indicative until a swap is opened.
The swap is carried out by an independent exchanger and the deposit address above is theirs. mad-pepe.vip never holds, receives or controls your funds, has no key to that address, and earns a referral commission. Opening a swap sends your receiving address, IP, browser and timezone to the exchanger for their compliance checks; we store none of it. Check their terms, fees and country restrictions before sending anything.
How the attack works step by step
-
You copy a wallet address. On a phone, you typically long-press an address in your wallet app or an exchange interface, then tap "Copy." That address now sits in the system clipboard - a temporary storage area shared by all apps on the device.
-
A malicious app reads the clipboard. If any app on your phone has background activity permissions or clipboard access (both common on Android, and possible on iOS under certain conditions), it can monitor the clipboard contents. The malware checks whether the copied text looks like a cryptocurrency address - usually a long alphanumeric string starting with a known prefix like "0x" (Ethereum), "1" or "3" (Bitcoin), or "T" (Tron).
-
The malware replaces the address. The moment the malware detects a valid address, it overwrites the clipboard with an address controlled by the attacker. This happens in milliseconds, before you paste the address into the send field.
-
You paste and confirm. Because your wallet app shows the address you just pasted (which now belongs to the attacker), you see a string that looks legitimate. Most users glance at the first few and last few characters, not the entire 40-character hash. The attacker's address often starts with the same characters as the intended address, making the swap harder to spot.
-
The transaction goes to the wrong wallet. You confirm the send, and the funds arrive in the attacker's wallet. The transaction is irreversible on the blockchain.
Why mobile swaps are especially vulnerable
Phones have two traits that make clipboard attacks more effective than on desktops:
-
App sandboxing is weaker. On a desktop, clipboard access is typically restricted to the foreground app. On Android, any app with the
READ_CLIPBOARDpermission (or that runs as a foreground service) can read the clipboard continuously. On iOS, clipboard access is more restricted but still possible if the app is in the foreground and the user has granted clipboard access - common for keyboard apps, photo editors, or "utility" apps. -
Screen size hides the address. A mobile screen shows only a few characters of a wallet address at a time. You cannot easily scan the full address for discrepancies. The attacker's address might differ only in the middle, where your eye does not naturally fall.
How clipboard malware gets onto your phone
The malware typically arrives through:
-
Third-party app stores or sideloaded APKs. Apps that promise free VPNs, wallpaper packs, or "crypto price alerts" often include clipboard-monitoring code.
-
Fake wallet apps that look like legitimate wallets but contain hidden clipboard readers.
-
Keyboard apps that request clipboard access to "predict text" or "improve typing." Some of these apps are known to exfiltrate clipboard data.
-
Trojanized updates to legitimate apps, though this is rarer on official stores.
What does not stop clipboard malware
-
Copying from a different source (exchange, block explorer, friend's message) does not help. The malware reads the clipboard regardless of origin.
-
Copying a shorter address (like a memo ID) is not safer. The malware can target any pattern it recognizes.
-
Using a hardware wallet does not protect you if you still copy the receive address onto your phone.
What does help
-
Manually type the address. This is impractical for most users, but it bypasses the clipboard entirely.
-
Use a wallet that generates a QR code and scan it from your phone's camera. QR codes are not stored in the clipboard.
-
Check the address character by character in a text editor on a separate device before sending. This is tedious but effective.
-
Install apps only from official stores and review permissions. Revoke clipboard access for any app that does not need it.
-
Use a dedicated "swap phone" with no extra apps installed. This reduces the attack surface.
The hub page this belongs to, "Mobile wallet swap safety mistakes to avoid," covers broader errors like using public Wi-Fi, failing to verify transaction details, and relying on unverified dApp browsers. Clipboard malware is one specific mistake in that set - but it is the most common cause of stolen funds during mobile swaps.
Not financial advice. mad-pepe.vip publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.