Clipboard Hijacking
Clipboard hijacking is a malware technique that silently watches your computer's or phone's clipboard and, when it detects a copied cryptocurrency address, replaces it with an attacker's address. Because sending crypto almost always involves copying and pasting an address, a successful swap sends your funds to the thief while everything else about the transaction looks normal.
A typical incident: a user copies their exchange deposit address to withdraw bitcoin from another platform. Malware on their machine recognizes the address format, substitutes a similar-looking attacker address in the clipboard, and the user pastes and confirms without noticing. Some clipper malware maintains large pools of addresses so the substitute even shares the first characters with the original, defeating a quick glance. The malware usually arrives bundled with pirated software, fake wallet apps, or malicious browser extensions.
The defense is verification at the moment of sending: compare the pasted address against the source character by character, or at least check several characters in the middle rather than only the ends. Hardware wallets help because the true destination is shown on the device's own screen, which malware on the computer cannot alter. Sending a small test amount before a large transfer adds another safety net. A common misconception is that careful typing avoids the risk; the substitution happens after you copy, so only checking the pasted result catches it.