What is clipboard hijacking?

In this article, you will learn what clipboard hijacking is and why it can be dangerous — especially when sending crypto. You will learn how this attack works, what the risks are, and how you can easily protect yourself. We also explain what you should do if you suspect you have become a victim.

What is clipboard hijacking?

Clipboard hijacking is a form of malware that monitors what you copy. Suppose you copy a wallet address to send crypto. Malware on your device can secretly replace that address with an attacker's wallet address. If you then execute the transaction without properly checking the address, your crypto will end up at the wrong address.

This attack is difficult to spot because wallet addresses often consist of long strings of characters. As a result, you usually only notice it when it is too late.

How does clipboard hijacking work?

Clipboard hijacking usually works via malware installed on your device. This can happen through:

  • Phishing emails with links to fake websites.
  • Malicious software or browser extensions.
  • Websites that automatically modify copied data via scripts.
  • Apps or extensions with access to your clipboard.

Once the malware is active, it monitors your clipboard. For example, if you copy a wallet address, it is automatically replaced by an address owned by the attacker — without you seeing any visible change.

Why is it dangerous?

  • You could send crypto to the wrong (malicious) address.
  • You often only notice it afterward.
  • Other sensitive data can also be copied or modified.
  • Blockchain transactions are irreversible.

How can you protect yourself?

You can easily reduce the risk of clipboard hijacking by keeping a few things in mind:

  1. Update your software regularly
    Install updates for your operating system, apps, and browser as soon as they are available.
  2. Use good antivirus software
    Choose reliable antivirus or antimalware programs and run scans regularly.
  3. Do not click on links or attachments indiscriminately
    Do not open suspicious emails, links, or downloads from unknown sources.
  4. Check what you paste
    Always compare the pasted wallet address with the original one. Pay special attention to the first and last four characters.
  5. Use a password manager
    This fills in your details automatically, so you do not have to copy them to your clipboard.
  6. Clear your clipboard regularly
    After use, copy something harmless (like a space) to overwrite old data.
  7. Use Two-Factor Authentication (2FA)
    This provides extra security for your account, even if someone manages to obtain your login details.
Tip: At Bitvavo, use the address book to verify wallet addresses in advance. This prevents you from sending to an incorrect or modified address.

What should you do if you suspect an attack?

Do you think you are a victim of clipboard hijacking? Follow these steps:

1. Scan your device for malware
Use a reliable antivirus or antimalware program to fully scan your device and remove malicious software. Also open your Task Manager (Windows) or Activity Monitor (Mac) and check if there are any unknown or suspicious processes active that you do not recognize.

2. Clear your clipboard
This prevents old, manipulated data from being pasted again.

  • On Windows: Go to Settings System Clipboard and click "Clear clipboard data".
  • On Mac: Open the Terminal app, type pbcopy , and press Enter. Or copy something harmless, like a space, to manually overwrite it.

3. Check your accounts
Log in to your Bitvavo account, your email, and your banking environment. Check if anything suspicious has happened, such as unknown logins or transactions.

4. Change your passwords
If you have copied sensitive information, it is wise to change your passwords. Choose strong, unique passwords and preferably use a password manager.

5. Maintain the security of your device
Keep all software up to date, use antivirus software with real-time protection, and enable 2FA where possible.

6. Contact Bitvavo
Has crypto been sent to a wrong address and do you suspect fraud? Contact our fraud team immediately via fraud@bitvavo.com. Also view our support page on safety and fraud for more information:

support.bitvavo.com/hc/en-us/categories/21897390840465-Fraud-account-safety

Warning: Blockchain transactions are final. Acting quickly increases the chance that we can support you with further investigation.
 

Frequently Asked Questions (FAQ)

What is the clipboard exactly?

The clipboard is a temporary storage area on your device. Everything you copy — such as text or wallet addresses — ends up here until you paste it somewhere or copy something else.

How do I recognize clipboard hijacking?

You paste an address that does not match what you copied, or you see unexpected transactions or suspicious processes on your device. These are signs of clipboard hijacking.

What if I sent crypto to the wrong address?

Blockchain transactions are irreversible. Contact the Bitvavo fraud team as soon as possible via fraud@bitvavo.com. We can help you with the next steps.

Still need help?

Our AI assistant Vavo can answer your questions instantly, 24/7.

Chat with Vavo