Wednesday 5 January 2022

Heads up and be safe: I just lost BTC because of Malware that highjacks my clipboard [Windows]

I just lost a significant amount of BTC (to me at least, I can only save ~100$/month). I had my last BTC (sats, really) purchases sitting in my exchange and wanted to move them to my (software) wallet that I use on my phone. So I copied/pasted it the address on a secure notepad app that syncs with PC, then checked that the address shown on my PC matched the wallet address. It did, so that's cool.

So on the PC I copied/pasted it on the address box for the withdrawal at my exchange, it was shown as a valid address and I proceeded with the transaction. WRONG!

I sat there waiting for my funds to appear on my wallet but they never did. Transaction was shown as completed on the exchange and then I got alarmed. Started to write an email to my exchange's support team and then it clicked.

I wanted to say that the destination address was 'X' but somehow it was being shown as 'Y' on the transaction history. But every time I tried to paste my address it was changing right before my eyes. So my email was looking like <<This is mi destination address: 'Y' // This is the address shown on the transacion history: 'Y'>>. Now, my notepad app was clearly showing that the adddress I was trying to copy was most definitely not 'Y', so something was up.

Anyway, at that point I deleted the email, no need to bother some support dude because of something that was looking more and more like a royal fuck up.

And then there it is, there was some malware on my PC that was actively seeking BTC addresses and switching them to something similar but a different address alltoghether from whoever scammer made the damned thing. I clearly fucked up by not realizing that, and now's too late.

Malwarebytes was quick to find and delete the thing and now the computer's clean again (just like my exchange account, haha. FUCK.)

Be safe out there and double check or triple check everything when doing a transaction. I didn't realize at the time so I'm an idiot, but maybe you won't have to be.

---

TL;DR

There's malware out there reading your clipboard to find BTC addresses, and when you try to copy/paste it will paste a similar address from the scammer. I didn't realize so I'm an idiot, but maybe you won't have to be.



Submitted January 05, 2022 at 08:14PM by _Rafs https://bit.ly/3JMcypZ

No comments :

Post a Comment