How clipboard hijackers steal a crypto address during a mobile swap
Clipboard hijackers steal a crypto address by replacing whatever you copied with their own address, usually right after you copy a recipient address and before you paste it into the payment field. On a mobile swap, this works because the clipboard is shared between apps, and many wallets or swap interfaces do not re-verify the pasted address against what you actually intended to send to.
Swap crypto
Live rates · no accountSend exactly to:
This asset needs a memo / tag. Send it with or the exchanger cannot credit your deposit.
You receive about at . Exchange reference .
Status: waiting for your deposit
You send from your own wallet straight to the exchanger — nothing to connect, no account, and you stay on this page throughout. Rates are indicative until a swap is opened.
The swap is carried out by an independent exchanger and the deposit address above is theirs. taponeth.vip never holds, receives or controls your funds, has no key to that address, and earns a referral commission. Opening a swap sends your receiving address, IP, browser and timezone to the exchanger for their compliance checks; we store none of it. Check their terms, fees and country restrictions before sending anything.
The attack does not require access to your phone's files, your wallet's private keys, or even your lock screen. It only needs to read and write the clipboard at the right moment. On Android, any app with clipboard access can read the most recent copied text. On iOS, the system prompts when an app reads the clipboard, but many users tap "Allow" without reading the prompt. Malware, a malicious keyboard, or a compromised "helper" app can all do this silently in the background.
Here is the typical sequence during a mobile swap. You generate a receiving address - say, from an exchange account or a friend's wallet. You tap "Copy." The address sits in the clipboard. The hijacker, which has been watching for anything that looks like a cryptocurrency address, immediately overwrites it with an address the attacker controls. The replacement often looks similar at the start and end - same prefix, same checksum characters - but the middle differs. You switch to your wallet app, paste, and the wallet shows a long string that you glance at for two seconds. You confirm. The swap goes to the attacker.
Several factors make this worse on mobile. Screens are small, so you are less likely to compare the full address character by character. Mobile wallets often show only the first and last few characters of a pasted address, which is exactly the part the hijacker leaves intact. And because you are mid-flow - copying from one app, pasting into another - you are not thinking about the clipboard as a shared, mutable resource. On a desktop, you might have a second window open to check the address. On a phone, you usually do not.
The attacker does not need to know your wallet type or the network. They just need to detect a plausible address format - a 42-character hex string for Ethereum-compatible chains, or a Base58 string for Bitcoin - and swap it. Some hijackers are more targeted: they watch for addresses from specific exchanges or specific token contracts, then replace with an address that matches the same network. This is how a swap can send tokens to the wrong network and the wrong recipient at once, though the two failures are separate.
Your best defense is not to rely on the clipboard at all. Type the address manually if it is short, or better, use a contact book inside your wallet where you have saved the address once and verified it carefully. If you must copy and paste, paste into a notes app first, then read the full address aloud or compare it against the source in a split view. Do that before you paste into the swap field. Also, clear your clipboard after every paste - on Android, the clipboard history can persist and be read later; on iOS, the paste prompt shows you exactly what is being pasted, so read it.
You can also use a QR code instead of copying text. Scan the QR from the source screen directly into the wallet. The QR contains the same address, but the scanner reads it as an image, not through the clipboard. This removes the hijack vector entirely, provided the QR code itself is not tampered with - which would require the source screen to be compromised, a different problem.
The broader lesson is that a mobile swap is a chain of small trust decisions: you trust the wallet app, the network, the exchanger, and the clipboard. The clipboard is the weakest link because it is invisible and shared. If you are doing a swap and something feels off - the pasted address looks slightly different, or the wallet warns about a mismatch - stop and start over. Do not "fix" the address manually.
For a fuller list of what else can go wrong when moving tokens on a phone, the hub page on mobile wallet swap mistakes to avoid covers the other common failure points, like selecting the wrong network or misreading a confirmation screen. This clipboard problem is one of the few that does not require you to make an error - the error is made for you.
Not financial advice. taponeth.vip publishes market data and general information about THE AMERICA PARTY. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.