Article may be outdated

This article is 2 days old. Some details may have changed since publication.

CoinDesk·3 min read·medium

CrowdStrike and federal authorities dismantle Russian malware that secretly stole crypto for 8 years

S
Shaurya Malwa
CrowdStrike and federal authorities dismantle Russian malware that secretly stole crypto for 8 years
AI Summary

CrowdStrike and federal authorities dismantled a Russian-based malware operation that stole cryptocurrency by replacing wallet addresses on users' clipboards. The malware, known as Sality, successfully exploited the common practice of copying and pasting long wallet addresses for eight years.

Why it matters

This demonstrates the persistent threat of simple, low-tech cyberattacks and the importance of verifying digital transactions in the crypto ecosystem.

Dive DeeperCreate a free account to unlock

The attack it delivered is simple enough that most crypto users are exposed to it. Wallet addresses are long strings nobody types by hand, so people copy and paste them.

Sality's main payload, which CrowdStrike called ‘EggJagger,’ sat on infected machines, watching the clipboard, and when it saw something resembling a bitcoin or ether address, it replaced the copied text with an address belonging to the attacker.

A victim pasting into their wallet and hitting send paid a malicious actor, with no warning and nothing to undo. A defense for users is to check the first and last characters of an address after pasting it, every time.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycryptobusiness

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in