The swap after Ctrl+C
A clipboard hijacker watches the clipboard and replaces a copied address with the attacker's. CryptoShuffler took 23 BTC this way in 201715; a trojanized Tor Browser with a clipper inside was detected about 16,000 times in 52 countries in 202319. Modern clippers pick a replacement that looks right: Laplas Clipper asks its server for a lookalike of the copied address21,22.
The swap no longer has to happen in the clipboard. In September 2025 malicious versions of
chalk, debug and sixteen other npm packages rewrote addresses inside
web pages and outgoing transactions, choosing the replacement by Levenshtein
distance25.