THE MALWARE WATCHED YOUR CLIPBOARD AND SWAPPED THE ADDRESS BEFORE YOU PASTED IT — EIGHT YEARS, 15,000 MACHINES — THE SCREEN ON YOUR HARDWARE WALLET IS THE ONLY ONE THAT CHECKS
Here is how they took the coins, and it has nothing to do with breaking anything. A program called EggJagger sat quietly on the machine and watched the clipboard, the little bit of memory that holds whatever you last copied. You copy an address. You move to the send box. You paste. In the space between those two actions it swapped the address for one of its own. What appeared on screen was a long string that began and ended about how you expected, because starting and ending characters are how most people check an address, and the middle belonged to somebody else.
Eight years of that, on more than 15,000 machines, inside a botnet that has been running since 2003. The confirmed haul from that payload is small next to the headlines these stories usually carry, about 12.1 million rubles, near $150,000, with an unspent pile that peaked around $1.35 million in January 2025. This week the Justice Department, the FBI, the Defense Criminal Investigative Service, CrowdStrike and police in Bulgaria, Hungary and Romania shut it down. The elegant part was the method: the machines found each other peer to peer, so CrowdStrike fed the network bad neighbors, quietly replacing real peers with dead ends until the thing was talking to nobody.
The lesson is older than the malware and it is free. A screen you do not control is not a source of truth. A hardware wallet carries its own small screen for exactly this reason, and it shows the address the transaction will actually pay, drawn from a device that never trusted your computer in the first place. Checking four characters at the front and four at the back of a line on a monitor is not verification. It is a habit, and the people who wrote EggJagger studied that habit and built a business on it.
Read the whole address off the device. Every time. Technologist.
Eight years of that, on more than 15,000 machines, inside a botnet that has been running since 2003. The confirmed haul from that payload is small next to the headlines these stories usually carry, about 12.1 million rubles, near $150,000, with an unspent pile that peaked around $1.35 million in January 2025. This week the Justice Department, the FBI, the Defense Criminal Investigative Service, CrowdStrike and police in Bulgaria, Hungary and Romania shut it down. The elegant part was the method: the machines found each other peer to peer, so CrowdStrike fed the network bad neighbors, quietly replacing real peers with dead ends until the thing was talking to nobody.
The lesson is older than the malware and it is free. A screen you do not control is not a source of truth. A hardware wallet carries its own small screen for exactly this reason, and it shows the address the transaction will actually pay, drawn from a device that never trusted your computer in the first place. Checking four characters at the front and four at the back of a line on a monitor is not verification. It is a habit, and the people who wrote EggJagger studied that habit and built a business on it.
Read the whole address off the device. Every time. Technologist.
DECRYPT · Wed Sep 2 · + BLEEPINGCOMPUTER Sep 2 · + THE REGISTER Sep 2 · + HELP NET SECURITY Sep 2 · DOJ / FBI / CrowdStrike announcement · + COINDESK (LATER) Wed Sep 2