Microsoft Warns of a USB Worm That Hijacks Crypto Wallets
Microsoft is warning crypto users about a nasty piece of malware. A worm it calls CryptoBandits spreads through USB drives, watches your clipboard, and silently swaps in the attacker's wallet address when you go to send funds. You think you are paying yourself. You are paying a thief.
This is a clipboard hijacker, one of the oldest tricks in crypto crime, but with sharper teeth. Microsoft says the malware has been spreading since February, and it now behaves more like a backdoor, exfiltrating data over the Tor network to hide the attacker. It targets Windows users and the seed phrases and private keys they copy and paste.
The method is simple and effective. The worm checks the Windows clipboard about every 500 milliseconds. If it sees a seed phrase or private key, it steals it and ships it out over Tor. If it sees a crypto address you copied to send a payment, it replaces it with the attacker's address before you paste, so the money goes to them with no visible warning. It spreads by infecting USB drives, swapping ordinary files for malicious shortcuts with the same names.
This is a user-safety story more than a market one, and a reminder of crypto's oldest weakness. Self-custody puts you in control, which also means a single copied-and-pasted line can drain a wallet with no bank to call and no reversal. As crypto adoption widens, these attacks scale with it, and clipboard swaps are devastating precisely because they look like nothing went wrong.
The fix is mostly hygiene. Microsoft recommends disabling AutoRun, blocking shortcut execution on USB media, and being careful with unknown drives. For users, the practical rules are old but still right: always verify the full address after pasting, use a hardware wallet, and never copy a seed phrase onto a connected machine. Boring habits prevent the worst losses.
So the threat is not some exotic exploit, it is a worm on a USB stick quietly editing what you paste. Microsoft flagged it, the fixes are simple, and the lesson is the same as always in crypto. Check the address twice. There is no undo button.
Microsoft Warns of a USB Worm That Hijacks Crypto Wallets
Microsoft is warning crypto users about a nasty piece of malware. A worm it calls CryptoBandits spreads through USB drives, watches your clipboard, and silently swaps in the attacker's wallet address when you go to send funds.
Sources
https://www.coindesk.com/tech/2026/06/19/microsoft-found-malware-that-hijacks-crypto-wallets-and-spreads-through-usb-sticks | https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/ | https://crypto.news/microsoft-warns-crypto-clipper-now-acts-like-backdoor/ | https://thenextweb.com/news/microsoft-crypto-clipper-usb-malware-tor-cryptocurrency-theft