Subscribe Now
Trending News

Blog Post

RUSSIAN HACKER STOLE BITCOIN WITH A COPY-PASTE TRICK FOR 8 YEARS – AND THE FEDS NEEDED 23 TO CATCH HIM
News

RUSSIAN HACKER STOLE BITCOIN WITH A COPY-PASTE TRICK FOR 8 YEARS – AND THE FEDS NEEDED 23 TO CATCH HIM 

RUSSIAN HACKER STOLE BITCOIN WITH A COPY-PASTE TRICK FOR 8 YEARS – AND THE FEDS NEEDED 23 TO CATCH HIM

Hook: You copy a Bitcoin address. You paste it. You check it. You send. And for the last eight years, a Russian cybercriminal was standing in the middle of that sentence – swapping your address for his, one clipboard at a time, and there was NOTHING you could have seen that would have caught it.

Meet EggJagger. It is the dumbest, most beautiful hack in Bitcoin’s history. And it worked for eight years.

The Trick That Shouldn’t Work

EggJagger is a clipboard hijacker. It sat silently on infected machines – over 15,000 of them worldwide – watching for anything that looks like a cryptocurrency wallet address being copied to the clipboard. The moment you copied a Bitcoin or Ethereum address to pay someone, it swapped it for an address controlled by its operator.

No pop-up. No warning. No change you could notice by looking at the first few characters – because the swap happened BEFORE you pasted. You checked the address you pasted. It looked right. It wasn’t.

CrowdStrike calls the operator SALTY SPIDER. Russian. Patient. And he had a very specific relationship with the money.

The Punchline: He Didn’t Even Spend It

Here’s where this goes from cybercrime report to philosophical insult. CrowdStrike estimates the clipjacking operation pulled in at least $150,000 – 12.1 million rubles. But the STOLEN, NEVER-SPENT portfolio peaked at about 147 million rubles in January 2025: a nominal $1.35 million, or roughly $4 million in real Western purchasing power.

Eight years of stealing people’s money, and the guy mostly just… held it. Sat on it. Watched it. The only drama was a DDoS campaign against a Ukrainian forum the day after Russia’s invasion, and a tantrum against a Russian exchange in 2023 over a personal dispute.

SALTY SPIDER is a collector. You were the collection.

23 Years To Catch A Clipboard

The Sality botnet behind EggJagger has existed since 2003. It survived because it had no central server to seize – infected machines talked to each other in a peer-to-peer mesh, and it spread through USB sticks and network shares like a cold. For 23 years, it was the cockroach of the Russian cyber underworld.

It took CrowdStrike’s Counter Adversary Operations team – working with the FBI, the Justice Department, Defence Criminal Investigative Service and police in Bulgaria, Hungary and Romania – to finally sinkhole the whole thing Monday, isolating every infected machine and cutting the operator off.

Great news, right? Here’s the part they don’t put in the press release: the malware is STILL on those 15,000 machines. The Shadowserver Foundation is calling internet providers to notify victims. You only get notified you were robbed – the money is long gone.

The Lesson They Hope You Don’t Learn

Exchanges, wallets and payment processors all tell you the same thing: "always double-check the address." But a clipboard hijacker makes double-checking USELESS – the address you check is the address the hacker gave you. The trick works because checking happens in the same compromised environment.

The only fix is to verify on a device the attacker can’t touch. A hardware wallet displays the address on its OWN secure screen – not on your infected computer. If the address on your hardware wallet’s screen doesn’t match what your computer shows, you just caught the hack. That’s what self-custody actually means: not "your keys," but your own set of EYES on every transaction.

Stop paying addresses you can only see through a compromised window. Get a hardware wallet – Blockstream Jade shows every address on-device, and it’s at https://loveisbitcoin.com/bull with coupon LOVEISBITCOIN.

So here’s the question: you’ve copy-pasted a Bitcoin address in the last month. How do you know – actually KNOW – it went to the right person?

Previous

RUSSIAN HACKER STOLE BITCOIN WITH A COPY-PASTE TRICK FOR 8 YEARS - AND THE FEDS NEEDED 23 TO CATCH HIM

Related posts

Leave a Reply

Please authenticate to comment:

Required fields are marked *

⚡ Zap This!

Support this content with sats on Nostr

Zap QR

Lightning Address (tap to copy):

✅ Copied!

Or zap via Nostr client:

🟣 Open in Primal