RUSSIAN HACKER STOLE BITCOIN WITH A COPY-PASTE TRICK FOR 8 YEARS – AND THE FEDS NEEDED 23 TO CATCH HIM
Hook: You copy a Bitcoin address. You paste it. You check it. You send. And for the last eight years, a Russian cybercriminal was standing in the middle of that sentence – swapping your address for his, one clipboard at a time, and there was NOTHING you could have seen that would have caught it.
Meet EggJagger. It is the dumbest, most beautiful hack in Bitcoin’s history. And it worked for eight years.
The Trick That Shouldn’t Work
EggJagger is a clipboard hijacker. It sat silently on infected machines – over 15,000 of them worldwide – watching for anything that looks like a cryptocurrency wallet address being copied to the clipboard. The moment you copied a Bitcoin or Ethereum address to pay someone, it swapped it for an address controlled by its operator.
No pop-up. No warning. No change you could notice by looking at the first few characters – because the swap happened BEFORE you pasted. You checked the address you pasted. It looked right. It wasn’t.
CrowdStrike calls the operator SALTY SPIDER. Russian. Patient. And he had a very specific relationship with the money.
The Punchline: He Didn’t Even Spend It
Here’s where this goes from cybercrime report to philosophical insult. CrowdStrike estimates the clipjacking operation pulled in at least $150,000 – 12.1 million rubles. But the STOLEN, NEVER-SPENT portfolio peaked at about 147 million rubles in January 2025: a nominal $1.35 million, or roughly $4 million in real Western purchasing power.
Eight years of stealing people’s money, and the guy mostly just… held it. Sat on it. Watched it. The only drama was a DDoS campaign against a Ukrainian forum the day after Russia’s invasion, and a tantrum against a Russian exchange in 2023 over a personal dispute.
SALTY SPIDER is a collector. You were the collection.
23 Years To Catch A Clipboard
The Sality botnet behind EggJagger has existed since 2003. It survived because it had no central server to seize – infected machines talked to each other in a peer-to-peer mesh, and it spread through USB sticks and network shares like a cold. For 23 years, it was the cockroach of the Russian cyber underworld.
It took CrowdStrike’s Counter Adversary Operations team – working with the FBI, the Justice Department, Defence Criminal Investigative Service and police in Bulgaria, Hungary and Romania – to finally sinkhole the whole thing Monday, isolating every infected machine and cutting the operator off.
Great news, right? Here’s the part they don’t put in the press release: the malware is STILL on those 15,000 machines. The Shadowserver Foundation is calling internet providers to notify victims. You only get notified you were robbed – the money is long gone.
The Lesson They Hope You Don’t Learn
Exchanges, wallets and payment processors all tell you the same thing: "always double-check the address." But a clipboard hijacker makes double-checking USELESS – the address you check is the address the hacker gave you. The trick works because checking happens in the same compromised environment.
The only fix is to verify on a device the attacker can’t touch. A hardware wallet displays the address on its OWN secure screen – not on your infected computer. If the address on your hardware wallet’s screen doesn’t match what your computer shows, you just caught the hack. That’s what self-custody actually means: not "your keys," but your own set of EYES on every transaction.
Stop paying addresses you can only see through a compromised window. Get a hardware wallet – Blockstream Jade shows every address on-device, and it’s at https://loveisbitcoin.com/bull with coupon LOVEISBITCOIN.
So here’s the question: you’ve copy-pasted a Bitcoin address in the last month. How do you know – actually KNOW – it went to the right person?