The clipboard swapper
The only adversary here who is already inside, and the only one that verification does not help against.
- What they want
- A payment sent to their address instead of the intended one, by replacing what you copied with something that looks similar.
- How they earn
- Whole payments, occasionally. The approach costs nothing to run against many machines at once, so a low success rate is still profitable.
- What it costs them
- Nothing per target. The software watches for anything address shaped and substitutes.
- How you meet them
- Something already running on your machine, installed alongside something else you wanted. Frequently the thing that promised to make Tor faster or easier.
- What gives them away
- The address in the field is not the address you copied. That is the only signal, and it is completely reliable if you look.
- What stops them
- Reading what actually landed in the send field before confirming, every time. And not installing convenience software in this area at all.
Why this one is different
Every other adversary in the register is defeated by verification. This one is not, because verification establishes that the destination you reached is genuine and says nothing about what your own machine did with a string afterwards.
It also inverts the usual advice about reading addresses. Elsewhere on this site the guidance is to compare the middle, because forgeries match the recognisable ends. Here the substitution is wholesale, so checking the first and last several characters catches it immediately. This is the one place where the quick check is the right check.
Where it comes from
- Anything promising faster Tor. There is no such product and the category is entirely made of this.
- Repackaged browser bundles. Software named similarly, distributed anywhere other than the project itself.
- Convenience wallets and helpers. Tools that offer to simplify the awkward parts, which is exactly where the awkwardness was doing work.
- Ordinary unrelated software. It does not have to arrive through this activity at all, which is why it reaches people who are careful about everything on this list.
The check that catches it
Before confirming any payment, look at the address in the field and compare the first and last several characters against the source. Not the middle, the ends, because a swap replaces the whole string rather than resembling it. It takes about three seconds and it is the only thing standing between this attack and a completed payment.
The same applies to an address you paste into the browser. If what appears in the bar is not what you copied, stop and treat the machine as the problem rather than the page.