Monday, June 22, 2026HomeRSS
비트코인$103,420▲ 1.24%나스닥18,642▲ 0.41%S&P 5005,430▲ 0.33%코스피2,704▼ 0.22%원/달러1,386.4▲ 3.10$2,418▲ 0.55%
비트코인·이더리움·디파이를 매일 쉽게
crypto

USB Crypto Wallet Malware Spreads via Windows Shortcuts to Steal Keys

Crypto wallet-stealing malware is spreading through USB drives and Windows shortcut files. The worm watches the clipboard for private keys and wallet addresses, then replaces the destination address during a transfer. Because blockchain payments are hard to reverse, Korean investors need stronger USB controls and full-address verification.

Partner picks

Relevant partner links for this story

A lightweight commerce block designed to add monetization without breaking reading flow.

Advertisement

This module may include affiliate links that earn a commission from qualifying purchases. 크립토데일리

USB Crypto Wallet Malware Spreads via Windows Shortcuts to Steal Keys

The main risk in this crypto wallet attack is not the wallet app itself but the path users take to move funds. Attackers use shortcut files on USB drives to install a worm on Windows PCs. Once active, it monitors the clipboard for private keys and wallet address patterns. When a user copies a destination address into an exchange or wallet, the malware can replace it with an attacker-controlled address.

USB shortcuts are the entry point

The flow has five steps: USB insertion, LNK shortcut execution, worm installation, clipboard monitoring, and address replacement. A file that looks like a document or folder can trigger a malicious install command. Because it behaves as a worm, it can spread to other USB drives connected to the same PC. No reliable infection count, stolen amount, or attacker-wallet count is fixed at this stage. Still, one exposed private key can put an entire wallet balance at risk, and one successful address swap can redirect the whole transfer.

Impact on Korean investors

Korean users often move between won-linked exchanges, personal wallets, and overseas DeFi services by copying addresses. That habit is exactly what clipboard hijacking targets. The won-denominated loss depends on coin amount, market price, and exchange rate at settlement. Domestic virtual-asset operators can strengthen monitoring, but an on-chain transfer signed from a personal wallet is technically and legally hard to reverse.

The last defense is verification

This threat is likely to persist in smaller repeated attacks against personal PCs and removable storage. Users should disable autorun, avoid unknown shortcuts, compare the full recipient address on a separate screen or hardware wallet, keep Windows patched, and never copy private keys to the clipboard.

Partner picks

Relevant partner links for this story

A lightweight commerce block designed to add monetization without breaking reading flow.

Advertisement

This module may include affiliate links that earn a commission from qualifying purchases. 크립토데일리

Key points

  • Crypto wallet-stealing malware is spreading through USB drives and Windows shortcut files. The worm watches the clipboard for private keys and wallet addresses, then replaces the destination address during a transfer. Because blockchain payments are hard to reverse, Korean investors need stronger USB controls and full-address verification.
  • Use the body and FAQ context before acting on this update.
  • Compare with related issues inside the category hub.
Category hubLatest storiesSitemap

FAQ

How does the USB malware target crypto wallets?

It uses USB shortcut files to install a worm on Windows PCs, then watches the clipboard for private keys and wallet addresses.

When does the address swap happen?

It can happen when a user copies and pastes a crypto destination address into an exchange or wallet transfer screen.

What should Korean investors check first?

Avoid unknown USB drives and LNK files, verify the full recipient address, and never copy private keys to the clipboard.

Related stories

Partner picks

Relevant partner links for this story

A lightweight commerce block designed to add monetization without breaking reading flow.

Advertisement

This module may include affiliate links that earn a commission from qualifying purchases. 크립토데일리

Continue your research path

Use category and latest hubs to deepen context and compare multiple sources in one session.

Explore this categoryRSSllms.txt