USB Crypto Wallet Malware Spreads via Windows Shortcuts to Steal Keys
Crypto wallet-stealing malware is spreading through USB drives and Windows shortcut files. The worm watches the clipboard for private keys and wallet addresses, then replaces the destination address during a transfer. Because blockchain payments are hard to reverse, Korean investors need stronger USB controls and full-address verification.
Partner picks
Relevant partner links for this story
A lightweight commerce block designed to add monetization without breaking reading flow.
Good fit for Korea-based visitors ready to buy.
View offerWorks well for price-sensitive gadget and desk-tool traffic.
View offerUseful for books, work tools, and international shoppers.
View offerAdvertisement
This module may include affiliate links that earn a commission from qualifying purchases. 크립토데일리

The main risk in this crypto wallet attack is not the wallet app itself but the path users take to move funds. Attackers use shortcut files on USB drives to install a worm on Windows PCs. Once active, it monitors the clipboard for private keys and wallet address patterns. When a user copies a destination address into an exchange or wallet, the malware can replace it with an attacker-controlled address.
USB shortcuts are the entry point
The flow has five steps: USB insertion, LNK shortcut execution, worm installation, clipboard monitoring, and address replacement. A file that looks like a document or folder can trigger a malicious install command. Because it behaves as a worm, it can spread to other USB drives connected to the same PC. No reliable infection count, stolen amount, or attacker-wallet count is fixed at this stage. Still, one exposed private key can put an entire wallet balance at risk, and one successful address swap can redirect the whole transfer.
Impact on Korean investors
Korean users often move between won-linked exchanges, personal wallets, and overseas DeFi services by copying addresses. That habit is exactly what clipboard hijacking targets. The won-denominated loss depends on coin amount, market price, and exchange rate at settlement. Domestic virtual-asset operators can strengthen monitoring, but an on-chain transfer signed from a personal wallet is technically and legally hard to reverse.
The last defense is verification
This threat is likely to persist in smaller repeated attacks against personal PCs and removable storage. Users should disable autorun, avoid unknown shortcuts, compare the full recipient address on a separate screen or hardware wallet, keep Windows patched, and never copy private keys to the clipboard.
Partner picks
Relevant partner links for this story
A lightweight commerce block designed to add monetization without breaking reading flow.
Good fit for Korea-based visitors ready to buy.
View offerWorks well for price-sensitive gadget and desk-tool traffic.
View offerUseful for books, work tools, and international shoppers.
View offerAdvertisement
This module may include affiliate links that earn a commission from qualifying purchases. 크립토데일리
Key points
- Crypto wallet-stealing malware is spreading through USB drives and Windows shortcut files. The worm watches the clipboard for private keys and wallet addresses, then replaces the destination address during a transfer. Because blockchain payments are hard to reverse, Korean investors need stronger USB controls and full-address verification.
- Use the body and FAQ context before acting on this update.
- Compare with related issues inside the category hub.
FAQ
How does the USB malware target crypto wallets?
It uses USB shortcut files to install a worm on Windows PCs, then watches the clipboard for private keys and wallet addresses.
When does the address swap happen?
It can happen when a user copies and pastes a crypto destination address into an exchange or wallet transfer screen.
What should Korean investors check first?
Avoid unknown USB drives and LNK files, verify the full recipient address, and never copy private keys to the clipboard.
Related stories

Bitcoin Holds Near $64,000 as Hormuz Threat Tests US-Iran Talks
Bitcoin regained ground over the weekend and hovered near $64,000 after Friday’s sell-off. Permanent ceasefire talks between the United States and Iran opened in Switzerland, but Iran’s renewed order to close the Strait of Hormuz revived the geopolitical risk the deal was meant to calm. Korean investors now need to track dollar prices, won exchange rates, an

Ethereum Sandwich Bot Jaredfromsubway.eth Drained of $7.5M via Fake Routes
Jaredfromsubway.eth, Ethereum’s largest sandwich bot, lost $7.5 million after it was induced to approve fake trading routes. The attacker used those approvals to drain WETH, USDC and USDT. The loss equals roughly more than 10 billion won on a simple conversion basis. The incident exposes approval risk across MEV bots and DeFi wallets.

비트코인 4일째 약세에 스마트컨트랙트·디파이 코인 낙폭 확대
비트코인이 나흘째 힘을 잃으며 크립토 시장 전반의 위험 회피 심리가 커졌다. 스마트컨트랙트와 디파이 코인은 고베타 자산으로 분류되며 하락장에서 더 큰 매도 압력을 받았다. Strategy의 배당형 우선주 STRC를 둘러싼 불확실성은 레버리지와 유동성 우려를 자극하고 있다.
Partner picks
Relevant partner links for this story
A lightweight commerce block designed to add monetization without breaking reading flow.
Good fit for Korea-based visitors ready to buy.
View offerWorks well for price-sensitive gadget and desk-tool traffic.
View offerUseful for books, work tools, and international shoppers.
View offerAdvertisement
This module may include affiliate links that earn a commission from qualifying purchases. 크립토데일리