USB加密货币钱包窃取恶意软件扩散,Windows快捷方式诱导安装蠕虫并瞄准私钥与转账地址
一种通过USB扩散的加密货币钱包窃取恶意软件正在利用Windows快捷方式作为入口。蠕虫会监控剪贴板中的私钥和钱包地址,并在转账时替换收款地址。链上交易确认后难以撤回,韩国投资者需要加强USB管控和完整地址核验。
Partner picks
Relevant partner links for this story
A lightweight commerce block designed to add monetization without breaking reading flow.
Good fit for Korea-based visitors ready to buy.
View offerWorks well for price-sensitive gadget and desk-tool traffic.
View offerUseful for books, work tools, and international shoppers.
View offerAdvertisement
This module may include affiliate links that earn a commission from qualifying purchases. 크립토데일리

这类加密货币钱包窃取恶意软件的关键风险,不在于直接攻破钱包应用,而在于接管用户的转账路径。攻击者把USB中的快捷方式文件伪装成普通文件或文件夹,诱导Windows PC执行蠕虫安装。感染后,恶意程序监控剪贴板中的私钥和钱包地址模式;当用户把地址复制到交易所或钱包页面时,目的地址可能被替换为攻击者钱包。
USB快捷方式成为入口
攻击链可分为5步:插入USB、执行LNK快捷方式、安装蠕虫、监控剪贴板、替换地址。由于具备蠕虫特征,它还可能复制到连接同一电脑的其他USB。当前无法确定感染数量、被盗金额和攻击者钱包数量。但只要一个私钥泄露,整个钱包余额就会面临风险;一次地址替换成功,也可能让整笔转账流向错误地址。
对韩国投资者的影响
韩国用户经常在韩元出入金交易所、个人钱包和海外DeFi之间复制地址。这个习惯正是剪贴板劫持的目标。韩元计价损失由币种数量、成交价格和汇率决定。即便本地虚拟资产平台加强异常交易监测,从个人钱包签名发出的链上转账仍很难在技术和制度上撤回。
最后的防线是核验
投资者应关闭USB自动运行,不打开未知快捷方式,在转账前用硬件钱包或另一屏幕核对完整地址,并避免把私钥复制到剪贴板。系统补丁和杀毒更新也应作为基本流程。
Partner picks
Relevant partner links for this story
A lightweight commerce block designed to add monetization without breaking reading flow.
Good fit for Korea-based visitors ready to buy.
View offerWorks well for price-sensitive gadget and desk-tool traffic.
View offerUseful for books, work tools, and international shoppers.
View offerAdvertisement
This module may include affiliate links that earn a commission from qualifying purchases. 크립토데일리
Key points
- 一种通过USB扩散的加密货币钱包窃取恶意软件正在利用Windows快捷方式作为入口。蠕虫会监控剪贴板中的私钥和钱包地址,并在转账时替换收款地址。链上交易确认后难以撤回,韩国投资者需要加强USB管控和完整地址核验。
- Use the body and FAQ context before acting on this update.
- Compare with related issues inside the category hub.
常见问题
USB恶意软件如何攻击加密钱包?
它通过USB快捷方式安装蠕虫,并在Windows电脑上监控剪贴板里的私钥和钱包地址。
地址替换什么时候发生?
用户复制并粘贴加密货币收款地址到交易所或钱包转账页面时可能发生。
韩国投资者应先做什么?
避免未知USB和LNK文件,转账前核对完整地址,不把私钥复制到剪贴板。
相关文章

比特币守在6.4万美元附近,霍尔木兹再封锁威胁压住美伊停火谈判
比特币在周五抛售后于周末反弹,价格回到6.4万美元附近。美国和伊朗在瑞士启动永久停火谈判,但伊朗再次下令关闭霍尔木兹海峡,重新点燃地缘风险。韩国投资者需要同时观察美元价格、韩元汇率和国际油价。

以太坊最大三明治机器人Jaredfromsubway.eth因虚假交易路径授权流失750万美元
以太坊最大三明治机器人Jaredfromsubway.eth在批准虚假交易路径后,损失750万美元的WETH、USDC和USDT。攻击者利用自动化授权结构转走资产。按简单汇率折算,损失约为100亿韩元级别。该事件凸显MEV机器人和DeFi钱包的授权风险。

비트코인 4일째 약세에 스마트컨트랙트·디파이 코인 낙폭 확대
비트코인이 나흘째 힘을 잃으며 크립토 시장 전반의 위험 회피 심리가 커졌다. 스마트컨트랙트와 디파이 코인은 고베타 자산으로 분류되며 하락장에서 더 큰 매도 압력을 받았다. Strategy의 배당형 우선주 STRC를 둘러싼 불확실성은 레버리지와 유동성 우려를 자극하고 있다.
Partner picks
Relevant partner links for this story
A lightweight commerce block designed to add monetization without breaking reading flow.
Good fit for Korea-based visitors ready to buy.
View offerWorks well for price-sensitive gadget and desk-tool traffic.
View offerUseful for books, work tools, and international shoppers.
View offerAdvertisement
This module may include affiliate links that earn a commission from qualifying purchases. 크립토데일리