Loading market data...

CrowdStrike and Feds Dismantle Sality Malware That Stole Crypto for 8 Years

CrowdStrike and Feds Dismantle Sality Malware That Stole Crypto for 8 Years

Federal law enforcement and CrowdStrike have dismantled Sality, a Russian-origin malware that quietly stole cryptocurrency for eight years by swapping copied wallet addresses with the attacker's own. The operation isolated more than 15,000 infected machines, cutting off a long-running drain on bitcoin and Ethereum funds.

How the theft worked

Sality used clipboard hijacking. When a user copied a bitcoin or Ethereum address to send a payment, the malware detected it and replaced it with the attacker's address. The victim would paste the altered address, and the funds would go to the thief instead of the intended recipient.

The technique is simple but effective. It doesn't require breaking into a wallet or cracking a password. It just waits for a moment of inattention. Over eight years, that added up to a steady, quiet stream of stolen crypto.

The takedown

CrowdStrike worked with federal authorities to dismantle the malware's infrastructure and isolate more than 15,000 infected machines. The operation was a collaborative effort, with the security firm providing the technical analysis and law enforcement handling the legal side.

Details on how the takedown was executed haven't been released. But the scale suggests a coordinated push to cut off the malware's command-and-control servers and clean up the infected endpoints.

What users should know

Clipboard hijacking isn't new, but it's still a threat. The best defense is to double-check the address you're sending to, especially for large amounts. Some wallets now show a checksum or a preview of the address, but that doesn't help if the malware swaps it after you copy.

The takedown doesn't mean the technique is gone. Other malware families use the same trick. But this particular operation, which ran for years, is now out of commission.

For the people who lost funds to Sality, there's no word on recovery. The stolen crypto is likely long gone, mixed and moved through multiple wallets. The win here is stopping the bleeding, not getting money back.