How did the Sality malware steal Bitcoin and Ethereum for eight years?

Sality malware siphoned crypto by secretly replacing copied wallet addresses with those belonging to Russian attackers, a tactic known as 'clippering.' A joint operation by CrowdStrike and federal authorities has now dismantled the botnet, isolating over 15,000 infected machines.
How did the Sality malware steal Bitcoin and Ethereum for eight years?

The Sality malware stolen Bitcoin and Ethereum by monitoring the clipboards of infected computers for cryptographic wallet addresses. When a user copied a destination address to initiate a transaction, the malware instantly swapped it for an address controlled by Russian-based threat actors. Because many users fail to verify every character of a long wallet string before clicking 'send,' funds were unknowingly routed to the hackers' wallets for nearly a decade.

This long-running operation was recently dismantled through a coordinated effort between the cybersecurity firm CrowdStrike and federal law enforcement agencies. By identifying and disrupting the malware's peer-to-peer (P2P) communication infrastructure, authorities managed to isolate more than 15,000 infected machines. This intervention effectively severed the connection between the malicious software and its command-and-control servers, halting the automated theft process.

The Sality takedown represents a significant victory in the ongoing geopolitical struggle against cybercrime originating from Russia. For U.S. crypto investors, the incident highlights a critical vulnerability in the 'hot wallet' ecosystem, where local machine security is just as important as exchange security. Federal authorities are increasingly prioritizing the dismantling of these 'invisible' theft rings that target retail holders rather than large-scale protocol exploits.

While the immediate threat from this specific botnet has been neutralized, the incident serves as a warning for users to adopt more rigorous security practices, such as using hardware wallets or transaction simulation tools. Moving forward, market participants should watch for further federal actions against international malware networks, as these enforcement operations are becoming a cornerstone of the U.S. strategy to protect the digital asset domestic market.