Microsoft flags ‘Crypto Clipper’ malware that steals seed phrases and swaps wallet addresses
Microsoft security researchers say a malware campaign dubbed “Crypto Clipper” targets cryptocurrency users by stealing wallet data, capturing screenshots, and enabling remote access. The campaign also replaces copied wallet addresses to divert transfers to attacker-controlled accounts. Microsoft said the malware has been active since at least February 2026.