The Address You Pasted Is Not Always the One You Copied
Clipboard malware can replace a copied crypto address. Check the paste, and compare a hardware wallet screen when the device supports it.
The Address You Pasted Is Not Always the One You Copied
Clipboard malware can replace a copied crypto address with a different one before you paste. MetaMask, Ledger, and Trezor describe that swap in their help pages and tell users to check the pasted address, then compare a hardware wallet screen when the device supports it.
Crypto addresses are long strings that people rarely type by hand. Many wallets and exchanges include a copy shortcut so a recipient field can be filled with a paste. That habit is what the malware uses.
What Clipboard Malware Does
MetaMask's clipboard-hacking help page says a malicious program on the device can watch new clipboard contents for a public crypto address. When it finds one, it replaces the copied address with an address the script is set to insert. The next paste into a send or withdrawal field can then point to the attacker's wallet if the user confirms the transaction.
Trezor's guide to its Trusted Display names the same tactic: clipboard malware can swap an address after you copy it, so the address you paste is not the one you copied. That is a second vendor describing the same mechanism. Neither page reports how often the swap occurs.
How to Check a Paste
MetaMask describes this check. Open the device's notes app or default text editor, such as Notepad on Windows or TextEdit on a Mac. Copy and paste ordinary text inside that file to confirm copy-and-paste still works. Then copy the address from MetaMask and paste it into the same file. If the pasted text does not match the address shown in MetaMask, MetaMask says to scan the device for malware and points to Apple, Microsoft, and Google support pages as starting points.
MetaMask also says this test can miss some programs. A script may wait until the paste lands in a wallet or another app that asks for an address, instead of a notes app. MetaMask's advice is to look at the recipient address after every paste, before confirming. It says checking a handful of characters at the start and end is a useful habit.
Ledger's receive guide, last updated September 11, 2026, gives the same paste check in a hardware-wallet setting. After you copy a receive address, check that it has not changed. Ledger recommends using Re-verify after the address is entered somewhere else, so the device screen can be compared again.
What a Hardware Screen Confirms
When a Ledger device is connected, Ledger Wallet can show the receive address on the device's Secure Screen. Ledger says to match that screen to the address in Ledger Wallet. If they do not match, reject the address and do not send to it. Generating a receive address without the device connected skips that comparison. Ledger says that address does not have the same level of security.
Trezor says malware on a computer or phone can change what those screens show, but it cannot change what the Trezor device shows. Trezor calls that device screen the Trusted Display. Before sending, Trezor says to check the destination address and the amount on the device, because those are the details the device will sign.
Trezor also states the limit. The device screen confirms what the hardware is doing. It cannot tell you whether an address someone gave you belongs to the person you meant to pay. Confirm the destination first, then use the screen to check that nothing changed along the way.
What These Checks Do Not Prove
A matching notes-app paste does not prove the device is clean. MetaMask says some malware can stay quiet until the paste is aimed at a wallet. Anti-malware software can miss programs. CryptoWorkPro cannot inspect a reader's device.
A hardware screen that matches Ledger Wallet or Trezor Suite confirms the address the device generated, or the transaction it is about to sign. It does not prove the intended recipient owns that address. Ledger's receive page still recommends sending a small amount first and confirming it arrived before sending a larger one. That is Ledger's own caution, not a guarantee.
Sources
- MetaMask Help, Clipboard hacking: https://support.metamask.io/stay-safe/protect-yourself/wallet-and-hardware/clipboard-hacking/
- Ledger Support, Receive crypto assets (last updated September 11, 2026): https://support.ledger.com/article/4404389453841-zd
- Trezor, Trusted Display: https://trezor.io/guides/trezor-devices/trezor-fundamentals/trezor-s-trusted-display-verify-every-address-on-your-device
Disclosure: Coverage is based on MetaMask, Ledger, and Trezor help pages, including Ledger's September 11, 2026 receive guide. Checking a paste or a device screen does not prove malware is absent or that an address belongs to the intended person. Generated artwork is illustrative. This article is not financial, legal, or investment advice. AI-assisted research and writing. Cited sources, not AI alone, support the claims.


