Need help? Support
BITCOIN
Tether Dominance USDT.D

Silent Swap malware targets BTC ETH XRP

Published 464 words 3 min read

TLDR

Silent Swap is a new, sophisticated browser malware that hijacks copied BTC, ETH, and XRP addresses, silently redirecting funds to attackers when victims make transfers.

  1. Silent Swap uses a fake Google Notes browser extension to monitor your clipboard and swap Bitcoin (BTC), Ethereum (ETH), and XRP addresses for attacker-controlled ones.
  2. It targets users of Chromium browsers who install unsigned or cracked software, with confirmed impact on BTC, ETH, XRP and other coins like Bitcoin Cash and Dash.
  3. The main defenses are avoiding untrusted installers, auditing browser extensions, and carefully verifying destination addresses, especially when moving larger amounts.

Deep Dive

1. How Silent Swap Works

Security researchers at McAfee Advanced Threat Research report that Silent Swap is delivered via malicious installers written in .NET or Golang, often masquerading as free or pirated software.

Those installers quietly deploy a fake Google Notes extension into Chromium-based browsers (Chrome, Edge, Brave, Opera), tampering with configuration files so the extension is sideloaded and trusted.

Once active, the extension watches your clipboard; when it sees a wallet address for Bitcoin (BTC), Ethereum (ETH), XRP, Bitcoin Cash, Dash and others, it queries an attacker backend and replaces it with the attackers address, as detailed in this Silent Swap campaign report.

2. Why BTC, ETH, XRP Users Are At Risk

Silent Swap does not break BTC, ETH, or XRP themselves; it exploits the users device and copy-paste habits. Any wallet or exchange transaction that relies on a copied address can be silently redirected.

The malware uses decentralized command-and-control and techniques like EtherHiding, avoiding hardcoded domains and addresses, which makes detection and blocking harder than older, simpler crypto clippers.

Researchers note global reach with a high concentration of victims in India, but the mechanism is generic: anyone running infected Chromium browsers and moving funds in major coins is exposed.

What this means

Even if you use reputable wallets and exchanges, a compromised browser can divert a single large transfer with no on-chain warning.

3. Practical Defenses For Holders

  1. Avoid unsigned or pirated installers and free tools from random sites; these are a primary Silent Swap infection vector.
  2. Regularly audit browser extensions and remove anything you did not explicitly install, including suspicious notes or utility add-ons.
  3. Before confirming a transaction, compare the destination address on your hardware wallet or exchange screen with the known address, not just what you pasted.

Risk note: Clipboard-hijacking malware can drain funds in one transaction, so the biggest risk is large, infrequent transfers done with minimal manual checks.

Conclusion

Silent Swap is a modern evolution of crypto-stealing malware, focused on BTC, ETH, XRP and other widely held coins by quietly swapping pasted addresses inside compromised browsers.

If you keep using Chromium browsers for crypto, the edge now comes from disciplined operational security: trusted software sources, clean extension lists, and habitually verifying destination addresses before every significant transfer.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top