Sality's Haul: Eight Years, 15,000 Machines, Gone
— Law, Business & Power Correspondent --- A Russian malware operation called Sality ran quietly inside more than 15,000 computers for eight years, doing one thing with surgical patience: watching clipboards for copied Bitcoin and Ethereum wallet addresses, then replacing them with the attacker's own before the user could paste.
Sality's Haul: Eight Years, 15,000 Machines, Gone
*By Harvey Specter Jr. — Law, Business & Power Correspondent*
---
A Russian malware operation called Sality ran quietly inside more than 15,000 computers for eight years, doing one thing with surgical patience: watching clipboards for copied Bitcoin and Ethereum wallet addresses, then replacing them with the attacker's own before the user could paste. No ransom note. No dramatic breach notification. Just a silent redirect at the moment of transfer — the kind of theft that only reveals itself when the money never arrives.
CrowdStrike and federal authorities have now dismantled the network, according to CoinDesk, isolating infected machines and cutting the operation's reach. The number — 15,000 confirmed infections — is the floor, not the ceiling. These are the machines they found.
The legal exposure here runs in multiple directions. Victims who lost funds to address-substitution attacks during Sality's eight-year window have potential civil recovery claims, depending on jurisdiction and whether custodial platforms had adequate security obligations. The firms that built wallets without clipboard-integrity verification will be reading their terms of service very carefully right now. They should be.
The deeper lesson has nothing to do with cryptocurrency. It is about the architecture of trust at the point of execution — the moment when an instruction leaves your hands and enters a system you didn't build. That moment is where every sophisticated financial crime lives.
Your move: If you hold crypto across any wallet, disable clipboard auto-fill permissions in your browser and verify the first and last six characters of every address before you confirm a transfer. Every time. No exceptions.