Futures
Access hundreds of perpetual contracts
CFD
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
CFD
U.S. stock CFD derivatives
US Stocks
Access real US stocks and ETFs
HK Stocks
Trade quality Hong Kong-listed stocks
Stock Futures
High leverage, 24/7 trading
Tokenized Stocks
Backed by real stock assets
IPO Access
Unlock full access to global stock IPOs
GUSD
Mint GUSD for Treasury RWA yields
Stocks Activities
Trade Popular Stocks and Unlock Generous Airdrops
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
IPO Access
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
Microsoft Warns of New ‘Crypto Clipper’ Malware Spreading via Infected USBs
Microsoft’s Threat Intelligence team has detailed a sophisticated new strain of Windows-based “clipper” malware that has been quietly targeting cryptocurrency users since February 2026.
Unlike typical modern cyber threats, this malware doesn’t rely on phishing emails, malicious browser extensions, or fake wallet apps. Instead, it spreads the old-fashioned way: through infected physical USB drives.
What is Clipper Malware?
A “clipper” is a highly specific type of malicious software designed to exploit a universal digital habit: copying and pasting.
The software constantly monitors a computer’s clipboard—the temporary digital memory used when you copy text. When it detects sensitive financial data, most commonly a cryptocurrency wallet address, it silently replaces it with an address controlled by the attacker.
The USB Infection Chain
According to a Microsoft report, the attack begins when a user plugs in a compromised USB drive and opens what appears to be a normal document. In reality, it is a disguised shortcut file.
Once opened, the virus silently installs itself and immediately attempts to jump to any other removable drives connected to the machine, allowing it to spread laterally between coworkers, friends, and systems.
Once active in the background, the stakes get incredibly high:
Going Dark Over the Tor Network
What makes this specific strain unusual—and dangerous—is how it hides its tracks.
Instead of connecting directly to standard internet servers, the malware utilizes a built-in, hidden version of the Tor network. By routing all of its stolen data through a local proxy to a secret .onion website, it easily evades traditional network security tools that monitor normal internet traffic.
Furthermore, the malware grants attackers remote command execution. This means criminals aren’t just stealing crypto; they gain a persistent backdoor to run any code they want on the infected computer.
How to Protect Your Funds
Because this malware specifically generates fake addresses that mimic the first and last characters of your intended destination, casual “eyeball” verification will fail.
To protect your assets, security experts recommend a few immediate adjustments:
Why This Matters
Unlike large-scale exchange hacks, the clipper malware directly targets individual investors by hijacking the simple act of copying and pasting. Because it perfectly mimics the look of real wallet addresses, casual spot-checking is no longer enough to protect your funds.
Stay in the loop with DailyCoin’s popular crypto scoops:
AI Crypto Tokens Slide Just as ETF Door Opens for Institutions
Kentucky Sues Polymarket and Kalshi, Challenging Trump-Era Crypto Policy
People Also Ask:
What is clipper malware? Clipper malware is a type of malicious software that monitors a device’s clipboard (where copied text is temporarily stored). When it detects specific data, like a cryptocurrency wallet address, it secretly swaps it with an address controlled by an attacker.
How does clipboard-hijacking malware spread? While many cyber threats spread online through phishing emails or malicious downloads, clipper malware can also spread physically via infected USB flash drives or laterally across shared local networks.
Why is casual verification not enough to spot a wallet address swap? Advanced clipper malware can automatically generate fraudulent wallet addresses that match the exact first and last characters of the original address. Because many users only visually check the outer flanks of a long address string, the swap easily goes unnoticed.
.social-share-icons { display: inline-flex; flex-direction: row; gap: 8px; border-radius: 8px; border: 1px solid #dedede; padding: 8px 16px; margin-bottom: 8px; }
.social-share-icons a { display: flex; color: #555; text-decoration: none; justify-content: center; align-items: center; background-color: #dedede; border-radius: 100%; padding: 10px; }
.social-share-icons a:hover { background-color: #F7BE23; fill: white; }
.social-share-icons svg { width: 24px; height: 24px; }
DailyCoin's Vibe Check: Which way are you leaning towards after reading this article?
Bullish Bearish Neutral
Market Sentiment
0% Neutral