Mastodon Skip to content
pulseofnations. Real News. Global Impact.
Subscribe
live markets
BTC$81,258▲ 5.08%ETH$2,506▲ 4.74%SOL$105.13▲ 5.78%TOTAL CRYPTO$2.74T▲ 1.95%S&P 5007,755.25▲ 2.04%NASDAQ26,635.22▲ 2.78%DOW53,685.37▲ 0.95%GOLD4,536.20▲ 12.46%WTI91.40▲ 13.77%BRENT95.60▲ 14.12%EUR/USD1.1637▲ 0.81%USD/JPY155.41▼ 1.38%DXY98.90▼ 1.06%

CrowdStrike Dismantles Botnet That Stole Crypto for 8 Years

Sality botnet hijacked BTC and ETH clipboard addresses for 8 years across 15,000 machines worldwide

PartnerSurfshark VPN

CrowdStrike and international law enforcement agencies dismantled Sality, a 23-year-old peer-to-peer botnet whose clipboard-hijacking module silently redirected Bitcoin and Ethereum payments to attacker-controlled wallets for eight years.

The disruption, executed on August 31 through a coordinated sinkhole operation, cut off more than 15,000 infected machines from their operator. CrowdStrike’s Counter Adversary Operations team worked alongside international law enforcement and the Shadowserver Foundation to poison Sality’s peer-to-peer network and divert traffic away from the attacker’s command infrastructure.

The operation was carried out during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas, according to the U.S. Department of Justice. The DOJ confirmed the operator was based in Russia and had maintained the botnet across infected machines in multiple countries for over two decades. The takedown involved authorities from several nations coordinating with CrowdStrike to execute the sinkhole at the same time, preventing the operator from migrating to backup infrastructure.

A botnet that outlasted most of its peers

Sality first appeared in 2003 as a file-infecting virus and evolved into a peer-to-peer botnet with two independent networks running the same codebase. For most of its 23-year lifespan, Sality served primarily as a delivery mechanism for other malware. But for the past eight years, its main payload was EggJagger – a clipboard monitor that watched for cryptocurrency wallet addresses being copied on infected machines.

The mechanism was simple but effective. When a victim copied a Bitcoin or Ethereum address to make a payment, EggJagger checked the clipboard and silently replaced the address with one controlled by the attacker. The swap happened without any visible confirmation to the user, making it nearly impossible to detect without carefully comparing addresses character by character before signing a transaction. A defense for users is to check the first and last characters of an address after pasting it, every time.

Because Sality had no central server to seize, the botnet was difficult to shut down through conventional means. Infected machines talked directly to one another, checking every 40 minutes whether their known peers were still online. The malware spread by attaching itself to programs shared on network drives and USB drives, regenerating without any effort from its malicious operator. Any computer that responded in the expected way was treated as part of the botnet with no further identity check.

How much was stolen

CrowdStrike estimated the operator – tracked as “SALTY SPIDER” and assessed to be based in the Republic of Bashkortostan, Russia – stole at least 12.1 million rubles (roughly $150,000) through EggJagger over its eight-year run. The actual value was likely higher, since much of the stolen crypto was never spent on-chain.

Those unspent holdings peaked at approximately 147 million rubles ($1.35 million) in early 2025 as crypto prices rose, according to CrowdStrike’s technical write-up. The operator is believed to have used peer-to-peer exchanges to convert stolen coins into fiat currency, though only a fraction of the stolen funds were ever cashed out. While the dollar figure is relatively small compared to major exchange hacks, the eight-year duration shows how a simple clipboard trick can persist when users do not verify addresses before sending.

The low dollar amount relative to the number of infected machines suggests that most stolen crypto went to wallets that were never cashed out, possibly because the operator lacked the infrastructure to move large volumes without triggering exchange compliance systems.

How the sinkhole worked

The disruption relied on a standard botnet-takedown technique: sinkholing. By taking control of key nodes in Sality’s peer-to-peer network, CrowdStrike and law enforcement redirected traffic away from the attacker’s command infrastructure. Infected machines can no longer receive new instructions or download additional payloads from the botnet, though the underlying malware remains on compromised systems until users run antivirus scans.

CrowdStrike exploited the botnet’s lack of identity verification to replace the real peer addresses with its own servers, cutting off more than 15,000 machines from the network. The Shadowserver Foundation, a nonprofit that provides free internet security services, assisted with the sinkhole infrastructure.

The DOJ said the operation was the result of months of coordination between CrowdStrike, federal agencies, and international law enforcement partners. The agency did not name the specific countries involved beyond confirming the operator’s Russian location. The takedown demonstrates that even long-running botnets with decentralized architectures are vulnerable to sinkhole operations when their peer verification is weak.

What crypto users should do

The takedown removes an active clipboard-hijacking threat but does not clean infected machines. Users who suspect compromise should run antivirus scans and, more importantly, verify wallet addresses through a hardware wallet screen or a trusted address book before signing any transaction – rather than trusting what appears in the clipboard.

Clipboard hijacking remains a common attack vector in crypto theft. Even after Sality’s disruption, similar payloads continue to circulate through other malware families. The Sality case is a reminder that hardware wallets exist for a reason: they let users verify destination addresses on a separate, trusted screen before money leaves the wallet.

For users who do not use hardware wallets, the safest habit is to always verify at least the first and last six characters of a pasted address against the original source before confirming any crypto transaction. It takes a few seconds and prevents the kind of silent theft that Sality carried out for nearly a decade.

SourcesCrowdStrike (blog post September 1, 2026); U.S. Department of Justice; CoinDesk; The Register; CryptoTimes
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch Ethereum Glamsterdam May Break Wallets, Gas Estimators Read →