📈 Get daily crypto insights that make you smarter about your money

Russian Malware Silently Swapped Crypto Addresses for 8 Years: How the FBI and CrowdStrike Finally Took Down the 23-Year-Old Sality Botnet

One of the oldest pieces of malware on the internet has finally been knocked offline — and it was quietly stealing cryptocurrency from regular users for at least eight of its 23 years. Cybersecurity firm CrowdStrike, working with US federal authorities including the FBI, has dismantled the Russia-linked Sality botnet through a global sinkhole operation that isolated more than 15,000 infected machines, according to CoinDesk and multiple security-industry reports.

By Keisha Williams | September 2, 2026

The Hook: A 23-Year-Old Thief With a Simple Trick

Sality is a piece of malware that has been infecting Windows computers since the early 2000s — making it, according to The Record, one of the longest-running botnets ever disrupted. A botnet is a network of hijacked computers that criminals control remotely without their owners knowing. For more than two decades, Sality’s operators used this zombie army mainly to send spam and distribute other malware.

Somewhere along the way, according to CoinDesk, the operators added a crypto-stealing module with a deceptively simple trick: the malware watched the victim’s clipboard — the temporary storage where copied text lives — for bitcoin and Ethereum addresses. When a user copied a wallet address to paste it into an exchange or wallet app, Sality silently swapped it for an address controlled by the attackers. The transaction looked completely normal. The money simply went to the wrong pocket. Security researchers call this “clipboard hijacking,” and it has been stealing crypto for eight years, per Decrypt’s reporting.

The Evidence: How the Takedown Worked

Dismantling a botnet that has survived for 23 years takes coordination. Here is what happened, according to CoinDesk, Help Net Security, The Record, and The Hacker News:

  • Global sinkhole operation — authorities and CrowdStrike redirected the internet channels Sality used to command its infected machines into “sinkholes,” servers they control, cutting the criminals off from their zombie network.
  • More than 15,000 machines isolated — CoinDesk reports the operation isolated over 15,000 infected computers, meaning the attackers can no longer issue them new instructions.
  • The network turned against itself — The Hacker News reports the takedown exploited Sality’s own peer-to-peer design, in which infected machines relay commands to each other, so the malware’s architecture became the weapon used to defeat it.
  • Federal backing — cybersecuritynews.com reports the FBI worked alongside CrowdStrike to disrupt the operation, part of a broader pattern of US law enforcement offensive operations against crypto-stealing infrastructure.

The Core Conflict: Takedown Versus Rebuild

Security professionals celebrated the operation, but they also caution that botnet takedowns are rarely permanent. Sality survived 23 years precisely because it is resilient — peer-to-peer botnets have no single server to unplug, and their operators have historically re-coded and rebuilt after each disruption. The sinkhole isolates machines that authorities can reach; machines in places beyond that reach may still be running the malware, and the source code still exists.

There is also an uncomfortable truth in how long this took. A malware family that openly hijacked crypto clipboard copies for eight years was disrupted only after infecting a relatively modest 15,000-plus machines — a reminder that crypto theft often lives in boring, low-tech corners of the internet rather than in the headline-grabbing billion-dollar exchange hacks.

Market Implications: What This Means for Your Crypto

Crypto investors should treat this news as a useful prompt to check their own habits, because clipboard hijacking is not extinct — only this particular operation was. The defenses are simple and free:

  • Always verify the first and last characters of a pasted address before hitting send. Clipboard malware swaps addresses in the fraction of a second between copy and paste.
  • Use antivirus or endpoint protection that flags clipboard-monitoring behavior, and keep your operating system updated — Sality spread by exploiting old, unpatched software.
  • Test with a small transaction first when sending to a new address. A small mistake costs a small amount.
  • Be skeptical of old computers repurposed for crypto. Sality ran on some machines for years without detection.

The Verdict: A Win Worth Savoring, With Eyes Open

The Sality takedown is a genuine law-enforcement win against infrastructure that preyed on ordinary crypto users — not exchanges, not protocols, just people copying and pasting wallet addresses on infected home computers. Every sinkholed machine is one fewer soldier in a criminal army. But the eight-year run is also proof that the quiet attacks are the ones that last. The strongest security habit in crypto remains the least glamorous one: slow down and double-check before you press send.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

9 thoughts on “Russian Malware Silently Swapped Crypto Addresses for 8 Years: How the FBI and CrowdStrike Finally Took Down the 23-Year-Old Sality Botnet”

  1. malware swapping crypto addresses since 2018 and nobody noticed for 8 years. thats the scariest part, clipboard hijacking is invisible until you check the tx

  2. 15,000 sinkholed machines sounds big until you remember Sality probably had multiples of that still dormant in places nobody monitors. Good work by CrowdStrike but this is whack-a-mole.

      1. Exactly, a sinkhole kills the current C2 servers, not the payload. Every unpatched windows box is a respawn ticket for these guys.

  3. sality is older than the iphone and it was out here farming pasted wallet addresses since 2018. av vendors flagged pieces of it years ago, the global takedown is what took forever

  4. 23 years old and quietly swapping wallet addresses for 8 of them. imagine getting clipped by malware older than half the people in this comment section

  5. 15,000 sinkholed machines sounds big until you remember the botnet ran for two decades. The address-swapping variant is the scary part, most people never verify a pasted address.

      1. typing the last few chars only helps if the malware swaps after you check lol. verify the first AND last 6 on the device screen, never trust the clipboard

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,336.00+0.2%ETH$2,393.66-0.9%SOL$99.48-0.2%BNB$686.66+1.1%XRP$1.34-1.2%ADA$0.1969+0.1%DOGE$0.0814-0.4%DOT$0.8596-1.0%AVAX$7.17-0.8%LINK$11.12-0.8%UNI$5.79+2.4%ATOM$1.46-1.0%LTC$49.69+0.6%ARB$0.1241+16.7%NEAR$1.86-3.2%FIL$0.8101+5.7%SUI$0.7295+0.6%BTC$77,336.00+0.2%ETH$2,393.66-0.9%SOL$99.48-0.2%BNB$686.66+1.1%XRP$1.34-1.2%ADA$0.1969+0.1%DOGE$0.0814-0.4%DOT$0.8596-1.0%AVAX$7.17-0.8%LINK$11.12-0.8%UNI$5.79+2.4%ATOM$1.46-1.0%LTC$49.69+0.6%ARB$0.1241+16.7%NEAR$1.86-3.2%FIL$0.8101+5.7%SUI$0.7295+0.6%
Scroll to Top