A malware family known as Sality, active since 2003, has been quietly redirecting cryptocurrency payments by swapping wallet addresses on infected machines, according to newly detailed findings. The technique, which targets both Bitcoin and Ethereum transactions, has reportedly been running for the last eight years.
Sality is not a new threat. It first emerged more than two decades ago as a file-infecting virus and has since evolved through multiple iterations, adapting to new attack surfaces as they became available. The addition of cryptocurrency wallet manipulation represents one of its more recent and financially consequential capabilities.
The mechanism is straightforward but effective: once a device is compromised, the malware monitors the clipboard or transaction process for wallet addresses and substitutes them with addresses controlled by the attackers. Because cryptocurrency transactions are irreversible once confirmed on-chain, victims who do not carefully verify the destination address before sending funds have no recourse to recover the diverted payments.
Scale of the infection
More than 15,000 computers have been infected by Sality, based on figures cited in the disclosure. The scale suggests a persistent, low-visibility operation rather than a single high-profile breach, with infections apparently accumulating steadily over the years rather than in a sudden spike.
The choice of Bitcoin and Ethereum as targets is unsurprising given their status as the two most widely held and traded cryptocurrencies, offering attackers the broadest possible pool of potential victims and the deepest liquidity for laundering diverted funds.
What it means for users
The persistence of address-swapping malware such as Sality underscores a recurring weak point in cryptocurrency security: the moment a user copies and pastes a wallet address is often the point of greatest vulnerability, regardless of how secure the underlying blockchain protocol itself may be. Basic hygiene measures, including manually verifying the first and last characters of a destination address before confirming a transfer, remain one of the few effective defences against this class of attack.
No further details have been disclosed regarding the identity of those behind the Sality operation, the total value of funds diverted through the scheme, or specific remediation steps being taken by security researchers or cryptocurrency platforms in response.




