Top

U.S. dismantles Sality botnet tied to crypto wallet address theft

September 02, 2026, 1:26 PM
U.S. federal law enforcement agencies and cybersecurity firm CrowdStrike have dismantled the Sality botnet, which covertly changed users’ cryptocurrency wallet addresses to steal funds, CoinDesk reported. Sality had been active since 2003 and was used over the past eight years to intercept crypto transfers. At the center of the attack was clipboard-monitoring malware known as “Egregor.” When users copied a Bitcoin or Ethereum wallet address, the malware detected it and replaced it with an attacker-controlled address. If victims failed to notice the switch and pasted the altered address into a transaction, the funds were sent to the attackers. CrowdStrike estimated at least 12.1 million rubles, or about $150,000, was stolen over eight years. The firm added that the value of the attackers’ holdings rose with crypto prices, reaching as much as $1.35 million in early 2025 as a large share of the stolen assets was apparently kept rather than sold.

Leave the first comment

You need to log in to leave a comment.
Log In
Loading