US joins CrowdStrike in crackdown on crypto-stealing malware
US authorities and international partners disrupted the Sality botnet, which had used clipboard-hijacking malware to divert about $150,000 in crypto over eight years.
Jorge Franganillo / Wikimedia Commons (CC BY 2.0)
US federal authorities have moved against a malware network linked to cryptocurrency theft, working alongside CrowdStrike and other private-sector partners in an international operation. The action targeted the Sality botnet, which officials said had been active for years and had been used to compromise devices and enable broader cyberattacks. The effort also involved law-enforcement agencies in Bulgaria, Hungary and Romania, plus the Shadowserver Foundation.
How the malware worked
Officials said the network relied on malware that could infect a victim’s device and interfere with cryptocurrency transactions. CrowdStrike said the group behind Sality had used a tool called EggJagger to watch a clipboard for wallet addresses and replace them with addresses controlled by the operators. That kind of manipulation can be difficult for users to spot if they copy and paste payment details quickly.
The Justice Department said the disruption was part of a wider international push rather than a purely domestic case. By coordinating with foreign authorities and security firms, investigators aimed to take down the infrastructure that allowed the malware to keep spreading. The announcement did not indicate that the underlying threat had vanished altogether, only that this particular operation had been disrupted.
What investigators say was stolen
US officials said Sality had been installing malware on compromised devices since 2003. Over the past eight years, the activity tied to the botnet and its related tools redirected about $150,000 in cryptocurrency, according to the announcement. That figure is modest by the standards of major crypto hacks, but it shows how small-scale theft can accumulate over long periods.
The case highlights how cybercriminals continue to exploit basic user behavior around digital assets, especially the copying of wallet addresses. It also underscores the role of security vendors in modern enforcement work, where private firms often provide threat intelligence and technical support that help authorities map malicious infrastructure. For crypto users, the episode is another reminder that wallet-address tampering remains a live risk.
Because cryptocurrency transfers are generally irreversible, even a brief malware infection can have lasting consequences. The Sality case suggests that threats do not always arrive as headline-grabbing exchange breaches; some work quietly in the background, intercepting routine transactions one by one. That makes endpoint security and careful transaction checks central defenses for anyone handling digital assets.
This article is not investment advice and recommends no asset, level or direction; a single session's move is not evidence of a trend. For background see Crypto, Altcoin, Bitcoin, and for terms the finance glossary.
Frequently asked questions
What did US officials and CrowdStrike target?
They targeted the Sality botnet and related malware used to interfere with cryptocurrency transactions and broader cyberattacks.
How much crypto was affected?
Officials said about $150,000 in cryptocurrency was redirected over the last eight years.
What did the malware do?
It monitored clipboard activity for wallet addresses and replaced them with addresses controlled by the operators.
Sources
Related News

Bitcoin edges higher as most large-cap coins rise
Bitcoin, ether and four large-cap altcoins mostly traded higher on Wednesday, with BNB leading gains and XRP the only decliner. The move was broad but modest, leaving the market mixed rather than directional.

Bitcoin, ether edge higher as altcoins mostly rise
Bitcoin and ether traded modestly higher on Tuesday, while most large-cap altcoins also advanced. BNB was the lone decliner in a narrow session that kept moves contained across the board.

Bitcoin edges higher as altcoins mostly firm
Bitcoin, ether and most large-cap altcoins were modestly higher on Sunday, with only Solana slipping. The moves were small, but they still show how quickly relative performance can shift across liquid crypto pairs.
Strategy Sells Bitcoin to Support Dividends and Buybacks
Strategy sold 1,638 Bitcoin to raise cash for STRC dividend payments and repurchases, while also increasing its USD reserve and continuing MSTR share sales.
Crypto phishing campaign targets 885,000 phone numbers
Rapid7 says a phishing operation dubbed Asterix targeted about 885,000 phone numbers across several countries, with logs tied to Binance users and fake Crypto.com emails.

Bitcoin edges higher as BNB leads large-cap crypto gains
Crypto traded mixed on Wednesday, with three of the six tracked tokens higher and three lower. BNB outperformed, while XRP posted the weakest move and bitcoin held near flat.