CrowdStrike and DOJ Dismantle Botnet That Hijacked Bitcoin (BTC) Payments for 8 Years

CrowdStrike and US authorities dismantled Sality, a botnet that hijacked Bitcoin and Ethereum payments for eight years, isolating 15,000 machines.

(02:08 PM UTC)
3 min read
AI SummaryAI
  • CrowdStrike and federal authorities isolated more than 15,000 machines infected with the Sality botnet.
  • Sality's EggJagger payload replaced copied Bitcoin and Ethereum wallet addresses with attacker-controlled ones.
  • The botnet operated for eight years, stealing at least 12.1 million rubles, roughly $150,000.
  • Unspent stolen holdings peaked at about $1.35 million in January 2025 under operator SALTY SPIDER.
k7rq2fdm

Eight Years of Clipboard Hijacking

CrowdStrike and US federal law enforcement have dismantled Sality, a Russia-based botnet that spent its final eight years hijacking Bitcoin (BTC) and Ethereum payments on infected computers. The malware's central trick targeted one of crypto's most routine habits: wallet addresses are long strings nobody types by hand, so users copy and paste them. Sality's main payload, which CrowdStrike calls EggJagger, monitored the clipboard of every infected machine, and whenever it detected text resembling a bitcoin or ether address, it silently swapped the copied string for one controlled by the attacker. A victim pasting the address into their wallet and hitting send paid the wrong party entirely, with no warning and no way to reverse the transfer. CrowdStrike estimates the operator stole at least 12.1 million rubles, roughly $150,000, through that mechanism alone. The botnet itself dated back to 2003 and had no central server to seize: infected machines communicated directly with one another, checked whether their known peers were still online every 40 minutes, and spread by attaching themselves to executable files shared over network drives and USB drives. CrowdStrike turned that serverless design into the operation's weak point, replacing legitimate peer addresses with its own servers and cutting off more than 15,000 infected machines worldwide. The action was executed on Monday during a live demonstration at the firm's Day Zero summit in Las Vegas, and the Justice Department press release confirms the takedown of Sality-linked infrastructure.

SALTY SPIDER's Unspent Haul

The operator, tracked by CrowdStrike under the designation SALTY SPIDER, ran a materially more profitable strategy than the raw theft figures suggest: the stolen coins were largely left untouched, and that patience paid off. The unspent whale-sized portfolio peaked at roughly 147 million rubles in January 2025, a nominal $1.35 million, or about $4 million in purchasing power in a Western capital — an accidental long-term HODL built entirely from hijacked funds. Before EggJagger, Sality earned its keep delivering credential theft, spam, proxy services and denial-of-service payloads for other operators. One incident stands out: a September 2023 denial-of-service attack on AvanChange, a Russian cryptocurrency exchange, whose payload was compiled seconds before upload — a timing pattern the security firm reads as an impulsive response to a personal grievance, given that the operator relied on exchanges like it to convert stolen coins into cash. The takedown itself spanned four countries: the Justice Department, FBI and Defense Criminal Investigative Service seized Sality domains in the United States, while police in Bulgaria, Hungary and Romania took down servers in Europe. The Shadowserver Foundation is now working with internet providers to notify victims. Unlike an on-chain replay attack, this threat never touched the blockchain — it struck before a transaction was ever signed — and infected machines still carry live malware until it is manually removed. Users choosing venues to move funds can consult our guide to the best crypto exchanges for custody hygiene.

Checking the Address Still Matters

Our read of the official filing is that the load-bearing fact is architectural, not financial: Sality survived 23 years precisely because it had no central point to seize, and it fell only when researchers exploited its blind trust in any machine that answered the handshake correctly. For Bitcoin and Ethereum users, the takeaway is unglamorous — a $150,000 haul over eight years was built on nothing more than people pasting addresses without checking the first and last characters. Verify every address after pasting; the malware is gone, but the trick outlives any single botnet.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.