Printer Driver Hijack Steals Nearly $1M in Bitcoin, MistTrack Warns

Printer Vulnerability Exposes Cryptocurrency Wallets to New Security Threat

  • A backdoor in an official printer driver is being used to steal cryptocurrency from users’ wallets.
  • The exploit replaces crypto wallet addresses copied to a user’s clipboard with the attacker’s address.
  • At least 9.3 Bitcoin, valued at about $989,000, has been stolen using this method.
  • The attacker’s wallet has been active since 2016 and is linked to multiple crypto exchanges.
  • This attack is similar to past clipboard-hijacking Malware incidents, but spreads via legitimate-looking software drivers.

MistTrack, a blockchain security platform, recently announced that a malicious exploit is targeting crypto users by embedding a backdoor into a printer driver. The exploit, discovered by the Cybersecurity arm of SlowMist, allows the attacker to intercept and alter cryptocurrency wallet addresses stored in a user’s clipboard.

- Advertisement -

According to on-chain data from MistTrack, the attacker has collected a minimum of 9.3 Bitcoin, worth around $989,000, from victims’ crypto transactions. The suspect’s wallet has sent and received funds from numerous on-chain addresses, and has been linked to several crypto exchanges.

The official printer driver identified in this attack installs a backdoor program once loaded onto a device. “The official driver provided by this printer carries a backdoor program. It will hijack the wallet address in the user’s clipboard and replace it with the attacker’s address,” stated MistTrack in a recent post.

The malware works by monitoring the clipboard, which temporarily stores data a user copies. When a user copies a crypto wallet address, the malware replaces it with the attacker’s address. If the change goes unnoticed, funds are unintentionally sent to the attacker’s wallet.

A similar technique surfaced in March 2025 with malware called MassJacker, according to CyberArk. MassJacker allegedly used hundreds of thousands of unique addresses and spread through pirated or cracked software from unofficial sources. However, the current printer driver exploit relies on a recurring wallet address and is distributed through legitimate-seeming software.

- Advertisement -

On-chain activity shows the main attacker’s wallet address has been operational since April 2016. The last detected transaction before the recent thefts was on March 14, 2024. The wallet has connections to several crypto exchanges, potentially complicating tracing efforts.

Cybersecurity experts advise crypto users to only install drivers and applications from verified, official sources to reduce exposure to these types of clipboard-hijacking threats.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Stocktwits Bullish: MSTR, ASST Rally as BTC Tops $93,000 Now

Bitcoin held above $93,000 as crypto equities were largely unchanged in after-hours trading on...

Ethereum exit queue near zero as staking demand surges today

Validator exit queue has fallen to 32 ETH with a wait time of about...

Aeva 4D LiDAR Selected for Nvidia DRIVE Hyperion – L3/L4 AVs

Aeva's FMCW 4D LiDAR was selected for NVIDIA's Hyperion autonomous vehicle platform.The sensor adds...

Amazon launches Alexa.com web AI chat with shopping, devices

Amazon launched a browser-based chat interface called Alexa.com for its Alexa+ assistant.Early Access users...

Micron Rockets Past $310, Emerging as 2026 AI Darling Rally!

Micron shares climbed above $310, breaching $310.52 on Monday.MU has surged over 30% since...
- Advertisement -

Must Read

Forex Trading Vs Crypto Trading: Which One Should You Choose?

So you're trying to decide between two types of trading: Forex and cryptocurrency.Forex trading is the big player in the trading world, with lots...
Bitcoin (BTC) $ 93,710.00 1.41%
Ethereum (ETH) $ 3,221.81 2.15%
XRP (XRP) $ 2.39 12.64%
Bittensor (TAO) $ 277.90 6.68%
Polkadot (DOT) $ 2.21 3.93%
Cardano (ADA) $ 0.423383 6.22%
Chainlink (LINK) $ 13.85 2.50%
Hyperliquid (HYPE) $ 26.83 1.78%
Monero (XMR) $ 447.04 5.26%
Hedera (HBAR) $ 0.130986 4.50%
Toncoin (TON) $ 1.90 2.67%