Last updated: December 22, 2026
- Most crypto theft never touches the blockchain — it exploits habits around pasting, copying from history, and trusting inbound contact.
- Clipper malware swaps a copied address for a lookalike sharing the same start and end characters. Verify the full pasted address, every time.
- Dust and address-poisoning transfers plant fake entries in your history — one study counted 270 million attempts and roughly $83.8M in losses.
- Unsolicited tokens, NFTs, and "support" DMs are attack vectors, not opportunities. No legitimate support asks for your phrase or contacts you first.
- Wallet drainers are an industry: $494M stolen in 2024 across ~332,000 victims, up 67% year over year (Scam Sniffer).
Wallet security guides obsess over seed phrase storage — ours included — and rightly. But the data says the bigger losses happen somewhere else entirely: in the space between your keys and the chain, where the only thing standing between an attacker and your funds is your habits.
The attack surface outside the chain
Scam Sniffer tracked $494 million lost to wallet drainers in 2024 across roughly 332,000 victims — a 67% increase year over year. The tooling is commoditized: drainer kits like Inferno, Angel, and Pink are sold as drainer-as-a-service, meaning the attacker buys the kit, not the skill.
None of these attacks break cryptography. They exploit the human layer — what you paste, what you copy out of transaction history, who you trust in your inbox. That is good news in one narrow sense: habits are cheaper to fix than software.
Clipboard malware: the paste that betrays you
Clippers are resident malware with a single job: watch the clipboard. When you copy something matching a crypto address pattern, the malware swaps it for an attacker-controlled address — one generated to share the same first and last characters as the address you copied. You paste 0x1a2B…f9C2, glance at the edges, see 0x1a2B…f9C2, and sign. The middle was theirs.
Edges are not verification. Vanity address generation makes matching prefixes cheap, and checking only the start and end of an address is exactly the habit clippers are built around. The defense is boring but absolute: after pasting, read the full address — or at minimum a segment from the middle. For large transfers, send a small test amount first and confirm it arrived. Saved address-book entries beat re-pasting entirely.
Dust attacks and address poisoning
Dust is a trace amount of crypto sent to your wallet uninvited. Sometimes it is a probe; more often now it is address poisoning — a zero-value or tiny transfer lands in your transaction history, sent from a lookalike address that mimics one you actually use: a frequent counterparty, or even your own. Later, when you copy "the address I sent to last time" out of history, you get theirs.
The scale is industrial. A USENIX Security 2025 study counted 270 million poisoning attempts, 17 million victim addresses, and about $83.8 million in losses. The countermeasure costs nothing: never copy a recipient address from transaction history. Re-copy from the original source — an address book entry or a verified message — every single time.
Mystery tokens and the signature they want
An unknown token or NFT appears in your wallet. A site tied to it promises you can sell it or "claim" a reward — and the claim flow requests a signature: an approve, a setApprovalForAll, or a permit / Permit2 message. Approvals persist until revoked, so a single signature can hand a drainer the right to move everything you approved, long after you have forgotten the site.
The rule: do not interact with unsolicited assets — not to sell, not to "reject," not even to check. Interaction is the payload. Hide the token and move on; a real airdrop never needs your phrase or a rushed signature.
Fake support and the seeded-wallet trap
No legitimate wallet support team DMs you first, asks for your phrase, or routes you to a "sync" or "validate" page. Fake support is the highest-volume social attack there is, because the ask is the entire attack — your phrase, handed over politely to someone who sounded helpful.
Its cousin is the seeded-wallet honeypot: someone sells or "leaks" a phrase to a wallet that visibly holds tokens. Send gas to move them and a sweeper bot drains the deposit in the same block — the tokens were never the prize. Any phrase that arrives in your inbox is a trap by definition; a real holder would never give one away.
The field guide — and the honest limits
Five threats, five tells, five moves:
| Threat | What you see | Your move |
|---|---|---|
| Clipper | Pasted address differs mid-string from what you copied | Re-copy and verify the whole string, not the edges |
| Address poisoning | Lookalike transfer entries in your history | Never copy recipient addresses from history |
| Bait token / NFT | Unsolicited asset; a site offering a "claim" | Do not interact — hide it and move on |
| Fake support | First-contact DM; asks for a phrase or a "sync" | Block and report — real support never asks |
| Seeded wallet | A "free" or found phrase holding visible funds | Ignore — gas you send is swept instantly |
Now the honest limit: no wallet can fully patch the human layer, and Nova is no exception. A clipper swaps the address outside the wallet entirely — verifying after you paste is yours to do, always. What on-device tooling can do is shrink the signing surface: Nova Shield screens every transaction before you sign — on-device, across eight exploit classes — and flags risky recipients and approval requests. Zero telemetry means your activity is never harvested; it also means we cannot see a scam happen, so you remain the last checkpoint. Tooling plus habits — that is the realistic defense.
Nova Shield reviews transactions on-device before you approve them — flagging risky recipients, approvals, and drain patterns — while air-gapped phrase input and zero telemetry keep the rest of the surface small. No accounts, no KYC.