BlocktoBlockto
CrowdStrike, US Authorities Take Down Russian Botnet That Stole Crypto for 8 Years
TECH

Photo: Illustrative

CrowdStrike, US Authorities Take Down Russian Botnet That Stole Crypto for 8 Years

CrowdStrike and federal law enforcement have dismantled Sality, a Russia based botnet active since 2003 that spent the last eight years quietly hijacking cryptocurrency transactions. The malware exploited a common habit among crypto users: copying and pasting long wallet addresses instead of typing them manually.

Tristan R.
By Tristan R.

Senior Author · September 2, 2026

2 min
Key takeaways
CrowdStrike and federal law enforcement have dismantled Sality, a Russia based botnet active since 2003 that spent the last eight years quietly hijacking cryptocurrency transactions.
The malware exploited a common habit among crypto users: copying and pasting long wallet addresses instead of typing them manually.
How the Attack Worked The malware's core component, dubbed EggJagger by CrowdStrike, monitored infected computers' clipboards.

CrowdStrike and federal law enforcement have dismantled Sality, a Russia based botnet active since 2003 that spent the last eight years quietly hijacking cryptocurrency transactions. The malware exploited a common habit among crypto users: copying and pasting long wallet addresses instead of typing them manually.

How the Attack Worked

The malware’s core component, dubbed EggJagger by CrowdStrike, monitored infected computers’ clipboards. Whenever it detected something resembling a bitcoin or ether address, it silently swapped the copied text with an address controlled by the attacker.

Victims who pasted and sent funds had no way to catch the switch, and the transaction could not be reversed. Security experts recommend checking the first and last characters of any pasted address before confirming a transaction.

Losses Reached Over $1 Million at Peak Prices

CrowdStrike estimates the attackers stole at least 12.1 million rubles, roughly $150,000, over eight years. Much of that crypto sat untouched in wallets, and as prices rose, its value climbed to as much as $1.35 million by early 2025.

No Central Server, But a Fatal Flaw

Sality had no single command server to shut down. Instead, infected machines communicated directly with each other, checking in roughly every 40 minutes and spreading through shared network drives and USB devices. The system accepted any responding computer as part of the network without verifying its identity, a weakness CrowdStrike exploited to insert its own servers and cut off communication.

More Than 15,000 Machines Isolated

The takedown was carried out during a live demonstration at CrowdStrike’s Day Zero summit in Las Vegas, isolating over 15,000 infected machines from the botnet. Authorities confirmed the operation was based in Russia.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Tristan R.
Tristan R.

8+ years covering crypto markets, macro, and geopolitics. Previously at Decrypt and CoinDesk. Focused on the intersection of digital assets and traditional finance.