U.S. cybersecurity firm CrowdStrike and federal law enforcement agencies have dismantled the Salty botnet, which secretly replaced users' cryptocurrency wallet addresses to steal funds, Coindesk reported. Salty has been active since 2003 and has been used to intercept cryptocurrency transfers for the past eight years. The core of the attack was the malicious program 'Egzecutor,' which monitored users' clipboards. When a user copied a Bitcoin or Ethereum wallet address, Egzecutor detected it and changed it to the attacker's wallet address. If the victim did not notice the address change and pasted it as is to send funds, the funds would be transferred to the attacker. CrowdStrike estimated that at least 12.1 million rubles, approximately $150,000, were stolen over eight years. The attackers held a significant portion of the stolen cryptocurrency, and with price increases, the asset value swelled to up to $1.35 million by early 2025.