
You copied a Bitsz deposit, pasted it into Send, glanced at the first and last characters, they matched, and you signed. Clipboard malware can replace a deposit address after Copy, keeping those edges while the middle belongs to an attacker. Compare the full pasted string to this order’s UI before you broadcast. You will split payout from deposit, stop on any mismatch, read a hardware-wallet screen, and pack Order ID plus TxID for support if the coins already left.
Quick answer: A clipper swaps a crypto address in your clipboard after Copy. Bitsz has two paste surfaces: Recipient’s address (payout) and the one-time deposit (pay-to). Copy the deposit only from this order screen. Compare every character, including the middle. There is no “address verified” chip. HTTPS does not watch your clipboard. If the strings differ, do not sign. If a TxID already went to the swapped To, send Order ID plus TxID to official support. Do not expect recovery.
Bitsz is a non-custodial instant exchange (since 2023). After you click Exchange you get a unique one-time pay-to string for this request. A clipper hits whichever string you just copied, not the TLS padlock. If the order host is not bitsz.io, leave that page and use the official Bitsz domain checklist.
Copy the deposit only from this Bitsz order (paste checklist)
Copy pay-to from this order UI.
Recipient’s address is the payout: copy it from a Receive screen you control, then paste it into the widget. The one-time deposit is the pay-to string: copy it from this order UI, then paste it into wallet Send.
Do this: keep those two strings apart. Do not paste last week’s deposit, a chat message, or a screenshot. Reusing a unique pay-to string is a different failure; use the one-time swap address reuse checklist. Do not treat Recipient’s address as the string you pay.
| String | Bitsz one-time deposit (pay-to) | Recipient’s address (payout) | Clipper replacement |
|---|---|---|---|
| Paste direction | Copy from Bitsz, paste into wallet Send | Copy from your Receive, paste into the widget | Whichever you just copied |
| First and last characters | May match a lookalike | May match a lookalike | Often designed to match |
| If already sent there | Can credit this order if unique and the network matches | Bitsz pays you | Third-party send; recovery is not promised |
Verdict: Start with the Bitsz swap widget, paste Recipient’s address from a wallet you own, then copy the one-time deposit only from this order. First and last characters are not a pass.
Compare the full pasted string, not only the first and last characters
Read the middle, not only the edges.
A clipper needs a lookalike that survives a two-second glance. Microsoft’s CryptoBandits write-up (17 June 2026, active since February 2026) describes replacements that keep the first two characters on many Bitcoin “1”/”3″ and Tron “T” formats, and only the last character on “bc1q” and “bc1p”. Laplas-style tools match both ends on Bitcoin. Check Point Research (17 June 2026) described a pool of over 15,500 attacker wallets.
Some convert pages and wallet blogs still say the first and last 4-6 characters are enough. That is a speed habit, not clipper defense. Do not follow that here. Do this: read the middle. Do not type a long address by hand.
Workflow: First copy the one-time deposit from this Bitsz order UI. Then paste it into wallet Send. Next compare every character, including the middle, to the same order screen. Then, if you use a hardware wallet, read the destination on the device. Do not sign if any character differs.
- Confirm the order page is bitsz.io before you copy anything.
- Copy Recipient’s address only from a Receive screen you control.
- Create the Bitsz request, then copy the one-time deposit only from this order UI.
- Paste that deposit into wallet Send, or paste payout into the widget if that was the step.
- Compare the entire pasted string to the same Bitsz screen, including the middle characters.
- If any character differs, abort the signature and do not send a test amount to the new string.
- Paste the same copy into a local text file. If the file matches the order but the wallet field does not, distrust the browser.
- On a hardware wallet, read the full destination on the device screen and abort if it is not the intended string.
- Sign once, send the exact You send amount to this order’s unique deposit, and save Order ID.
- After broadcast, confirm explorer To equals this order deposit. If To is swapped, collect Order ID plus TxID for official support.
Make sure you check this order, not a saved address from yesterday.
Avoid broadcasting if the pasted string differs
Stop on mismatch. Do not test-send.
If pasted is not the UI string, do not broadcast. Do not invent a Bitsz “address verified” badge. The live widget (3 October 2026) shows You send, You receive, Network, Floating or Fixed, Recipient’s address, and Exchange. There is no address-verified chip. HTTPS encrypts the channel to bitsz.io. It does not watch your clipboard.
Do not send a small payment to “test the problem.” A micro-send to a swapped string is a gift to the attacker. If a local text file matches Bitsz but the wallet field does not, suspect an extension (McAfee Silent Swap, 30 June 2026). A clean Notepad paste is not a green light. Recopy on a clean profile or another device.
If the source page now shows a new address without a paste mismatch, recopy from this order (rotation). If a lookalike sits in history and the clipboard never changed, recopy from live Receive; that is address poisoning, not a clipper.
Do this: abort the signature, recopy from the order UI, and compare again. Do not trust the padlock as clipboard defense. Do not send a test amount to the swapped string.
Checking the hardware wallet destination screen before you sign
A hardware wallet is a small signing device with its own screen. Malware on the computer can still swap what you copied. It cannot rewrite Trezor’s Trusted Display: if destination or amount mismatch, do not approve. Ledger says abort and read the address the device will sign. A Ledger Live clipboard-mismatch warning is a stop. Confirmed device transfers cannot be cancelled. The laptop matching Bitsz is not the source of truth.
If you only skim prefix and suffix on the device, a lookalike can pass. Read the full destination. With no hardware wallet, use a QR from the order screen, not the clipboard.
Do this: compare the device text to the intended full string, then approve only on a match. Do not approve because the laptop looked fine.
If you already sent to a swapped address, collect Order ID and TxID (support checklist)
A confirmed on-chain send to the attacker’s To is a third-party payment. Bitsz does not hold, store, or manage your funds. Terms of Use 2.5 cover incorrect addresses. 6.3 puts verification before submission on you. 6.5 may refuse a valid request and return coins to the sender (live copy: refund handled manually, up to 68 hours). That is not a clawback from a clipper wallet.
Save Order ID and TxID. Write Bitsz support (support@bitsz.io) with intended vs pasted destination, Network chip, ticker, and the explorer URL. Check To on mempool.space, etherscan.io, or tronscan.org. Do not expect recovery. Do not send a seed phrase. If someone DMs you as “support” after a miss, use the fake exchange support checklist.
A “T” vs “0x” clash is a network miss, not a clipper. Wrong You send vs wallet debit is an amount miss. A return you hoped would land in You receive is a refund-destination question, not a clipper clawback.
Do this: send the Order ID plus TxID packet to official support and stop extra deposits. Do not promise yourself a clawback. Do not broadcast a second payment to the hijacked To.
FAQ
Is checking the first and last characters enough against a clipper?
No. Lookalike clippers keep the first two characters or only the last character. Compare the full pasted string to this order’s UI, including the middle.
Can Bitsz reverse a send to a hijacked address?
No. A confirmed send to the attacker is a third-party payment. Terms 2.5 and 6.3 put address errors on you. Terms 6.5 returns a valid request to the sender, not a clawback. Save Order ID and TxID and write support. Do not expect recovery.
Does HTTPS or the Bitsz badge stop clipboard malware?
No. TLS and the site badge protect the channel to bitsz.io. They do not watch your device clipboard. If the host is not bitsz.io, use the official-domain checklist instead.
Should I type a long address by hand?
No. Typing creates a different error class. Copy from this order UI or a Receive screen you control, then compare the entire paste. On a hardware wallet, still read the device screen.
I pasted into Recipient’s address. Is that the Bitsz deposit?
No. Recipient’s address is the payout (You receive). The one-time deposit is where you send You send. Check both strings if you touched both fields. A clipper can hit either paste.
The pasted address matches in Notepad but changes in the wallet. What should I do?
Treat the browser as untrusted. Do not send. Recopy on a clean profile or another device. Matching Notepad does not prove the Send field is clean.
Ledger Live warned about a clipboard mismatch. What now?
Abort. Read the full destination on the Ledger screen. If it is not the intended Bitsz deposit or payout, do not sign. Confirmed transfers cannot be cancelled.
Disclaimer: The material in this article is not financial or investment advice. Everything stated here reflects the author's personal view and should not be treated as a recommendation to trade or invest. We make no warranties regarding the accuracy, reliability or completeness of the information presented. Cryptocurrency markets are highly volatile and can move unpredictably. Before committing any funds, every investor, trader or crypto user should study several independent sources and check the regulations that apply in their own jurisdiction.