Security Hub

Sality Botnet Dismantled After Eight Years of Crypto Theft

Published: Sep 2, 2026By Aleksandar Dukic

Key Analysis

CrowdStrike and the DOJ isolated 15,000+ machines infected by Sality, an eight-year malware operation that stole Bitcoin and Ethereum from victims worldwide.

Sality Botnet Dismantled After Eight Years of Crypto Theft

Listen To This Article

Sality Botnet Dismantled After Eight Years of Crypto Theft

5m 22s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

CrowdStrike and the U.S. Department of Justice have dismantled Sality, a malware operation that ran for eight years and stole Bitcoin and Ethereum from infected computers. According to reporting from Decrypt, the takedown isolated more than 15,000 compromised machines spread across multiple countries. It is a rare, clean win against the kind of organized cybercrime that quietly targets ordinary crypto holders rather than exchanges or protocols.

Sality was not a flashy exchange hack or a bridge exploit. It was patient. For eight years it sat on victims' machines, waiting for the moment a wallet was opened or a clipboard held a wallet address, then moving funds out. That patience is the point. The most durable crypto theft is not the headline-grabbing $9.7 billion liquidation event. It is a small percentage skimmed from thousands of people who never knew their device was compromised.

Inside the coordinated takedown

The operation paired a private security firm with federal law enforcement. CrowdStrike handled the technical side of identifying and isolating infected endpoints, while the DOJ provided the legal authority to seize infrastructure and coordinate across jurisdictions. Isolating 15,000-plus machines is the hard part. Botnets survive by being distributed, so cutting off the command channel and severing infected hosts from the operators is what actually stops the bleeding.

The eight-year runtime tells you how these operations persist. Malware families like Sality mutate, change their command-and-control servers, and reinfect. A single arrest rarely ends them. A coordinated takedown that seizes the infrastructure and isolates the hosts at the same time is what breaks the cycle, and even then the code often resurfaces under a new name.

The theft mechanic that catches people

Most crypto-stealing malware does not need to break cryptography. It waits for you to do the work. Two techniques dominate:

  • Clipboard hijacking. You copy a wallet address to paste it into a send field. The malware silently swaps it for the attacker's address. You paste, confirm, and sign a transaction that looks correct at a glance but sends to a wallet you have never seen.
  • Credential and seed theft. The malware scrapes browser sessions, keylogs a password, or reads a seed phrase saved in a text file or screenshot. Once it has the seed, it does not need your device again. It can drain the wallet from anywhere.

Neither technique attacks the blockchain. They attack the human at the keyboard and the machine under the keyboard. That is why an exchange's security budget does not protect you here. If the private key touches a compromised computer, the strength of the underlying network is irrelevant.

The Sality takedown is a good outcome, but it is also a reminder that the endpoint is the weak link. A few practices meaningfully cut the risk:

Keep signing keys off general-purpose machines. A hardware wallet keeps the private key on a separate device that signs transactions without exposing the seed to your PC, so clipboard swaps and keyloggers have nothing to steal. This is the core case for spending from your own wallet with hardware-backed signing rather than leaving keys in a hot software wallet on a daily-driver laptop.

Verify the full destination address, not the first and last four characters. Address-swapping malware often generates a lookalike address that matches the visible ends. Check the middle.

Treat any seed phrase stored digitally as already compromised. Screenshots, cloud notes, and text files are exactly what these families scan for.

For everyday spending, this is part of why custody design matters when you pick a card. A crypto card that draws from a self-custodied wallet shifts the security burden onto your own key hygiene, which is a benefit only if that hygiene is sound. A custodial card program moves the counterparty risk to the issuer instead. Neither is automatically safer. The Sality case simply shows that the device you sign on is a live attack surface, and hardware separation is the cheapest way to shrink it. Tools like a dedicated hardware wallet from Ledger exist specifically to keep the key off the infected machine.

The broader signal

Takedowns like this are getting more coordinated, and that is the encouraging part. Pairing a commercial security vendor's telemetry with the DOJ's legal reach is a template that has now worked against an eight-year operation. It will not stop malware authors from rebuilding, but it raises the cost and shortens the runway.

For context, the market barely noticed. As of September 2, 2026, Bitcoin traded at roughly $76,606, down 1.8% on the day, with Ethereum near $2,376. Malware takedowns do not move price because the theft they target is diffuse and off-market. The impact lands on individual victims, not order books, which is exactly why it goes underreported relative to a single large exploit.

Overview

CrowdStrike and the DOJ dismantled Sality, an eight-year botnet that stole Bitcoin and Ethereum by isolating more than 15,000 infected machines. The malware relied on clipboard hijacking and seed theft rather than attacking the blockchain itself, which is why endpoint hygiene and hardware-based key separation matter more than the security of any exchange or network. The takedown is a template win, but the code will likely resurface, so the practical takeaway is to keep signing keys off internet-connected general-purpose machines.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.