Sality Botnet Disrupted After Crypto Wallet Theft
An international law-enforcement operation led by US authorities has disrupted the Sality botnet, a malware network active since 2003. Officials in Bulgaria, Hungary and Romania, supported by Europol, Eurojust, CrowdStrike and the Shadowserver Foundation, seized domains and redirected infected computers to sinkhole servers.
Sality evolved into a peer-to-peer botnet that once reached up to 1 million computers. More than 11 million unique IP addresses have been linked to its infrastructure. Before the operation, CrowdStrike identified more than 15,000 infected devices still receiving malicious payloads.
For about eight years, Sality distributed EggJagger clipboard-hijacking malware. The tool replaced copied Bitcoin and Ethereum wallet addresses with attacker-controlled addresses. CrowdStrike estimates the crypto theft generated at least $150,000, while the value of never-spent digital assets reached about $1.5 million in January 2025.
The Sality disruption cut off the botnet’s existing command structure but did not remove malware from infected devices. No arrests were reported, and operators could try to rebuild the network. The event is unlikely to move Bitcoin or Ethereum prices materially, but traders should verify wallet addresses before transfers and strengthen endpoint security.
Neutral
The disruption is primarily a cybersecurity development rather than a change in cryptocurrency fundamentals, liquidity or regulation. It is therefore unlikely to create sustained buying or selling pressure in Bitcoin or Ethereum.
In the short term, traders may briefly react to reports of wallet theft or renewed malware activity with caution, but the estimated loss of at least $150,000 is small relative to the market capitalisation and daily trading volume of both assets. The operation could also improve user confidence by limiting the botnet’s current command infrastructure.
The longer-term risk remains operational. Sality malware was not removed from infected devices, and the lack of reported arrests leaves open the possibility of a rebuilt network. Any future rise in clipboard-hijacking incidents could damage sentiment and increase transaction-related losses, but this event alone is not expected to materially affect Bitcoin or Ethereum prices.