ClickFix Campaign Abuses Google Sheets and Browser JavaScript to Swap Crypto Wallet Addresses on SwapZone and SimpleSwap
Cisco Talos details a ClickFix campaign, active since October 2025, that tricks crypto traders into pasting JavaScript via Chrome's address bar or a Tampermonkey extension to hijack deposits on SwapZone and SimpleSwap; since March 2026 it fetches payloads…
Cisco Talos is tracking a months-long ClickFix campaign that shifted from OS command execution to browser-based JavaScript injection targeting sessions on two crypto swap services, SwapZone and SimpleSwap. Lures posed as leaked vulnerability reports describing non-existent API flaws, promising loyalty bonuses and payouts up to 38% higher. Victims are led to paste JavaScript into Chrome's address bar or install a Tampermonkey extension; since March 2026 the loader fetches obfuscated JavaScript from cells in public Google Sheets via the Visualization API, and a Tampermonkey variant in use since April 2026 re-injects the payload on every return visit, giving the attackers persistence despite takedown efforts. The payload behaves like a web skimmer, rewriting deposit addresses on screen and in web responses, inflating displayed amounts, hijacking the clipboard, and overriding the fetch API. Talos counted 49 attacker-controlled Bitcoin addresses, 24 of which received at least 0.159 BTC (~$10,000) by early August 2026, with proceeds routed through roughly 30 wallets and more than 3,000 addresses in apparent mixing. The campaign survived two disruption attempts; Talos urges role-based extension restrictions and browser monitoring.
- Cisco Talos reported the campaign on September 9, 2026; it began in October 2025.
- Targets two cryptocurrency swap services: SwapZone and SimpleSwap.
- Lures pose as leaked vulnerability reports describing non-existent API flaws, promising loyalty bonuses and payouts up to 38% higher.
- Victims paste JavaScript into Chrome's address bar or install a Tampermonkey extension.
- Since March 2026, the loader fetches obfuscated JavaScript from public Google Sheets cells via the Visualization API; Tampermonkey usage observed from April 2026.
- The payload swaps deposit addresses on screen, in web responses, and in the clipboard, inflates displayed amounts, and overrides the fetch API.
- The Tampermonkey variant re-injects the payload on every return visit, persisting despite takedown efforts.
- 49 attacker-controlled Bitcoin addresses tracked; 24 received at least 0.159 BTC (~$10,000) by early August 2026, and Talos believes actual losses are likely higher.
Coverage timelineoldest first · each row is one article
- · 6d agoHackers Abuse Google Sheets to Hijack Crypto Wallet Addresses in ClickFix Attacks
Cyber Security News· 55
Cisco Talos details a crypto-theft ClickFix campaign abusing Google Sheets to swap wallet addresses, with about $10,000 in observed Bitcoin losses.
- · 6d agoClickFix Moves into the Browser to Steal Cryptocurrency
Infosecurity Magazine· 48
Cisco Talos details a ClickFix campaign injecting browser JavaScript via Google Sheets to skim crypto deposits, stealing at least ~0.159 BTC since October 2025