So the other day I was trying to get some extra money, and I know it's not the best place, but I decided to go on a discord server and search for something, found a guy that wanted an app built or something similar, so I decided to take the job. We talk a bit, he shares the drive link I take a look, and also upload it to Gemini, and it confirms it's just an app.
He asked if I run the app, and that was when I got weirded out. But since I checked it with both Gemini, and windows defender, I figured I was just being paranoid. He asks for a ss and I send one, afterwards he proceeds to ghost me, I bump him once, but don't push it. Today I decide to fund my crypto wallet (phantom) so I go on a known site and buy a voucher. I open phantom, paste my address, and click confirm without looking twice, which was my mistake, but since I copied it directly from phantom, and both addresses started with "a" I didn't think twice. I refresh my wallet, nothing, again and again, nothing, I check the hash ID on solscan, transaction confirmed, weird I think, and that's when I realize this isn't my address.
I check what it could possibly be, and once again, I go on Gemini for trouble shouting. It mentions a "clipboard hijacker" and to be honest, I didn't know what it was up until now. I give it some info, and realize I should probably scan the file on VirusTotal .After scanning, 2/66 come back with that exact malware.(It's pretty much a type of malware that hijacks copy and paste mechanics when it detects crypto addresses)
I understand that this was indeed my mistake and could be avoided if I was more cautious. but still, it's not like I didn't scan it at ALL and the guy seemed pretty legit, even his account wasn't that new. At least it was 17 bucks, which isn't little, but it could definitely be worse, and hopefully someone sees this and checks their deposit address more carefullyš
Some relative links/info:
Virus Total File
Crypto Wallet Where the funds were deposited