Scam defense / Updated 2026-07-30

The 'Paste This to Continue' Trap: Fake CAPTCHAs and Fix-It Prompts That Drain Wallets

A fake CAPTCHA or 'fix this error' prompt that tells you to paste a command into your computer is not a fix. Learn how the ClickFix technique installs the malware that empties crypto wallets.

How this guide is checked

Official sources first, no wallet connection, no guaranteed returns.

Reviewed on 2026-07-30 by WildWildCrypto Safety Desk. Method: Human editorial review with official-source checks, affiliate-disclosure checks, and no-financial-advice checks.

Publisher: WildWildCrypto Editorial. Corrections go through the contact page. We do not ask for seed phrases or tell you what to buy.

fake CAPTCHA paste command scam matters because You are trying to watch a video, join a call, or fix a stubborn error, and a box appears telling you to press two keys and paste something to continue. It looks like a formality. It is the whole attack.

This guide shows you exactly what that instruction is, why it defeats antivirus, and the single rule that makes it fail every time.

You will learn how the clipboard is loaded behind your back, which lures to expect, what the malware takes from a crypto user, and what to do if you already pasted.

What the 'paste this to continue' attack actually is

Security researchers call this technique ClickFix, and Microsoft Threat Intelligence describes the shape of it plainly: a page instructs the user to complete a human verification process by following the displayed instructions, and following those instructions launches malicious code. In practice you are told to copy something, press a key combination — Windows key plus R, or open Terminal on a Mac — paste, and hit Enter. Three or four small, obedient actions, none of which feels like installing software.

The deception sits in the copy step, because you never actually copy anything yourself. The page loads the attacker's command onto your clipboard in the background the moment you interact with the fake verification checkbox. Microsoft documented pages that reference a hidden file through an invisible frame precisely to trigger that clipboard write. So the text you paste is not the text you think you are moving; it is a command that fetches and runs a program from the attacker's server.

That detail is what makes this different from every scam that came before it. Nobody sent you an attachment. Nobody needed you to enter a password. There is no suspicious download for a browser to block, because the browser did not download anything — you opened your own operating system's command box and ran an instruction with your own hands. From the machine's point of view, the owner made a choice. This is why the technique spread so fast: it converts a security decision into a chore, and people do chores without reading them.

Checklist

  • The instruction always moves you out of the browser and into a system command box.
  • The clipboard is loaded by the page, not by you.
  • Nothing is downloaded through the browser, so download warnings never fire.
  • You supply the execution, which is exactly what the attacker cannot do alone.

Why crypto users are the ones who pay for it

What lands after the paste is almost always an infostealer — software whose entire job is to sweep a machine for anything sellable and send it out in one pass. Microsoft's May 2026 analysis of a macOS ClickFix campaign lists what these families collect: browser credentials, Keychain entries, iCloud data, and cryptocurrency wallets. The same report names the wallet applications targeted directly — Exodus, Ledger Live, Trezor Suite, Electrum, and Monero — and notes that the malware replaces legitimate cryptocurrency wallet apps with trojanized versions, so the app you open tomorrow may no longer be the app you installed.

For a crypto holder this is not one theft, it is a sweep of every access route at once. Browser session cookies can carry an attacker into an exchange account without a password. A stored password vault can unlock email, and email can reset almost everything else. Wallet files and any recovery phrase that was ever typed, screenshotted, or saved on that computer are read at leisure, offline, long after you closed the tab.

The scale explains why you will meet it rather than read about it. Microsoft reported ClickFix campaigns targeting thousands of enterprise and end-user devices globally every day, with its Defender Experts team observing thousands of devices affected per month in early 2025, and a single malvertising campaign drawing tens of thousands — if not hundreds of thousands — of unique visitors in one day. There is no targeting here in the personal sense. It is a net, and ordinary users with a browser wallet holding a few hundred dollars are caught in exactly the same pass as anyone else.

One structural point is worth holding onto: a hardware wallet's private keys are never present on the computer for an infostealer to read. That does not make the device immune to every consequence below, but it removes the single most valuable thing on the machine from the sweep.

The lures you will actually meet

The most common wrapper is a fake human-verification box. Microsoft documented pages impersonating Cloudflare Turnstile and Google reCAPTCHA prompts — the exact widgets you have clicked through a thousand times without incident — alongside impersonations of Microsoft Word, Google Meet, Booking.com, Discord, and even the Social Security Administration. The lure works on familiarity, not fear: you are not being threatened, you are being asked to do the boring thing you always do.

The second wrapper is the helpful fix-it article. The 2026 macOS campaign Microsoft analysed did not use fake CAPTCHAs at all. It planted troubleshooting posts on legitimate publishing platforms — blog posts on Medium, pages on Squarespace, notes on the Craft platform — offering storage-optimisation and system-repair instructions in several languages. Someone searching for a genuine problem finds a genuine-looking answer, and the answer is a command to paste into Terminal.

The third wrapper is a live conversation, and it is the one crypto users meet most often. Sekoia's analysis of a fake-interview campaign documented more than forty lookalike job-interview websites where a candidate is asked to record a short video introduction, then hits a staged error claiming the camera or microphone is blocked, with a helpful instruction to paste a command to fix the driver. The error is fabricated to produce the paste. If you are job hunting in crypto, read that pattern together with our guide on fake job offers, because the interview is the delivery vehicle and this is the payload.

Expect the names and the packaging to keep changing — Microsoft has already published on variants of this family across Windows and macOS, using different bait each time. The instruction is the constant, not the costume.

Checklist

  • Fake 'verify you are human' boxes that ask for keystrokes instead of a click.
  • Search-result articles offering a paste-in fix for a common computer problem.
  • Video calls or interview sites reporting a camera or microphone error with a paste-in repair.
  • Fake update or repair prompts branded as Microsoft, Google, Discord, or a government agency.

The rule that defeats all of it

Adopt one rule and this entire attack family stops working: never paste anything into Run, Terminal, PowerShell, or a command prompt because a web page, a chat message, or a person on a video call told you to. Real verification happens inside the browser window. A real Cloudflare or Google check never asks for keystrokes outside it. A real video call never repairs a microphone by having you run a command. If the instruction crosses that boundary, the answer is no — regardless of how legitimate the page, the brand, or the person appears.

Apple now enforces a version of this at the operating-system level. Microsoft's report notes that macOS 26.4 and later warn users directly when this pattern is detected, telling them that pasting is blocked because scammers often encourage pasting text into Terminal. Treat that message, or any similar warning from your system, as a full stop rather than an obstacle to work around. On Windows, the tell is any instruction mentioning the Windows key plus R, since that key combination exists to run commands and has no role in verifying that you are human.

If you have already copied something, do not open a command box to inspect it — copy some harmless text over it to clear the clipboard, close the page, and move on. Beyond that, reduce what a single compromised machine can cost you: keep the private keys for meaningful holdings on a hardware wallet so they never exist on the computer at all, protect your primary email and exchange logins with a hardware security key rather than codes that can be replayed, and keep your operating system and browser updated so the surrounding defences are current.

Checklist

  • Never paste a command into Run, Terminal, or PowerShell on a stranger's instruction.
  • Treat a system warning about pasting into Terminal as final, not advisory.
  • Any mention of Windows key plus R in a 'verification' step is the giveaway.
  • Overwrite the clipboard and close the tab instead of inspecting the command.
  • Keep meaningful keys on a hardware wallet, so an infected computer has nothing to read.

If you already pasted the command

Assume the whole device is compromised rather than one application, and stop using it for anything sensitive immediately. Because these payloads harvest credentials, wallet files, and session cookies in a single sweep, changing one password on the same machine simply hands the attacker the new one. Move to a different, clean device — a phone that was never involved is fine — and work from there.

From that clean device, work in order of blast radius. Change your primary email password first and sign out of all active sessions, because email is the reset path to everything else. Then do the same for exchange accounts, and enable app-based or hardware two-factor authentication if you were relying on text messages. Treat any hot wallet whose keys or recovery phrase ever existed on the infected computer as burned: create a new wallet on a clean device and move the funds, rather than trusting that the old one was missed. Review and revoke outstanding token approvals from the new wallet's perspective, and check for wallet applications that may have been replaced with trojanized versions by reinstalling them from official sources after the machine is rebuilt.

Then deal with the machine itself. A full operating-system reinstall is the only reliable answer to an infostealer, since these families are designed to survive an antivirus scan that runs after the fact. Report the incident to the FTC and, if the loss is significant, to the FBI's Internet Crime Complaint Center — those reports are what let researchers and browser vendors flag the hosting infrastructure for everyone else. Finally, expect the follow-on scam: anyone who appears afterwards promising to recover stolen crypto for an upfront fee is running the second half of the same business, and the FTC's guidance on irreversible crypto payments applies exactly as it did the first time.

Checklist

  • Stop using the infected device for anything sensitive.
  • Work from a separate clean device, starting with your primary email.
  • Move funds to a wallet created on a clean device; treat the old one as exposed.
  • Reinstall the operating system rather than trusting a scan.
  • Report it, and ignore anyone offering paid fund recovery.

Authority sources used

Outbound links are included for verification and entity authority, not decoration.

FAQ

I pasted the command but nothing seemed to happen. Am I fine?

No — 'nothing happened' is the intended experience, not evidence that you escaped. These commands are written to run silently: they fetch a payload from a remote server and execute it in the background, often while the page you were on carries on as normal or finally lets you through to the content you wanted. There is usually no installer window, no progress bar, and no visible change, because the entire value of the technique depends on you not realising anything ran. What the malware does next is quiet by design too — reading browser credentials, session cookies, password stores, and cryptocurrency wallet files and sending them out in a single pass, which can complete in seconds. Treat any paste-and-run instruction you followed as a confirmed compromise regardless of what you saw on screen. Move to a different device, change your primary email password and sign out of all sessions from there, treat any wallet whose keys touched that machine as exposed, and reinstall the operating system rather than assuming a quiet screen meant a quiet outcome.

Why doesn't antivirus stop this?

Because from the machine's perspective, nothing suspicious was delivered — the owner opened a system command box and typed an instruction. There is no downloaded file for a browser to warn about and no installer for a scanner to inspect, since the command itself pulls the payload directly into memory using tools that are already trusted parts of the operating system. Security software is built to be cautious about intercepting a person's own deliberate commands, and that is precisely the gap this technique was designed to sit in. Modern endpoint protection does increasingly detect these patterns, and Apple now blocks and warns on suspicious pastes into Terminal on recent macOS versions, but detection always trails the newest variant and the family is repackaged constantly. This is why the defence has to be behavioural rather than technical: the reliable protection is refusing to paste a command on someone else's instruction in the first place, because that decision happens before any security product gets a chance to weigh in.

Is this only a Windows problem?

No. The technique started on Windows, where users are directed to the Run dialog or PowerShell, but Microsoft published a detailed analysis in May 2026 of a campaign built specifically for macOS, where victims were instead told to paste commands into Terminal. That campaign spread through fake troubleshooting and storage-optimisation posts hosted on legitimate publishing platforms in multiple languages, and the payloads collected browser credentials, Keychain entries, iCloud data, and cryptocurrency wallets, targeting wallet applications including Exodus, Ledger Live, Trezor Suite, Electrum, and Monero. Apple's response confirms how real the macOS version is: recent macOS releases now warn the user outright that pasting is blocked because scammers often encourage pasting text into Terminal. The safe assumption is that any operating system with a command line is a target, and the rule does not change between them — no legitimate website, call, or wallet ever asks you to paste a command into your system to continue.

How is this different from clicking a phishing link?

A phishing link tries to get something out of you — a password typed into a fake login page, or a signature approving a malicious transaction. This technique gets you to do something for the attacker instead: you personally execute code on your own machine, which is the one step remote attackers usually cannot take without an exploit. That difference matters practically. Phishing defences work by inspecting destinations and warning you about fake sites, and a password manager that refuses to autofill on a lookalike domain will often save you. None of that applies here, because the page you are on may be a real website, the widget may be a convincing copy of a genuine verification tool, and the damage happens in your operating system rather than in the browser. It also means the outcome is broader: phishing usually costs you one account or one transaction, while a successful paste hands over browser credentials, session cookies, stored passwords, and wallet files in a single sweep. The defences are complementary — verify domains for links, and never run commands for anyone.

Would a hardware wallet have protected me?

It protects the most important thing, but not everything. A hardware wallet generates and stores private keys on the device itself, so they never exist as files on your computer for an infostealer to read — which means the funds it secures are not directly drainable by this kind of malware, even on a fully compromised machine. That is a meaningful and specific protection, and it is the strongest argument for keeping serious holdings off browser-based wallets. What it does not cover is everything else the sweep collects. Exchange accounts reached through stolen session cookies or a stolen password vault are still at risk, as is any recovery phrase you once typed, photographed, or saved on that computer — including a hardware wallet's own phrase if it was ever entered there. Microsoft also documented malware replacing legitimate wallet applications with trojanized versions, so the companion app you use to interact with a hardware device should be reinstalled from official sources after any compromise. Verify addresses on the device's own screen before approving, keep the recovery phrase strictly offline, and the hardware wallet does the job it is built for.