The same attack, one layer deeper
The malware that rewrites your clipboard runs on the same machine where people keep seed phrases in notes apps, private keys in text files, and 2FA backup codes in screenshots. A clipboard watcher doesn’t just swap addresses. It scans everything that passes through for anything shaped like a key. Unencrypted text on an infected machine is already gone. The address swap is just the version you get to watch happen. That is the case for keeping keys and codes in an encrypted vault on your device, and for never letting a real seed phrase touch a clipboard at all.