Hacker News new | ask | show | jobs
by dan-robertson 1758 days ago
The exploit was that the victim downloaded some malware (that came bundled with software he intended to download) which ran in the background looking for a Bitcoin address in his clipboard and quickly replacing it with a different one. It wouldn’t be possible to do that in an ordinary JavaScript application (lots of restrictions on clipboard access) and the malware was not a website so turning js is irrelevant