Twice in 2026, months apart, I copied a cryptocurrency deposit address from an exchange and the transaction went to the same unrelated EVM address -- clearly I have some malware or something, or maybe something less malicious -- anyone have any advice?
Incident 1: I copied a Gemini BNB Smart Chain deposit address and withdrew BNB from Kraken. Gemini later confirmed that the destination was not associated with Gemini. This was done on a Firefox browser through Gemini and Kraken's website.
Incident 2: Six months later I copied a Kraken USDC/Arbitrum One deposit address and sent from MetaMask. It again went to the exact same unrelated address. This was done through an Opera browser via MetaMask extension.
Both were performed on the same Windows computer, using different browsers. The first incident did not involve MetaMask. I have successfully copied many other crypto addresses without this happening.
Has anyone encountered malware or a clipboard utility that selectively replaces only EVM addresses or triggers only inside crypto transaction forms? What diagnostic tools and persistence locations should I inspect?