Skip to main content
  1. Home
  2. Computing
  3. News

Opera’s new Paste Protect feature stops the clipboard attack your antivirus can’t catch

ClickFix attacks trick you into compromising your own device, and no major browser had a native defense against them until now.

Add as a preferred source on Google
Opera Paste Protect featured
Opera

Most online scams are easy enough to spot once you know what to look for. Fake login pages, suspicious attachments, or urgent wire transfer requests are dead giveaways. But ClickFix doesn’t look like any of them. It presents itself as a solution, and it asks you to do something so routine that few people think twice about it.

The technique was behind more than 53 percent of malware loader incidents last year, according to cybersecurity firm Huntress, and no major browser had a native defense against it until now. Opera is fixing that with a new feature called Paste Protect.

Why ClickFix slips past your computer’s existing defenses

A typical ClickFix attack begins on a webpage that claims something has gone wrong, like a video that won’t play or a CAPTCHA that keeps failing. The page then walks you through fixing it, which involves copying a command and running it on your computer. That command can install malware, steal saved passwords, or give an attacker remote access to your device.

ClickFix attacks are so effective because you are the one carrying out these actions, instead of an external threat that antivirus software is built to detect. A command you paste into the terminal doesn’t fit that profile, and your clipboard goes unexamined by most security tools.

Recommended Videos

Another exploit, called clipboard hijacking, uses the same gap differently. Rather than tricking you into copying something harmful, it waits for you to copy something legitimate and quietly swaps it out. For instance, if you copy a bank account number or crypto wallet address and paste it somewhere, what actually gets pasted may belong to an attacker. Opera’s Paste Protect is designed to block both of these attacks.

What Paste Protect actually does

In a blog post, Opera explains that Paste Protect consists of two distinct components. The first, Hijack protection, has been part of Opera since 2021, and it monitors your clipboard for unauthorized changes made by external applications. If something tries to swap out what you copied without your knowledge, it gets caught before you paste.

The newer addition is Injection protection. It screens clipboard content in real time and checks it against patterns commonly associated with malicious scripts on Windows, macOS, and Linux. When something is flagged, the copy action stops immediately, and a warning pop-up appears explaining what was caught. A red icon also shows up in the address bar, and you can expand the alert to see the first 120 characters of the blocked content.

Start safer with Opera One.

Meet Paste Protect: Opera’s unique feature that blocks suspicious clipboard attacks before you click paste.

Built into Opera One, for a more protected browsing experience from the first tab. pic.twitter.com/KqsDoqH9W5

— Opera (@opera) July 2, 2026

Paste Protect is enabled by default on the desktop version of Opera, so you don’t need to change any settings to safeguard yourself from ClickFix attacks. If you’re a developer who regularly copies commands from trusted sources like GitHub, you can override the block with a five-second hold, or permanently whitelist specific websites through the Privacy and Security section in Opera’s settings.

No other major browser currently offers anything comparable natively. Chrome users can install third-party extensions like ClickFix Block to get some level of protection, but that requires knowing the threat exists in the first place. For now, Paste Protect makes Opera the only major browser where the protection is there by default.

Pranob Mehrotra
Pranob is a seasoned tech journalist with over eight years of experience covering consumer technology. His work has been…
Google’s new Magic Pointer Play Store listing reveals a Gemini shortcut built for Googlebooks
The unannounced app turns the cursor into a contextual AI tool for search, image creation, and shopping
Plant, Text, Business Card

Google has quietly published a new Play Store listing for Magic Pointer, an unannounced app built for Googlebooks. Updated on July 10, the app turns the cursor into a Gemini shortcut that can act on whatever a user selects on screen.

Magic Pointer can send an image to Lens, generate a related image, or surface a shopping action without forcing users to open a separate chatbot. Regular Android devices currently show as incompatible, so the listing offers an early preview rather than a broad release.

Read more
You can stop using AI, but this new report says you probably can’t escape it
A UK survey found that most people feel AI exposure is unavoidable, raising harder questions about consent, privacy, and whether opting out is still realistic
AI Chatbots

More people are trying to use less AI, but avoiding it altogether may already be impossible.

A survey of 2,055 UK adults found that 42% deliberately limit how much AI they use. Another 70% said avoiding AI exposure would be difficult or impossible, even when they actively wanted less of it.

Read more
The face on an AI interviewer may matter as much as the decision it makes
Researchers found that race and gender matching changed how fairly rejected applicants viewed an automated interview, even though everyone received the same outcome
File, Computer Hardware, Electronics

An AI hiring system can treat every applicant the same and still leave some people feeling targeted. Researchers found that rejected candidates judged an automated interview differently depending on the race and gender of the avatar delivering the result.

Around 220 participants completed a simulated interview for a fictional customer support role with one of four photorealistic AI avatars. Everyone was rejected, yet perceptions of fairness shifted with the interviewer’s appearance. An algorithm audit could miss that reaction because candidates don’t experience the system as raw code. They experience a face asking questions and judging their answers.

Read more