# @ethstatus: separate privacy apps still expose metadata trails Source: https://x.com/ethstatus/status/2026686908265644440?s=46 ## Summary The article argues that privacy leaks between separate apps, not just inside them, because app switching, clipboard data, shared device identifiers and operating system learning engines let behaviour from different apps be correlated. It cites January 2026 attacks in which the "Pro.exe" clipboard hijacker, distributed by "RedLineCyber" through Discord communities, swapped copied crypto wallet addresses, and mid-February 2026 research by unnamed researchers into ZeroDayRAT, a commercial mobile spyware sold on Telegram that performs similar clipboard address injection. The article presents Status, a privacy super app that keeps chats, wallets, communities and browsing in one local-first environment, as a way to reduce these metadata trails. ## Article Most people think privacy is just about keeping their messages from being read. But in reality, every tap, pause, scroll, switch, and delay leaves a silent trail behind. That trail is your data footprint, data trails aren’t about one action. They’re about patterns, a single data point means nothing But stack thousands of small signals together and suddenly a system knows: • where you are • when you’re active • who you talk to • what you care about • what you’re likely to do next And most of this happens outside the message content itself. The invisible leaks happen between apps Here’s the part most people miss. You might use: • one app for private chats • another for your wallet • another for browsing • another for community spaces Each app might claim to be “private” on its own. But the moment you switch between them, your privacy starts to leak. Why? Because privacy is not just about what happens inside an app - it’s also about what leaks between them. Modern digital systems create many subtle connection points where data and behaviour can be captured and correlated. 1) App switching creates metadata trails Even if messages are encrypted, the fact that you used certain apps in sequence can be revealing. Systems and third-party services can infer behavioural patterns based on app usage order and timing. No one needs message contents - behavioural sequencing alone is powerful metadata. 2) Clipboard and keyboard data crosses app boundaries When you copy something in one app and paste in another (like a wallet address, private link, or username), that data temporarily lives in system-level clipboard history. Some keyboards log clipboard data for smart suggestions. Some apps have been found reading clipboard contents silently. Cloud clipboard sync can even move it to other devices. So data from a “private” app can leak through system utilities. Just this year, clipboard hijacking attacks have hit hard. In January 2026, attackers abused Discord communities (gaming, gambling, and crypto streaming) to spread "Pro.exe" a Python-based clipboard hijacker distributed by threat actor "RedLineCyber." It silently monitors the clipboard, detects crypto wallet addresses (BTC, ETH, etc.), and swaps them with the attacker's address the moment you paste, often right after switching from a Discord chat to your wallet or exchange. Funds were stolen irreversibly, with no obvious traces until it's too late. Even more recently, in mid-February 2026, researchers disclosed ZeroDayRAT, a commercial mobile spyware sold on Telegram targeting Android and iOS. It scans for popular wallet apps like MetaMask, Trust Wallet, Binance, and Coinbase, then performs clipboard address injection replacing copied addresses to reroute transfers to the attacker. It also collects broad cross-app metadata: app usage patterns, real-time location (plotted on maps), notifications, device model, OS details, and battery status. All while enabling live camera/mic access. No message content is needed; the leak is triggered on app switches and copy-paste actions. 3) Shared device identifiers tie apps together Even if apps don’t share data directly, they often share device-level signals such as advertising identifiers, IP address patterns, OS version, device model, and screen characteristics. Services embedded across multiple apps can correlate activity from the same device, like: “This same device used App A and App B within 3 minutes.” That links identities across apps without you logging into both with the same account. 4) System Learning Engines Connect Your Activity System learning engines connect your activity Your device operating systems learn behaviour patterns to provide suggestions and automation. These systems model cross-app activity (like opening Maps after Calendar events or sharing links from browser to chat apps). This creates a unified behavioral profile at the operating system level. Data brokers don’t need your messages They work with timing patterns, app usage graphs, location overlaps, and shared network signals. Combined, this makes it possible to infer financial status, interests, relationships, and community involvement. No encryption is broken - correlation itself becomes the leak. This is where Status privacy super app is different Status was designed around a simple idea: Privacy shouldn’t be fragmented and depend on how well you manage your digital interactions and settings across ten apps. It should be the default, cohesive, private environment you operate in. Instead of forcing users to constantly jump between apps and inadvertently leak their digital footprint, Status keeps your: ✦ chats ✦ wallets ✦ communities ✦ browsing inside one private, secure, local-first environment. Less switching = fewer digital trails. Fewer digital trails = fewer ways to tie your actions together Metadata is the real currency of the internet. Big platforms don’t need to read your messages. They just watch the patterns. Over time, those patterns become a behavioural fingerprint. Status is built to minimise metadata footprints, not just encrypt content. That distinction matters. Privacy isn’t hiding Real privacy isn’t about disappearing from the internet. It’s about: ✦ reducing unnecessary exposure ✦ avoiding cross-app identity stitching ✦ keeping interactions inside a single private environment When your chat, wallet, and browser live together, fewer external systems get a chance to observe you and fewer opportunities arise for the clipboard swaps, app enumeration, and massive metadata correlations we've seen in recent years. . Final thought Using digital services almost always leaves some traces behind. The question is: ✦ how many ✦ how linkable ✦ and who gets to profit from them Status is all about minimizing those trails, limiting correlation, and giving you more control over your data. Privacy isn’t a setting It’s an environment And that’s what Status is building