BitGo, the Palo Alto-based bitcoin security startup, said it quietly launched a dynamic fraud filtering service in its wallet earlier this year, adding a new layer of protection against suspicious transactions. According to comments from BitGo co-founder and CEO Mike Belshe, the feature has already helped at least one customer avoid losses of more than $10,000, equal to over 18 BTC at the time referenced in the report.
The announcement highlights BitGo’s broader strategy of combining multisignature wallet architecture with transaction-level risk controls. Rather than relying solely on private key storage and signing procedures, the company is attempting to identify transactions that appear abnormal or fraudulent before they are completed. In practical terms, that means BitGo may refuse to co-sign a transfer if the request triggers its fraud checks.
Built on a multisignature security model
BitGo was among the early providers to bring multisignature bitcoin wallets to market. Traditional wallets often depend on a single private key, which creates a straightforward but significant point of failure: if that key is stolen, compromised, or lost, the funds may be at risk. BitGo’s model instead uses a 2-of-3 multisig structure, where three keys are created and any two are required to authorize a bitcoin transaction.
Under this design, one key is held by the user, another is used in the transaction authorization flow, and BitGo keeps one key offline as a backup. The setup allows the company to apply user-defined policies and security checks before co-signing transactions. This architecture has been positioned as a safer alternative to single-key wallets, particularly for users and businesses handling larger balances or operating in more complex treasury environments.
Beyond retail wallet functionality, BitGo also offers enterprise-focused services for bitcoin portfolio management, corporate treasury operations, and business enablement. Extending fraud checks to these environments could be especially relevant for organizations that manage operational flows through APIs and automated systems.
Targeting clipboard hijacking malware
The company framed malware as one of the most important real-world threats facing bitcoin users, especially malware designed to manipulate copied wallet addresses. In this type of attack, a victim copies a legitimate bitcoin address into the clipboard, but malicious software silently replaces it with an attacker-controlled address before the user pastes it into the wallet interface. If the substitution goes unnoticed, the funds are sent to the wrong destination and are typically unrecoverable.
BitGo specifically referenced Trojan.Coinbitclip, a malware strain identified by Symantec in February. The malware was designed to monitor the clipboard for copied bitcoin addresses and then swap them with addresses controlled by the attacker. The emergence of such threats underscored an uncomfortable reality for users: even when private keys remain secure, a transaction can still be compromised at the moment the destination address is entered.
According to Belshe, BitGo’s new dynamic fraud filtering service is able to block this category of attack. The company did not provide a detailed technical explanation of how the filtering engine evaluates fraudulent behavior, but its stated approach is clear: if a transaction request appears suspicious, BitGo will not add its co-signature.
“BitGo will not co-sign requests that appear to be fraudulent and will instead report an error to the user,” Belshe wrote.
Wallet and API coverage expands the protection layer
One notable element of the launch is that the fraud checks apply not only to the BitGo wallet itself but also to the BitGo API. That broadens the scope of the feature beyond individual end users and into developer and enterprise workflows. For firms integrating BitGo’s infrastructure into custody, treasury, or payments systems, additional transaction screening at the API level may help reduce accidental transfers, malware-related losses, or operational mistakes.
The rollout also reflects a growing recognition in the bitcoin industry that wallet security is not just about key storage. Attackers increasingly target the endpoints around a transaction, including browsers, desktops, clipboard data, and user behavior. A multisignature setup can reduce the risk of unilateral theft, but it does not by itself eliminate every attack vector. Dynamic fraud filtering is therefore being introduced as a complementary control rather than a replacement for existing wallet security practices.
Balancing convenience and stronger security
Historically, users looking for the strongest protection against malware have often turned to hardware wallets, which keep signing operations offline and reduce exposure to internet-connected systems. Hardware devices remain an important defense against key theft and certain categories of malicious software. However, they can be less convenient in some day-to-day or enterprise use cases, particularly where transaction speed, policy controls, and software integration matter.
BitGo’s move suggests an attempt to narrow that gap by improving protections within online wallet and API environments. By screening transaction requests dynamically and refusing to co-sign those that appear illegitimate, the company is adding a risk-based checkpoint inside the transaction flow itself. For users, that may serve as a valuable backstop in cases where malware interferes with address handling or transaction construction.
At the same time, the announcement stops short of claiming complete protection from all forms of malware or fraud. Instead, the company’s message is more measured: dynamic filtering can help block suspicious requests, reduce losses, and strengthen an already layered multisig system. The fact that BitGo says the service already saved one customer from losing more than $10,000 and 18 BTC offers an early example of its intended value.
As bitcoin wallets continue to evolve, BitGo’s latest update highlights an industry trend toward combining cryptographic safeguards with behavioral and transaction-level analysis. In a threat landscape where attackers do not need to steal a private key to redirect funds, that additional layer may become increasingly important for both individual users and institutional operators.

