This is not even a clipboard problem. If the site is compromised, they can display the correct value in the input form, but submit the malicious value in the code that triggers the wallet transaction.
The user’s wallet software can detect these by warning the user that the contract address is unknown or never before seen by them.
The user’s wallet software can detect these by warning the user that the contract address is unknown or never before seen by them.