The other direction needs no attacker at all. Plenty of ordinary text
you copy carries non-ASCII on purpose, and much of it you cannot check by eye.
Copy a password, an API key or a recovery phrase from a password manager or a
documentation page. Real ones contain typographic dashes, accented letters, or a
non-breaking space a web form quietly inserted. You cannot proof-read a secret by
looking at it. A silent auto-fold delivers a different string that appears
identical - so you lock yourself out, or worse, save a corrupted credential you will
never trace back to the paste that mangled it.
For anything you cannot re-read - a secret, a signature, an exact path - a silent
rewrite is both undetectable and irreversible. Nothing malicious happened. The bytes
were fine; the "cleaner" is what broke them.