Online advertising firm Adform, one of Europe’s largest adtech firms, suffered a supply-chain attack. Its JavaScript tracking script, 'trackpoint-async.js', served from 's2.adform.net', was compromised. This script is embedded in websites using Adform's advertising platform.
The trojanized JavaScript continuously monitored the clipboard of users visiting websites that embedded the affected script. If it detected Bitcoin, Ethereum, or TRON wallet addresses, it replaced them with an attacker-controlled address. The code also rewrote addresses entered directly into form fields, not just those copied to the clipboard, and replaced addresses every three seconds.
Security researcher Kevin Beaumont discovered the malicious activity, explaining that this allowed end-user devices of downstream websites to be compromised with crypto-stealing malware.
Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. The company stated the code was not designed to install software or establish persistence, operating only while an affected page remained open. While Adform's notice identifies July 27 as the affected date, Kevin Beaumont reported seeing malicious activity via Adform over the past week.
Adform advises users to clear their browser cache, as the altered file may remain cached even after the fix. Additionally, users are recommended to check any wallet address before sending funds to ensure it is the intended recipient's address.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Adform, an online ad provider, was hacked on July 27, resulting in malicious code being served through its ad network. This code replaced cryptocurrency wallet addresses in users' clipboards with attacker-controlled addresses, leading to potential theft of cryptocurrency.
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. This supply-chain compromise allowed attackers to potentially redirect Bitcoin, Ethereum, or Tron payments from users visiting sites using the affected Adform script.
Online advertising firm Adform experienced a supply-chain attack where its JavaScript tracking script was compromised to replace cryptocurrency wallet addresses copied to users' clipboards with attacker-controlled ones. This incident allowed for the redirection of cryptocurrency payments from users visiting websites that embedded the affected Adform script, impacting a broad range of potential victims.