Adform Script Hijacked to Replace Crypto Wallets


Hackers compromised Adform’s tracking script to swap crypto wallet addresses on websites, putting Bitcoin, Ethereum and Tron users at risk.

A compromised JavaScript file distributed through advertising technology company Adform was briefly turned into a tool for swapping cryptocurrency wallet addresses, creating a potential risk for anyone making Bitcoin, Ethereum, or Tron transactions on affected websites.

Adform said it detected the incident on July 27, 2026, removed the malicious code shortly afterward, notified affected customers, and reported the breach to the relevant authorities. While the issue has since been resolved, the company is urging users to clear their browser cache, as some browsers may still hold a cached copy of the altered script.

The compromised file, trackpoint-async.js, was served from s2.adform.net and is widely used across multiple websites. Because the same script is shared by many unrelated sites, attackers only needed to compromise a single resource to reach a much larger number of potential victims. Rather than targeting individual websites, the attack exploited a shared component, making it a classic example of a software supply-chain compromise.

Instead of installing malware on visitors’ devices, the malicious code focused on manipulating cryptocurrency wallet addresses inside the browser. Anyone copying a Bitcoin, Ethereum, or Tron wallet address from an affected page could have unknowingly pasted a different address inserted by the script. Researchers also found the code could rewrite wallet addresses typed directly into forms, meaning simply avoiding copy-and-paste would not have prevented the attack.

Independent security researcher Kevin Beaumont, who first disclosed the compromise, said the script continued replacing wallet addresses even after users tried copying the correct one again. At the time of his investigation, neither the malicious file nor its supporting infrastructure was flagged by VirusTotal. Researcher Max Maass later published a captured copy of the altered JavaScript to help with further analysis.

A closer look at the script showed that attackers had appended two malicious components to Adform’s legitimate code. One continuously monitored clipboard activity, searching for cryptocurrency wallet addresses and replacing matching values with hardcoded alternatives. It also attempted to contact an external server, transmitting the hostname and path of the webpage being viewed.

The second component worked directly inside the webpage, scanning text, rewriting wallet addresses entered into input fields, text areas, and editable content, and intercepting copy, cut, paste, and typing events. It even restored the user’s cursor position after making changes, making the address substitutions far less noticeable.

Adform said it found no evidence that the malicious code successfully transmitted visitors’ IP addresses or details about the websites they were browsing. However, the company acknowledged that its technical analysis indicated such data transmission may have been possible, although investigators have not confirmed whether any information actually reached the attackers.

Several important questions remain unanswered. Adform has not disclosed how the attackers gained access to its deployment environment, how many websites served the compromised script, how many visitors were exposed, or whether any cryptocurrency was ultimately diverted. There is also some uncertainty surrounding the timeline. While Adform identified July 27 as the affected date, Beaumont said he observed malicious activity linked to Adform over the previous week.

As a precaution, Adform recommends clearing browser caches and carefully verifying every cryptocurrency wallet address before sending funds. The company also stressed that the malicious code was not designed to install additional malware or remain on a user’s device once the affected webpage was closed.

Although Adform’s advertising platform supports around 1,800 customers, delivers approximately 1.5 billion advertisements each day, and operates in more than 180 countries, the company said those figures should not be viewed as an indication of the incident’s scale. It has not disclosed how many websites or visitors were actually affected, and the identity of the attacker remains unknown.

Source : The Hacker News

Related articles :


Reports are sourced from official documents, law-enforcement updates, and credible investigations.

Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.