Adform Ad Script Compromised to Hijack Cryptocurrency Transactions
Online advertising firm Adform experienced a supply-chain attack where its ad script was compromised, leading to the theft of cryptocurrency by replacing wallet addresses.
Online advertising giant Adform has fallen victim to a sophisticated supply-chain attack, where its own ad script was compromised to inject malicious code capable of stealing cryptocurrency. The attack, discovered by security researcher Kevin Beaumont, targeted Adform's widely used JavaScript tracking script, 'trackpoint-async.js,' which is embedded on countless websites globally.
This trojanized script continuously monitored the clipboard of users visiting websites that utilized Adform's platform. If it detected a cryptocurrency wallet address for Bitcoin, Ethereum, or TRON, it would surreptitiously replace it with an attacker-controlled address. This malicious substitution aimed to redirect any cryptocurrency payments intended for legitimate recipients directly into the attacker's digital wallets.
Adform, a major player in the adtech industry, provides a comprehensive platform including Demand-Side Platform (DSP), Supply-Side Platform (SSP), ad servers, and management tools. The compromise of its tracking script meant that any website relying on Adform's services became a potential vector for distributing this cryptocurrency-stealing malware to its visitors.
Beaumont noted that the compromised script was not flagged as malicious by any major antivirus engines on VirusTotal, underscoring the stealthy nature of the attack. Beyond clipboard hijacking, the malicious Adform-hosted scripts were also observed communicating with an attacker-controlled server, sending victim IP addresses, referring websites, and URL paths, suggesting a broader data exfiltration effort.
Adform confirmed the suspicious activity on July 27, stating that it had identified and removed the malicious code shortly after Beaumont's discovery. The company assured users that further measures were taken to secure the platform and protect visitors. According to Adform, the code was not designed to install software or establish persistence on user devices, operating only while an affected webpage was open.
While Adform asserts that its services are now safe, the investigation is ongoing. The company advised individuals who visited affected websites on July 27, 2026, to clear their browser cookies to remove any lingering malicious code. Adform has also directly communicated with affected clients, providing them with necessary information and recommended actions.
Analysis of samples confirmed that obfuscated malicious code was appended to the legitimate Adform tracking library. This code included a function specifically designed to identify and replace strings matching cryptocurrency wallet address formats, both in the clipboard and directly on web pages. The malicious activity was reportedly ongoing for about a week before detection, with the oldest identified sample dating back to July 26, 2026.
This incident highlights the significant risks associated with supply-chain attacks in the advertising technology sector. The widespread integration of third-party scripts means that a single compromise can have a cascading effect, impacting numerous downstream websites and their users, particularly those engaging in financial transactions.