Adform's Shared Ad Script Turned Into a Crypto Wallet Hijacker
Adform, a digital advertising technology company whose tracking code runs across thousands of commercial websites, confirmed that attackers modified one of its JavaScript files on July 27, 2026, according to The Hacker News.
The file, once compromised, silently replaced legitimate cryptocurrency wallet addresses with attacker-controlled ones. Anyone who copied a Bitcoin, Ethereum, or Tron address on an affected page that day may have pasted a different destination entirely, without any visible warning. Independent researcher Kevin Beaumont noted that even re-copying a wallet address did not help: the script kept overwriting it.
This is a supply chain attack (where compromising one shared resource gives attackers access to every downstream site using it). Adform's tracking script can run unconditionally across entire websites, so a single tampered file reached unrelated sites without those sites being individually breached. Think of it like a contaminated ingredient distributed to hundreds of restaurants at once.
The script also rewrote addresses typed directly into form fields, not just clipboard content. It attempted to phone home to an external server with page details from each visitor.
Adform says no evidence confirms that visitor IP addresses were transmitted, though it acknowledged the capability existed in the code. How many sites carried the file, how many visitors were exposed, and whether any funds were stolen remain unknown.
What you should do: If you copied a cryptocurrency wallet address on any website on July 27, do not send funds to it without re-verifying the address through a trusted, separate source. Clear your browser cache now. Before sending any crypto transfer, always verify the destination address character by character against the original source.
Sources

