Adform Ad Script Compromise: Third-Party Supply Chain Attack Targeting Cryptocurrency Users
Attackers modified Adform's trackpoint-async.js to replace Bitcoin, Ethereum and Tron wallet addresses in clipboard data and form fields. Adform identified 27 July 2026, but public reporting suggested activity may have lasted up to a week.
Affected
Attackers modified Adform's shared trackpoint-async.js resource, served from s2.adform[.]net, to rewrite cryptocurrency wallet addresses in visitors' browsers. The captured code recognised Bitcoin, Ethereum and Tron addresses.
Clipboard replacement was only one route. The malicious blocks also walked page text and rewrote values in input, textarea and contenteditable fields, hooked value setters, and intercepted copy, cut, paste and input events. Adform said the code operated only while an affected page was open and was not designed to install software or establish persistence.
Adform detected and removed the code on 27 July 2026, notified affected clients and reported the incident to authorities. The exposure timeline remained unresolved at source time: Adform identified 27 July as the affected date, while independent researcher Kevin Beaumont reported seeing malicious activity delivered through Adform during the preceding week. The incident may therefore have lasted up to a week rather than a settled one-day window.
The public scope was also unresolved. Adform had not disclosed how many sites or visitors received the altered resource, how its deployment path was compromised, whether funds were diverted or who was responsible. It had not published indicators of compromise at source time.
Adform advised users to clear browser caches because the altered file might remain cached after remediation and to verify wallet addresses before transferring funds. Site operators should review third-party script exposure and available telemetry, while avoiding assumptions about impact until Adform publishes further evidence.
Sources