Adform Ad-Tech Script Hijacked to Swap Crypto Wallet Addresses
Adform, an advertising technology company based in Denmark, has confirmed that its platform was compromised by attackers who modified a JavaScript file to substitute visitors' cryptocurrency wallet addresses with one controlled by an outside party. The incident occurred on July 27, 2026.
The tampered file, trackpoint-async.js, is used by Adform's clients across over 180 countries and displays approximately 1.5 billion ads daily, according to the company's 2025 annual report. A review of a captured sample found two malicious segments appended to the legitimate script, with their replacement text scrambled using a six-byte XOR cipher.
Adform has alerted its clients whose sites carried the affected script and advised visitors who used those sites on July 27 to clear their browser cache and double-check any cryptocurrency wallet address before completing a transfer. The company has not disclosed how many websites were impacted, how many visitors were exposed, or whether any funds were diverted.
Independent security researcher Kevin Beaumont identified the tampering and published his findings, stating that the injected code monitored visitors' clipboards and swapped in a substitute address whenever it detected a pattern matching a Bitcoin, Ethereum, or Tron wallet. Beaumont also reported that neither the file nor the domains and IP addresses tied to it triggered any detections when checked against VirusTotal.