Adform Attack Exposes Crypto Users to Targeted Wallet-Swapping
A critical cybersecurity incident has exposed cryptocurrency users to targeted wallet-swapping attacks through a browser-side attack vector.
The attack, which was disclosed at the start of August 2026, targeted a shared resource file used by Adform, a major advertising technology provider. By injecting malicious code into this widely utilized library, attackers achieved a rare supply-chain compromise that propagated directly to unrelated downstream sites without requiring individual breaches.
The script targets copied text or directly inputted form fields containing cryptographic addresses. If a user attempts to transfer cryptocurrencies like Bitcoin, Ethereum, or TRON, the script silently replaces the intended destination string with an attacker-controlled address.
The replaced strings are heavily obfuscated using a six-byte XOR key, and initial threat intelligence scans showed that the altered scripts and associated domains returned zero initial detections on standard platforms like VirusTotal.