Adform Platform Compromised in Cryptocurrency Wallet Address Swap Hack
Adform, an advertising technology company based in Denmark, has confirmed that its platform was compromised by attackers who altered a JavaScript file to swap cryptocurrency wallet addresses with one controlled by an outside party.
The incident occurred on July 27, 2026, and the company detected it the same day. Adform's own documentation explains how the tampered file, trackpoint-async.js, can be set to run on a single page or sitewide.
Independent security researcher Kevin Beaumont identified the tampering and reported that the injected code monitored visitors' clipboards and swapped in a substitute address whenever it detected a pattern matching a Bitcoin, Ethereum, or Tron wallet.
The substitution was persistent, with Beaumont noting that 'even if you notice the address is wrong and recopy the wallet, it keeps replacing it.'
Adform has advised visitors to clear their browser cache and double-check any cryptocurrency wallet addresses before completing a transfer. The company has also notified affected clients directly and reported the incident to authorities.