Advertising technology provider Adform has disclosed that attackers compromised one of its JavaScript files and modified it to intercept and alter cryptocurrency wallet addresses copied by visitors to affected customer websites. The tampered script functioned as a clipboard hijacker, a technique commonly used to redirect crypto payments to attacker-controlled wallets without the victim noticing.
Because Adform’s scripts are widely embedded across advertising networks and partner sites, the poisoned code had the potential to reach a broad set of end users through no fault of the sites themselves, a hallmark risk of supply chain attacks against shared ad-tech and analytics tooling.
What Happened
According to Adform, the malicious code was detected on July 27, 2026. The company removed it promptly, notified affected clients, and reported the incident to relevant authorities. Any user who visited a site loading the compromised script on that date and copied a cryptocurrency wallet address, such as a Bitcoin address, during that window could have had the address silently swapped for one controlled by the attackers.
Clipboard hijacking malware of this type typically monitors the system clipboard for strings matching wallet address formats and replaces them with a lookalike or attacker-owned address just before the victim pastes it into a transaction. Victims often only discover the substitution after funds have already been sent to the wrong destination.
Recommendations for Security Teams
- Review browsing activity and ad-tech script inclusions from July 27, 2026, particularly on sites known to embed Adform tags
- Advise users who conducted cryptocurrency transactions on that date to verify the destination address against a trusted source before assuming any transfer was legitimate
- Treat third-party ad and analytics scripts as part of the software supply chain, applying subresource integrity checks and monitoring where feasible
- Encourage users to manually verify wallet addresses character by character rather than relying solely on copy-paste, especially immediately after visiting ad-supported sites
This incident underscores the risk posed by widely distributed third-party scripts in the advertising ecosystem, where a single compromised file can be leveraged to target financial transactions across an unrelated and unsuspecting customer base.
