Adform Hit by Supply Chain Attack: Ad Script Stole Cryptocurrencies from Visitors
A supply chain attack on Adform injected malicious ad scripts into websites, silently stealing cryptocurrencies by hijacking user clipboards.
Illustrative image generated with AI
On July 27, 2026, thousands of websites integrating the Adform advertising platform unknowingly served a tampered JavaScript file. The code, injected into the trackpoint-async.js file distributed from the domain s2.adform.net, remained active for about a week before being discovered by researcher Kevin Beaumont.
This wasn’t a simple defacement. The payload was designed for silent, surgical theft: it monitored the browser clipboard and replaced Bitcoin, Ethereum, and TRON wallet addresses on the fly with addresses controlled by the attackers.
How the malicious script worked
The alteration targeted one of Adform’s core ad-tracking components. The trackpoint-async.js file, loaded on every page within the ad server’s network, performed two background operations:
- Cryptocurrency address replacement: it intercepted clipboard content using the
navigator.clipboardAPI. Whenever it detected a pattern matching a Bitcoin, Ethereum, or TRON wallet, it replaced it with a malicious address. The swap also occurred transparently on visible text fields within the page that displayed payment addresses. - Data exfiltration: at the same time, the script sent the victim’s public IP, referrer, and the current URL path to the server
84.32.102[.]230:7744, which belonged to the attacker’s infrastructure. No files were downloaded locally, and no persistence was created on the device.
The oldest sample analyzed so far, timestamped July 26, 2026, 23:29:03 GMT, confirms the attack was already underway before the weekend. At the time of scanning on VirusTotal, the code was completely invisible to all antivirus engines.
The attacker’s infrastructure and threat latency
The domain s2.adform.net is a legitimate origin, used by the platform to serve tens of millions of requests daily. Modifying the JavaScript file within that distribution chain gave the attackers immediate reach across all partner sites, without needing to compromise each publisher individually.
The remote server at 84.32.102[.]230 listened on port 7744. The IP address, geolocated in a European data center, was reachable without authentication. The exfiltrated traffic included browsing information sufficient to profile victims and contextualize ongoing transactions.
The wallet substitution wasn’t limited to the clipboard. Analyzing the sample uploaded to Pastebin, Beaumont highlighted routines that also intercepted <input> fields and visible text nodes on the page, making the attack effective even when a user simply viewed a payment address before copying it.
Discovery and immediate countermeasures
The alarm was raised on July 31, 2026, when Kevin Beaumont noticed anomalous behavior on a site using Adform and isolated the tampered sample. Within hours, Adform’s security team removed the malicious code from distribution and restored a clean version of the script.
The company communicated directly with affected customers, providing guidance on corrective actions. It also publicly stated that services are now secure and that the compromise involved visits made on July 27, 2026.
For end users, the main recommendation is to clear browser cookies and site data. Even though the script didn’t create persistence, cached copies might still contain the malicious logic.
Impact and residual risks
The attack required no victim interaction beyond normal browsing. Any site—regardless of sector, including e-commerce, news, or financial portals—that included Adform technology exposed its visitors to the risk of cryptocurrency payment hijacking.
No aggregate data on the amount stolen is currently available. The attackers’ wallets received transactions during the active window, but on‑chain tracking is complicated by the fungible nature of many exchanges and mixers. Moreover, the exfiltration of IPs and URLs could fuel subsequent phishing campaigns.
This incident once again highlights the security challenges in the ad‑tech supply chain. Even a single JavaScript file, if signed and distributed by a trusted vendor, can become a cross‑cutting attack vector when compromised at the source.
Sources
This article is an original reworking based on the sources below.




