Protect.Computer
NEWS

Ad Giant Adform's Script Hijacked to Steal Crypto Wallet Funds

· 1 min read · Malicious byte Digital scams
Ad Giant Adform's Script Hijacked to Steal Crypto Wallet Funds

Adform, one of Europe’s largest advertising technology firms, confirmed that its JavaScript library trackpoint-async.js was compromised by attackers who appended obfuscated clipboard-hijacking code. Any website that embedded Adform’s script on July 27, 2026, became an unwitting delivery vehicle: visitors whose browsers loaded the page had their clipboard continuously monitored for cryptocurrency wallet addresses, which were silently swapped out for the attacker’s own. If a victim copied a wallet address to make a payment and pasted it into a crypto transfer form, their funds would have gone to the attacker instead. The malware could also rewrite wallet addresses displayed directly on web pages — so even reading a payment address off a page was not safe.

Security researcher Kevin Beaumont identified the malicious activity, which archive.org snapshots suggest began as early as July 26 at 23:29 GMT. Adform says it detected suspicious activity on July 27, classified it as a “cybersecurity threat,” removed the malicious code, and has since notified affected clients. The company states its platform is now safe, but its investigation is ongoing. This kind of attack — embedding malicious code inside a legitimate, widely trusted third-party script — is particularly hard to defend against because the malicious content is delivered by infrastructure that websites already trust.

How to check if you’re affected

Affected products include any website that embedded Adform tracking technology on July 27, 2026. If you visited a site using Adform’s script that day and handled any cryptocurrency transactions:

  • Clear your browser cookies and cache immediately, as Adform recommends this to eliminate the malicious code.
  • Double-check any cryptocurrency wallet addresses you copied and pasted that day by comparing them character by character with the intended recipient before considering any transaction final.
  • Review browser extension permissions, especially clipboard-access extensions, and remove any you do not recognise.

Sources

Related reading