Interestana
Home/News/Hackers Poison Adform Script to Swap Crypto Wallet Addresses
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Hackers Poison Adform Script to Swap Crypto Wallet Addresses

Hackers Poison Adform Script to Swap Crypto Wallet Addresses

Attackers compromised the advertising technology company Adform by modifying a JavaScript file served to its clients, effectively transforming it into a browser-side tool capable of rewriting cryptocurrency wallet addresses. Adform detected this malicious activity on July 27, 2026. Upon discovery, the company promptly removed the malicious code from its systems and initiated notifications to its affected clients. Furthermore, Adform reported the incident to the relevant authorities, signaling the seriousness of the breach. The attack targeted users who visited websites utilizing the compromised Adform script on July 27. For any user who copied a cryptocurrency wallet address, such as for Bitcoin, while interacting with an affected site, the copied address would have been surreptitiously replaced with one controlled by the attackers. This sophisticated attack vector highlights the risks associated with third-party scripts embedded in websites, particularly in the rapidly evolving landscape of cryptocurrency transactions. Adform, a prominent player in the digital advertising space, provides ad serving, ad management, and ad tracking solutions to a wide array of businesses globally. Its platform is designed to help advertisers reach their target audiences efficiently and measure the effectiveness of their campaigns. The compromise of its script meant that any website relying on Adform's services for ad delivery or tracking could have been inadvertently weaponized against its visitors. The specific cryptocurrency wallet addresses targeted were not limited to Bitcoin, but also included others, suggesting a broad aim to intercept funds across various digital currencies. The incident underscores the critical importance of robust security measures for third-party vendors, as a single point of failure can have cascading effects across numerous downstream clients. The investigation into the full scope of the breach and the identity of the perpetrators is ongoing, with authorities working to understand the extent of the financial losses and to prevent future occurrences. The attack also brings into sharp focus the vulnerabilities inherent in the digital supply chain, where the integrity of code served by trusted providers can be subverted for malicious purposes. This incident serves as a stark reminder for businesses to conduct thorough due diligence on their technology partners and to implement stringent monitoring protocols to detect anomalies in real-time. The financial implications for Adform's clients and their customers could be significant, depending on the volume of transactions and the value of the cryptocurrency involved. The company's swift response in removing the malicious code and notifying clients is a crucial step in mitigating further damage, but the trust placed in such platforms has been undeniably shaken.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next