BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Adform supply-chain attack swaps crypto wallet addresses

Adform supply chain attack rewrites Bitcoin, Ethereum, Tron wallet addresses via JavaScript.

  • Attackers modified Adform’s JavaScript file to rewrite Bitcoin, Ethereum, and Tron wallet addresses on July 27, 2026.
  • The malicious code replaced addresses both via clipboard copy and direct form field entry, and it kept swapping even if users recopied.
  • The compromised resource, trackpoint-async.js, turned the ad-tech platform into a supply‑chain vector affecting downstream websites.
  • Adform recommends clearing browser caches and verifying wallet addresses before any fund transfer.

On July 27, 2026, attackers compromised Adform’s JavaScript library, turning it into a browser‑side tool that rewrites cryptocurrency wallet addresses on any site carrying the script. The malicious code was served from s2.adform[.]net; Adform detected the incident that same day, removed the code, and notified affected clients.

- Advertisement -

The altered script appended two obfuscated blocks to the legitimate library, using a six‑byte XOR key to hide replacement strings for Bitcoin, Ethereum, and Tron patterns. Security researcher Kevin Beaumont, who disclosed the compromise, wrote: “Even if you notice the address is wrong and recopy the wallet, it keeps replacing it.” Max Maass published a captured copy of the script on the same day.

The first block watches for the copy event, reads the clipboard every four seconds, and attempts an HTTP request to an outside server containing the page hostname and path. The second block walks document text nodes and intercepts copy, cut, paste, and input events to rewrite addresses in form fields and contenteditable elements. Adform stated in its incident notice that transmission of IP addresses or site information may have been possible, though no evidence of that was found.

Adform said the code did not install software or persist beyond the page session. The company has not disclosed how many sites or visitors were exposed, how attackers gained access, or whether any funds were diverted. It advises users to clear browser caches and double‑check wallet addresses before sending any cryptocurrency.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Nvidia’s Hyperscaler Revenue Seen at $237B in 2026: Barclays

Barclays analyst Tom O’Malley’s “napkin math” projects NVIDIA could generate $237 billion in hyperscaler...

MetaMask Proactively Exits 17K Validators After Breach

MetaMask proactively exited over 523,000 staked ETH ($1.4 billion) across 17,000 validators following a...

LatAm stablecoin liquidity hinges on few providers: report

A new report from Varys Capital and Verda Ventures found only 16 companies in...

WordPress SC Malware: 8 Persistence Methods, Blockchain C2

Security researchers have uncovered a WordPress malware codenamed SC that uses the Ethereum blockchain...

ARK Invest Sells AMD, Buys $81M Nvidia in Portfolio Shake-Up

Cathie Wood’s Ark Invest purchased $81 million worth of NVIDIA (NVDA) stock on Tuesday,...

Must Read

12 Hosting Providers To Buy VPS With Bitcoin: An Expert Guide for 2026

You need a VPS. You want to pay with Bitcoin. Simple enough, right?Not quite. The market for crypto VPS = VPS hosting that accepts...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading