← Back to blog

Adform Script Poisoned to Redirect Crypto Payments

Attackers compromised Adform's JavaScript to swap cryptocurrency wallet addresses on customer sites. The breach affected visitors who copied Bitcoin addresses on July 27.

TL;DR

  • Hackers injected malicious code into Adform’s ad script.
  • The script altered cryptocurrency wallet addresses in real-time.
  • Attack occurred on July 27 before being detected and patched.
  • Adform notified clients and reported the breach to authorities.
  • Businesses using Adform should audit their site security.

Cybercriminals targeted the advertising platform Adform by injecting malicious JavaScript into one of its scripts. The code was designed to automatically replace visible cryptocurrency wallet addresses with attacker-controlled ones. This manipulation occurred silently in users’ browsers, affecting any visitor who copied a wallet address from a site using the compromised script.

Adform discovered the breach on July 27, 2026, and immediately removed the malicious payload. Affected customers were notified, and the company worked with law enforcement to investigate the attack. While the window of compromise was brief, the potential impact on end-users highlights the risks of third-party script dependencies in modern web applications.

How the Attack Worked

  • Attackers modified a legitimate JavaScript file served by Adform.
  • The malicious script scanned web pages for cryptocurrency wallet addresses.
  • Detected addresses were swapped in real-time without user knowledge.
  • Only Bitcoin addresses were targeted during the compromise window.
  • No evidence suggests data exfiltration or account takeovers occurred.

Impact and Recommendations

  • Websites using Adform’s ad serving tools were potentially affected.
  • Visitors who copied wallet addresses on July 27 may have sent funds to attackers.
  • Adform responded quickly but acknowledged the severity of supply-chain attacks.
  • Organizations should audit third-party scripts and implement subresource integrity (SRI).
  • Monitoring for unauthorized financial redirects is advised for impacted sites.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.