Adform, a prominent European advertising technology enterprise, recently disclosed a severe security breach. Hackers successfully compromised the company on July 27, 2026. According to rigorous analysis by security researchers, the attackers subtly replaced Adform’s legitimate advertising and tracking codes with malicious scripts.
Consequently, when users visited compromised downstream websites, these scripts attempted to manipulate their clipboards or text input fields, specifically targeting cryptocurrency addresses. If users neglected to meticulously verify their transaction destinations, they risked inadvertently transferring their cryptocurrency directly to the attackers.
In its 2025 annual report, Adform highlighted that its advertising services span over 180 countries globally, serving an astounding 1.5 billion daily ad impressions. However, the official Adform security incident update remains sparse on specific details, meaning the true scale of affected users currently remains unknown.
Supply Chain Attack: Hijacking Downstream Visitors
Online advertising technology inherently relies upon specialized scripts to harvest data and deliver targeted advertisements in real time. Therefore, websites must natively load these ad platform scripts directly within their source code. When attackers successfully hijack an advertising platform, they can manipulate these scripts and inject malicious code. Subsequently, users visiting websites running these tainted codes become unwitting victims, requiring absolutely zero direct interaction to trigger the exploit.
Security researchers discovered that the attackers successfully tampered with Adform’s core script resources deployed across client websites, prominently including the `trackpoint-async.js` file. Because countless websites embed these tracking codes, this incident represents a quintessential supply chain attack. The victimized websites themselves were never directly breached; rather, the third-party scripts they trusted and loaded were compromised. Ultimately, the profound risk cascaded down to the ordinary users browsing those sites.
Malicious Scripts Target Cryptocurrency Addresses
According to Adform’s official statement, the malicious code specifically sought to intercept select cryptocurrency transactions involving Bitcoin, Ethereum, and TRON. The script operated by attempting to replace a user’s intended wallet address, copied to their clipboard, with an alternative address controlled by the attackers. If the user executed the transfer without rigorously double-checking the destination address, they would irreparably send their assets directly to the hackers.
Technical analysis reveals that the malicious script did not merely monitor copy operations. It actively processed pasting actions, input fields, text areas, and other editable content surfaces directly on the webpage. Therefore, even if a user refrained from simply copying and pasting a wallet address, merely typing an address matching the formatted pattern within the page could trigger the malicious script’s rewriting attempt.
Adform clarified that, based on current intelligence, this malicious code was not designed to install persistent malware onto user devices. It did not establish any form of permanent residency. The malicious script executed exclusively while the affected webpage remained open. Consequently, this malware functioned more akin to a transient, browser-side script rather than a traditional, long-term systemic Trojan program.
Crucial Attack Details Remain Under Investigation
Adform declared the situation contained, confirming they dispatched specialized notifications to affected clients while simultaneously reporting the attack to relevant regulatory authorities. For general internet users, Adform strongly advises clearing browser caches if they visited any website utilizing Adform advertisements around July 27th, as browsers may have temporarily cached the malicious script locally.
If users engaged in Bitcoin, Ethereum, or TRON transactions during this critical window, they must immediately audit their transaction histories and verify the accuracy of their recipient addresses. Unfortunately, completed cryptocurrency transactions are immutably irreversible. Thus, the primary, devastating risk of this address-substitution attack remains the permanent, unrecoverable transfer of funds into adversarial accounts.
Nevertheless, numerous critical questions remain unanswered. Adform has yet to reveal precisely how the attackers commandeered the script publication pipeline. Furthermore, the duration of the malicious code’s deployment, the exact number of impacted websites, and whether actual financial losses occurred remain undisclosed. Finally, it is currently unknown if the hackers successfully exfiltrated visitor IP addresses or sensitive browsing session data.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.