VMTech
Discuss a project

Compromised Adform Script Replaced Crypto Wallet Addresses on Customer Sites

Compromised Adform Script Replaced Crypto Wallet Addresses on Customer Sites

On July 27, 2026, advertising technology company Adform detected malicious code in trackpoint-async.js, removed it, notified affected clients and reported the incident to authorities. The altered JavaScript replaced Bitcoin, Ethereum and Tron wallet addresses on customer websites, including addresses entered directly into form fields.

Why the shared script created systemic risk

Adform's tracking code can run on a single page, across selected sections or throughout an entire website. Compromising that shared resource therefore gave the attackers access to unrelated downstream sites without requiring a separate breach of each organization.

The payload installed no software and established no persistence. It operated only while an affected page remained open, but one altered address at the moment of payment could redirect an irreversible transfer. Cached copies may also remain after the server-side fix.

How the address replacement worked

A captured sample contained two malicious blocks appended to the legitimate library, with replacement strings hidden using a six-byte XOR key. One block monitored copy activity and attempted to read the clipboard every four seconds. The other traversed page text and rewrote values in input, textarea and contenteditable elements.

“Even if you notice the address is wrong and recopy the wallet, it keeps replacing it.”

The code also intercepted copy, cut, paste and input events, while hooks on form-value setters altered programmatic writes. One payload attempted to send the page hostname and path to an external server. Adform found no evidence that visitor IP addresses or browsing information were transmitted, although its analysis said transmission may have been possible.

The exposure window remains disputed: Adform identified July 27, while security researcher Kevin Beaumont reported activity over the preceding week. The company has not published the number of affected sites, visitors or page loads, and no diverted funds have been confirmed. The attacker and initial access method are also unknown.

The case adds a browser-side example to the growing risk of software supply-chain attacks, showing how one trusted deployment path can expose otherwise unrelated businesses. Companies should inventory third-party scripts, monitor them for unexpected changes, clear affected caches promptly and require cryptocurrency addresses to be verified through a separate channel before authorizing payment.

#websecurity#supplychain#javascript#cryptosecurity
Open analytics
On the site 1 views
min read 3 01.08.2026
Instagram

Compromised Adform Script Replaced Crypto Wallet Addresses on Customer Sites

Open the post on Instagram ↗