Adform Supply-Chain Attack Compromises Cryptocurrency Wallets

Adform Supply-Chain Attack Compromises Cryptocurrency Wallets

First seen 4 Aug 2026, 02:19 UTC Scworldwww.bleepingcomputer.com 89% similarity 67.5

Article Content

Browse articles
ThreatCluster

Adform, a major online advertising firm, suffered a supply-chain attack that injected scripts into its ad platform, leading to the theft of cryptocurrency. The malicious JavaScript, 'trackpoint-async.js', monitored users' clipboards for Bitcoin, Ethereum, and TRON wallet addresses, replacing legitimate addresses with those controlled by an attacker. Security researcher Kevin Beaumont discovered the issue, which affected users visiting websites using Adform's technology on July 27, 2026. Adform confirmed the incident, removed the malicious code, and is conducting an ongoing investigation. Users are advised to clear their browser cookies to mitigate the impact. The attack did not install persistent malware but compromised devices while affected web pages were open. Adform has communicated with affected clients regarding the incident and recommended actions.

Key Points: • Adform's ad platform was compromised, injecting scripts that stole cryptocurrency wallet addresses. • The attack affected users visiting sites using Adform's technology on July 27, 2026. • Users are advised to clear browser cookies to eliminate the malicious code.

ThreatCluster AI How this analysis works

Timeline

2026-07-27
Malicious code detected in Adform's tracking script
Adform confirmed a supply-chain attack that injected scripts altering cryptocurrency wallet addresses.
BleepingComputer
2026-08-03
Scworld reports on Adform incident
Scworld published a brief summarizing the attack and its impact on cryptocurrency transactions.
Scworld
2026-08-04
BleepingComputer publishes detailed analysis
BleepingComputer provided an in-depth report on the supply-chain attack and its implications for users.
BleepingComputer

Community

Browse all →