Cybercriminals breached Adform’s supply chain in attempts to swap out victim’s crypto wallets.
Adform, one of the leading full stack independent advertising platforms, has been victim in a cybersecurity incident.
Malicious code was detected on Adform’s website, pointing to a malware designed to steal cryptocurrency.
In the attack, a section of Adform’s website tracking code used to measure visitor activity – “trackpoint-async.js” – was exploited. Hackers used code to interfere with Bitcoin, Ethereum, or Tron cryptocurrency transactions, looking to replace legitimate crypto wallet addresses copied to user clipboards with different addresses.
Advertisers and users of the platform have been advised to clear their browser cache, as altered files could stay in the cache after the fix and to check any wallet addresses before they transfer funds.
Adform said in a blog post: “On 27 July 2026, Adform detected suspicious activity and immediately launched an investigation under its incident-response procedures. Once the cybersecurity threat was confirmed, we contained the incident, removed the malicious code, and took further measures to protect website visitors, our clients, and the Adform platform.”
The ad platform confirmed the code was not designed to install software on a user’s device, nor should it establish persistence and it was only effective while the page was open.
Captured samples rewrote addresses that were entered into form fields, so clipboard pasting was not the only way to replace the addresses.
Adform serves around 1.5 billion ads per day, and is used by over 14,000 companies.
It’s not yet clear how many websites carried the file, how many visitors were exposed, whether the attack was successful in diverting any funds, or how the cybercriminals breached Adform’s deployment path.
“As browsers may temporarily store website code, we recommend that people who visited an affected website clear their browser cache as a precaution,” the blog post stated.
“If you displayed, entered, copied, or pasted a Bitcoin, Ethereum, or Tron wallet address while an affected webpage was open, please check the wallet address and any relevant transaction information for discrepancies.”
Supply chain attacks are incredibly common, and can be devastating. Most large businesses have hundreds of software and supply partners, and smaller organisations may not have the budget for the robust cybersecurity measures.