Technology News

Adform Adware Turns JavaScript Into Crypto Wallet Hijacker

Clients Warned After Script Modification Altered Bitcoin Addresses

A compromised Adform script rewrote Bitcoin wallet addresses on client sites, prompting a swift response from the ad tech firm.

Adform, a provider of web‑ad technology, discovered that a JavaScript file it serves had been altered to act as a browser‑side tool that rewrites cryptocurrency wallet addresses on any site that loads the script.

On July 27, 2026, the company identified the modification, removed the malicious code from its distribution network, and notified all affected customers.

The altered script was designed to detect the presence of a Bitcoin address on a page, then replace it with a different address that belonged to the attackers.

When a visitor copied the address from a client site, the copy buffer would contain the attacker’s wallet rather than the legitimate one.

Adform’s public statement noted that the change was limited to the script’s JavaScript logic; no server‑side components were compromised.

Clients who had the affected script on July 27 were advised to clear browser caches, update the script to the latest version, and verify that all displayed addresses matched their records.

In addition to client outreach, Adform reported the incident to law enforcement agencies and released a detailed technical brief to help site owners detect similar tampering.

Cybersecurity researchers confirmed that the attack vector relied on the script’s ability to execute in the visitor’s browser, allowing the address rewrite to occur without any network traffic to the attackers.

While the incident did not involve direct theft of funds, it exposed users to the risk of inadvertently sending cryptocurrency to a malicious address.

Adform’s rapid removal of the compromised code and its communication with clients are cited as best practices for mitigating supply‑chain attacks on third‑party scripts.

Adform Adware Turns JavaScript Into Crypto Wallet Hijacker

Adform, a provider of web‑ad technology, discovered that a JavaScript fi…

Adform, a provider of web‑ad technology, discovered that a JavaScript fi…

Adform, a provider of web‑ad technology, discovered that a JavaScript file it serves had been altered to act as a browser‑side tool that rewrites cryptocurrency wallet addresses on any site that loads the script.

On July 27, 2026, the company identified the modification, removed the malicious code from its distribution network, and notified all affected customers.

The altered script was designed to detect the presence of a Bitcoin addr…

The altered script was designed to detect the presence of a Bitcoin addr…

The altered script was designed to detect the presence of a Bitcoin address on a page, then replace it with a different address that belonged to the attackers.

When a visitor copied the address from a client site, the copy buffer would contain the attacker’s wallet rather than the legitimate one.

Adform’s public statement noted that the change was limited to the scrip…

Adform’s public statement noted that the change was limited to the scrip…

Adform’s public statement noted that the change was limited to the script’s JavaScript logic; no server‑side components were compromised.

Clients who had the affected script on July 27 were advised to clear browser caches, update the script to the latest version, and verify that all displayed addresses matched their records.

In addition to client outreach, Adform reported the incident to law enfo…

In addition to client outreach, Adform reported the incident to law enfo…

In addition to client outreach, Adform reported the incident to law enforcement agencies and released a detailed technical brief to help site owners detect similar tampering.

Cybersecurity researchers confirmed that the attack vector relied on the script’s ability to execute in the visitor’s browser, allowing the address rewrite to occur without any network traffic to the attackers.

While the incident did not involve direct theft of funds, it exposed use…

While the incident did not involve direct theft of funds, it exposed use…

While the incident did not involve direct theft of funds, it exposed users to the risk of inadvertently sending cryptocurrency to a malicious address.

Adform’s rapid removal of the compromised code and its communication with clients are cited as best practices for mitigating supply‑chain attacks on third‑party scripts.